
Build structured, reviewable AI governance inside your existing Microsoft 365 environment. We configure the controls, evidence and operating routines your organisation needs to demonstrate
accountable oversight-subject to scope, Microsoft licensing and legal applicability.
Netherlands-based
Specialist · AI · Security · Privacy
Microsoft 365 Native
Evidence-based delivery
EU-wide · Remote-first
The EU AI Act requires organisations to demonstrate how applicable governance obligations are
implemented not merely state intentions in policies or slide decks. Reviewers need structured,
traceable evidence that AI systems have been identified, classified, assessed and assigned
appropriate controls.
Protect your board against the dual risks of data privacy violations and AI liability through our converged governance architecture.
Structured site architecture with document libraries for FRIAs, DPIAs, governance policies, incident records, and audit artefacts. Controlled permissions, version history, and sensitivity labels applied.
AUDIT-READY STORAGE
STRUCTURED CLASSIFICATION
A structured four-week engagement that produces your AI inventory, risk classification, gap analysis, and a prioritised compliance roadmap built on your existing Microsoft 365 environment.
Fixed investment · Delivered remotely
End-to-end implementation of your AI governance infrastructure inside Microsoft 365 from the evidence vault and risk registers to Purview controls, Copilot Studio workflows, and your first completed FRIAs.
Scoped investment · Remote delivery
Continuous compliance monitoring, regulatory update integration, quarterly assessments, and ongoing audit support so your governance infrastructure stays current as the AI Act is enforced.
Monthly retainer · Scales with usage
BUILT FOR MICROSOFT 365
SHAREPOINT
Evidence vault, registers, and version-controlled documentation
MICROSOFT LISTS
AI risk register, FRIA log, DPIA tracker, vendor register
COPILOT STUDIO
Intake workflows, FRIA triggers, DSAR automation
PURVIEW
Sensitivity labels, audit logging, retention, and DLP controls
Governance artefacts are created and maintained within your Microsoft 365 environment where
the agreed architecture allows. No separate ESP governance platform is required. Relevant data
flows, Microsoft services and other processors are documented for each engagement.
Auditors receive structured, read-only access to the evidence vault through Microsoft 365's permission model no email attachments, no ad-hoc document requests.
Microsoft Purview provides unified audit logging and DLP controls that make the governance posture visible, searchable, and exportable for regulatory submissions.
Every assessment and classification is reviewed by a qualified compliance professional before archiving. Automation speeds the process. Human judgement ensures defensibility.
Start with a focused AI Act Readiness Call. We will review your current position and identify a practical path towards structured, reviewable AI governance.
We offer a focused set of remote services to help organisations turn complex privacy, AI governance and EU AI Act obligations into clear, practical action. Each solution is designed for lean teams that need expert support, simple workflows and concrete outcomes rather than long reports.
Watch how we leverage your existing Microsoft 365 environment to inventory your AI, classify risk, and build a prioritized roadmap for the Board.
The Act imposes strict "Duty of Care" requirements. Our architecture ensures you have an automated audit trail to prove oversight and mitigate personal legal risk.
The AI Act introduces role-specific governance, oversight and documentation obligations. Our architecture supports board oversight and traceable accountability. The legal exposure of individual directors depends on the facts, their role and the applicable national law.
A Fundamental Rights Impact Assessment is required only for the deployers and high-risk use cases covered by Article 27 of the EU AI Act. We first assess applicability. Where a FRIA is required, we help structure and document it; where Article 27 does not apply, a voluntary
fundamental-rights assessment may still be appropriate.
No. Our "Shield" acts as a governance layer that sits around your AI, enabling innovation within safe, compliant boundaries without slowing down your teams.
Yes. If you collect or process personal data, you must provide a privacy policy (or notice) that is transparent, clear and easily accessible.
It should explain what data you collect, how/why you use it, who you share it with (including third parties), data subjects’ rights, retention periods, and security measures.
You must keep personal data no longer than is necessary for the purpose for which it was collected (“storage limitation” principle). This means you should define retention schedules, justify retained data, and periodically review and delete or anonymise when no longer needed.
When a personal-data breach occurs that is likely to result in a risk to the rights and freedoms of individuals, you must notify the relevant supervisory authority without undue delay and, where feasible, within 72 hours after becoming aware of it. Affected data subjects must also be notified when the breach is likely to result in a high risk to their rights and freedoms.
Yes, but only if specific safeguards are in place. These may include: an adequacy decision on the recipient country, or appropriate safeguards (e.g., standard contractual clauses, binding corporate rules). You must also ensure data subjects are informed and there is documentation of the transfer.
You must appoint a DPO if: your organisation is a public authority, or your core activities require large-scale regular and systematic monitoring of individuals, or large-scale processing of special categories of data. Even if not mandatory, appointing a DPO is often a good best-practice to oversee compliance.
Organisations must facilitate these rights, respond without undue delay, and inform data subjects of their rights.
Individuals (data subjects) have multiple rights, including: right of access, right to rectification, right to erasure (right to be forgotten), right to data portability, right to restrict processing, right to object, and rights related to automated decision-making and profiling. Organisations must facilitate these rights, respond without undue delay, and inform data subjects of their rights.