Xelvio

AI governance

Context

Organisations are adopting AI tools faster than they are documenting how they use them. Customers, funders and regulators are beginning to ask. The EU AI Act applies to UK organisations placing AI systems on the EU market or whose outputs are used there, with obligations phased in through 2026 and 2027. The ICO expects AI processing of personal data to be covered by a DPIA. Procurement questionnaires increasingly include AI questions.

Scope

AI use policy

What staff may and may not enter into which tools, and on what basis.

AI inventory and risk classification

A register of AI systems used or built, classified by risk (including EU AI Act category where relevant), with owner, purpose and data involved.

DPIAs for AI processing

Where personal data is processed by a model, the assessment the ICO expects.

Vendor due diligence

Assessment of AI suppliers: training on customer data, residency, sub-processors, retention.

Governance for organisations building with AI

Documentation, human oversight, logging, transparency obligations and testing evidence, proportionate to the system.

Board briefing

A session for trustees or directors on what AI adoption means for their responsibilities.

Delivery

The AI register, DPIA records and policy library are maintained in the Xelvio Toolkit alongside the data protection framework. Xelvio uses AI in its own delivery: the Toolkit’s document generator produces first drafts of policies and assessments, which are then reviewed by a practitioner. This is stated openly.

Terms

AI governance review at a fixed fee; policy set at a fixed fee; ongoing work under the fractional compliance officer retainer. [Insert.]