Skip to main content

AI Services

AI Governance & Compliance

Scoped to the AI you actually deploy. This is not general enterprise AI governance consultancy, and we will say so rather than take work we cannot do properly.

AI governance documents what your AI systems do with data, on what lawful basis, and with what oversight. The Nexclick produces this for the systems it builds, written so it can be handed to a regulator, an auditor or an enterprise client's procurement team without rewriting.

Book a 20-minute callFixed-price project · AI Services from £3,500

Is this you?

What usually prompts the call

  • An enterprise client has sent a procurement questionnaire asking what your AI does with their data.
  • You have deployed AI tools and cannot say which providers process what.
  • Staff are using AI tools with client data and nobody has written a policy.
  • You need to show a regulator or an insurer how your AI systems are overseen.

What we do

The actual deliverables

Things that appear on an invoice, not adjectives.

Map the data path
What leaves your systems, to which provider, in which jurisdiction, under what terms, and how long it is retained. Frequently the first time anyone has written this down.
Establish the lawful basis
Under UK GDPR, for each processing activity the AI performs. Where personal data is involved this is not optional and it needs stating specifically rather than generally.
Provider terms review
Whether your data is excluded from model training, where it is processed, and what the retention terms actually say. Enterprise tiers usually exclude training; consumer tiers frequently do not.
Human oversight documentation
Who reviews what, at what point, and how a decision can be challenged. Automated decisions affecting individuals carry specific obligations.
Audit logging
What the system did, when, and on what input. Without a log there is nothing to show anyone who asks, and no way to investigate a complaint.
An acceptable use policy for staff
What may be put into which tools. Most organisations have people pasting client data into consumer AI tools with no policy, which is a real exposure.
A procurement-ready document
Written so it can be handed to an enterprise client’s security team without being rewritten. This is increasingly what unlocks contracts.

Checklist

The AI questions enterprise buyers now ask

These come from real procurement and security questionnaires. If you cannot answer them, contracts stall. Work through them — most organisations can answer fewer than half.

  1. 01Which AI tools does your organisation use, officially and unofficially?
  2. 02Which providers process data on your behalf, and where?
  3. 03Is client data excluded from model training, and can you evidence that?
  4. 04What is the lawful basis for each processing activity involving personal data?
  5. 05How long does the provider retain data you send them?
  6. 06Can a client request that their data is not processed by AI at all?
  7. 07Is any decision affecting an individual made without human review?
  8. 08How can such a decision be challenged, and by whom?
  9. 09What is logged, and how long are logs kept?
  10. 10Who inside your organisation is accountable for AI use?
  11. 11What is your policy on staff using consumer AI tools with client data?
  12. 12How do you assess a new AI tool before adopting it?
  13. 13What happens if an AI system produces a harmful or incorrect output?
  14. 14Have you assessed whether any system could produce discriminatory outcomes?
  15. 15Do you have a data protection impact assessment where one is required?
  16. 16How would a client be notified of an AI-related incident?

How it works

Step by step, with timeframes

Timeframes are typical rather than guaranteed, and they assume we get account access and approvals when we ask.

  1. 01Week 1–2

    Inventory the AI in use

    Systems we built, tools you bought, and tools staff are using unofficially. The third category is usually the largest and the least documented.

  2. 02Week 2–3

    Map data and review terms

    What flows where, provider terms, jurisdictions and retention.

  3. 03Week 3–4

    Document oversight and controls

    Human review points, audit logging, escalation and challenge routes.

  4. 04Week 4–5

    Produce the policy pack

    Staff acceptable use policy, procurement-ready documentation, and a register that can be maintained going forward.

What you get

Reporting and ownership

  • A written data flow map — what goes where, under what terms, for how long.
  • A stated lawful basis for each processing activity involving personal data.
  • A staff acceptable use policy covering which tools may be used with what data.
  • Documentation formatted for an enterprise procurement or security questionnaire.
  • An AI register you can maintain as new tools are adopted.

Tools and platforms

  • ICO guidance on AI and data protection
  • Provider data processing terms
  • Data flow mapping
  • Audit log design
  • Policy templates adapted to your operation

Timeline

How long this actually takes

Four to five weeks. Two scope statements worth being explicit about. This covers the AI you deploy — the systems we build and the tools you use — not general enterprise AI governance consultancy or EU AI Act conformity assessment, both of which need specialist advisers and we will refer rather than attempt. And this is documentation and process work, not legal advice: it should be reviewed by whoever handles your data protection compliance before you rely on it with a regulator or a client.

Pricing model

Fixed-price project

Fixed price for the documentation pack. Included at no extra cost for AI systems The Nexclick builds, because a system without a governance position is not finished.

Full pricing

Questions

AI Governance & Compliance questions

Do we legally have to do this?

Where AI processes personal data, UK GDPR obligations apply as they would to any processing — lawful basis, transparency, and specific rules around automated decision-making. Whether you need a data protection impact assessment depends on the risk. That determination is a question for your data protection adviser rather than for us.

Is our data used to train the model?

It depends entirely on the provider and the tier. Enterprise and business API tiers from the major providers generally exclude your data from training. Consumer tiers frequently do not. We check the actual terms rather than the marketing, and document what they say.

What about staff using ChatGPT with client data?

Extremely common and rarely covered by a policy. It is one of the more realistic exposures most organisations carry. The acceptable use policy addresses which tools may be used with what data, and it is worth writing whether or not you build anything.

Does the EU AI Act apply to us?

Potentially, if you place systems on the EU market or your outputs are used there, and the obligations depend on risk classification. That assessment needs a specialist adviser and we will refer you to one rather than attempt it. This service covers UK data protection and the practical governance of what you deploy.

Is this legal advice?

No. It is documentation and process work — mapping data flows, reviewing provider terms, documenting oversight, and writing policy. It should be reviewed by whoever handles your data protection compliance before you rely on it with a regulator or a client.

Why is this included with the systems you build?

Because a system without a documented data position is not finished. You cannot answer a client procurement question about it, and you cannot show a regulator how it is overseen. Delivering an AI system without that documentation leaves the client with a liability we created.

Tell us what you are trying to fix

A 20-minute call, no pitch deck. The Nexclick will tell you what we would do, roughly what it costs, and whether we are the right people for it.