AI governance advisory

AI is moving.Give it aclear direction.

Your organisation already uses AI. Shepherd helps you understand where it is, who is responsible and how to govern it in everyday work.

Mexico and Latin AmericaGlobal perspective. Local context.

The starting point

Before another policy, ask the right questions.

As AI tools, suppliers and use cases multiply, responsibility often falls between teams. A governance programme gives them a shared way to make decisions and act.

01

Where do we use AI?

Visibility into tools, systems and their owners.

02

Which risks matter?

Priorities shaped by context and potential impact.

03

Who makes the call?

Clear roles and evidence behind each decision.

How Shepherd helps

Start where you are. Move forward with structure.

A focused assessment, hands-on implementation or ongoing support. The scope starts with your organisation.

01

Understand

AI governance readiness assessment

A shared understanding of your AI use, governance maturity and the gaps worth addressing first.

For teams that need a clear starting point.

What you take away

  • An initial AI inventory and accountable owners
  • A 15-control maturity scorecard and gap matrix
  • An executive report and 90-day action plan
02

Build

Programme implementation

Turn the roadmap into a way of working: useful policies, accountable decisions and controls built into your processes.

For organisations ready to move from planning to practice.

What you take away

  • Policies, roles and a governance committee
  • Risk, impact and supplier assessment processes
  • Team training and an evidence repository
03

Operate

Managed AI governance

Keep the programme moving as tools, risks and the questions your team faces continue to change.

For teams that need ongoing specialist capacity.

What you take away

  • Register upkeep and reviews of new AI use
  • Risk, control and evidence monitoring
  • Committee support, reporting and customer questionnaires

A practical way of working

Governance lives in the decisions.

Documents people use. Responsibilities people understand.

Shepherd works with the people who already know your organisation: Security, IT, Legal, Privacy, Risk and the teams using AI. The aim is to make governance part of their work.

  1. 01

    Agree the context

    AI use, business priorities, the teams involved and the scope of the programme.

  2. 02

    Prioritise thoughtfully

    Identify meaningful gaps and define actions, owners and the evidence expected.

  3. 03

    Build with your team

    Design processes and controls that can be used within everyday operations.

  4. 04

    Review and improve

    Reassess risks, follow through on decisions and keep the programme current.

Standards as a reference

A solid framework. Applied to your reality.

Frameworks guide the programme. Your context determines the priorities and scope.

Management system

ISO/IEC 42001

A structure for developing an AI management system and preparing governance documentation and processes.

Risk management

NIST AI RMF

A reference for organising the identification, assessment and management of risk across the AI lifecycle.

Contextual readiness

EU AI Act

A readiness overlay where your organisation’s AI use and activities make this framework relevant.

Shepherd supports preparation and implementation. Accredited bodies provide certification; your legal advisers own legal conclusions.

Before we begin

Questions worth working through.

Do we need to develop AI to work with Shepherd?

No. Governance also matters when your organisation uses third-party tools or adds AI to existing processes. The scope starts with actual use, accountable owners and relevant risks.

Where should we start?

If you do not yet have a shared view of AI use and governance gaps, the readiness assessment is a useful starting point. If a programme is already in place, an initial conversation helps identify the specific support you need.

Can Shepherd certify our organisation?

No. Shepherd helps prepare and implement a governance programme. Certification is conducted by an accredited body and is not a guaranteed outcome of an engagement.

Can we build on existing policies and processes?

Yes. The work starts with your security, privacy, risk and compliance processes to identify what can be adapted to AI and where additional work is needed.

Is this a software platform?

This offering is professional advisory and ongoing support. The programme is designed around your organisation and can draw on tools your team already uses.

The next step

Start with a conversation.

Tell us how your organisation uses AI, what concerns you and what you need to resolve. From there, we can define the right scope.

Email Shepherd

Your email opens in your usual email application.