Practical AI governance templates, policy guidance and advisory support to put structure around how AI gets used in your business. Start free. Extend when you need to. Get advice when it matters.
Most businesses have AI and shadow AI being used somewhere in the business already, often before anyone has agreed how it should be used. There is no written policy, no acceptable-use position, no clear answer for the client who asks whether AI touched their work. Regulators, insurers and prospects are starting to ask — and “we’ll get to it” is no longer an acceptable answer.
Best-effort approaches don't survive a regulator question or a client questionnaire.
Different staff members making different judgement calls. Inconsistency is the audit risk.
When something does go wrong, the audit trail is everyone's memory. That's not defensible.
Plenty of businesses start with the downloads and never need more. Others come back for the extended pack as their business and AI usage grows. The advisory engagement is for when the templates have to hold up to a regulator, an insurer, or a serious client question.
The basics, ready to use as-is. Designed for SME businesses and aligned to ICO, DUAA 2025 and ISO 42001 thinking.
No contact details required.
Everything in the free pack, plus the working documents to operate the policy day to day. A structured starting point aligned to ISO 42001 principles, not a full governance framework or certification.
One-off.
For businesses that want the templates adapted to their business, the leadership conversations facilitated, and the policy actually adopted — not filed.
Typically 2 to 4 weeks to implement.
Short enough that people will actually read them. Specific enough that your regulator and your clients can take you at your word.
ICO, DUAA 2025, your sector regulator (SRA, RICS, FCA), the EU AI Act in summary — and where ISO 42001 fits.
What staff can use AI for, what needs sign-off, what is off-limits and how that is communicated.
A policy your business can take away and adapt, with the key clauses already written.
Who owns AI in your business, what the audit trail looks like, how incidents get handled.
Templates aligned to ICO guidance, DUAA 2025, sector-regulator expectations and ISO 42001 — so what you adopt holds up.
The next step is a 30-minute discovery and assessment call — no slide deck, no sales pitch.
An AI policy gives employees clear guidance on which tools they can use, what information they can enter and how AI-generated content should be checked. It reduces uncertainty and helps prevent unsafe or inappropriate use.
AI governance is usually a shared responsibility across senior leadership, IT, security, legal, compliance and business teams. We help define clear roles so that decisions are made consistently and issues are managed properly.
AI-generated content should always be reviewed before it is used for important decisions or external communication. We help organisations introduce review processes, user guidance and approval controls based on the level of risk involved.
Yes. Good governance helps organisations control how personal, confidential and sensitive information is used with AI tools. We help align AI policies and controls with your existing data protection, information security and compliance requirements.
AI governance should be reviewed regularly because technology, regulations and business use cases continue to change. We can provide scheduled reviews to update policies, assess new risks and ensure controls remain suitable.
Most businesses start with training or deployment, then add governance and ongoing support as the rollout matures. Not sure where to begin? A 30-minute call settles it.
Practical training to get real value from AI. Copilot-led skills for everyday users, covering Copilot and Claude, matched to the work each team does.
Get more from Microsoft Copilot than just the licence. Tenant readiness, permissions, security configuration and a controlled rollout done properly.
Keep momentum after go-live with hands-on support, user enablement and governance checks.
— Primary Care Workforce Academy
— Maxis GBN
— Curlew Capital
“PSTG are incredibly responsive and knowledgeable, always ready to tackle any challenge we face. Thanks to their support, we’ve been able to focus more on our core mission to provide patient‑centred healthcare in Bromley.”
— Bromley GPA
The same approach we take to every service we deliver — calm, sequenced, measurable.
Get the foundations right. Permissions, security, tenant readiness — so AI is safe before it scales.
Build the everyday skills and prompt patterns that turn licences into real, measurable productivity.
Govern what you have, decide what comes next, and keep AI moving at the pace of your business.
Say ‘yes’ to a practical partnership designed around what your organisation needs next.
Reduce risks and get rapid expert support.
Lower costs and streamline your Microsoft environment.
Build a roadmap that supports long-term growth & compliance.