Loading…
Loading…Loading…
Loading…AI Governance and Security · Build
The documents auditors, insurers and enterprise customers ask for, written to be used.
A proportionate policy set for your size: acceptable use covering personal devices and AI tools, data classification, access and joiner-leaver procedure, incident response with named roles, and an evidence pack that maps each policy to the control that satisfies it. Two to three weeks, with an annual review option.
Discuss this engagementWho this is for
Most businesses this size have no written policies at all, or they have a set someone downloaded years ago, renamed, and never opened again. Nobody in the building could tell you what the incident response plan says, because there has never been one, or because the one that exists was written for a business twice this size and nobody adjusted it.
Then a customer's procurement team sends a security questionnaire with a deadline on Friday, or the insurance renewal asks what your incident process actually is, and there is nothing accurate to send. Writing something under that kind of deadline pressure rarely produces a document anyone can stand behind a year later.
You get a policy set sized to your actual business: acceptable use, data classification, access and joiner-leaver procedure, and incident response with a named person against every role. Each policy maps to the control that actually satisfies it, so when someone asks how a rule is enforced you have a real answer rather than a paragraph of intent.
A policy nobody has read protects nobody, least of all the business that wrote it.
The whole set assembles into one evidence pack, organised the way the questionnaires you actually receive are organised, so answering one stops being a week of writing and starts being a matter of finding the right page.
Interview and collect what exists
Draft the set proportionate to your size
Review with leadership and adjust
Map policies to controls and assemble the pack
We start with an interview covering how your business actually runs, plus whatever documents already exist, used or not, so nothing gets rebuilt from nothing when a usable piece is already sitting in a drawer. From there we draft a set proportionate to your size: enough to be credible to an auditor, small enough that your team can actually read it in one sitting.
Leadership reviews the draft and adjusts anything that does not match how the business really works, because a policy leadership has not actually agreed to is not a policy your staff will trust. Once it is approved, we map every policy to the control that satisfies it and assemble the evidence pack, ready for the next questionnaire that lands.
You receive the policies themselves: acceptable use, data classification, and access and joiner-leaver procedure, each one written in language your staff will actually read. Alongside them, the incident response plan, with named roles against each step so nobody is improvising who calls whom at two in the morning.
And you receive the evidence pack: every policy mapped to the control that satisfies it, assembled and ready to hand to an auditor, an insurer, or a customer's procurement team the next time they ask. Take the annual review if you want the set to stay current as your business changes, rather than drifting quietly out of date the way most policies do.
The engagement

A unified operations platform and client portal for Airful, replacing fragmented workflow tools with a Supabase-backed operating layer.

From Email Migration to Full-Spectrum Business Partnership

Strategic Growth Partnership
No, we write them from how your business actually operates. That is the only way staff read them and follow them when it matters.
The pack is organised to answer the common enterprise questionnaires directly, section by section. You can hand it to whoever is asking and point them straight to the relevant answer.
No, where a regulation applies we map the obligation into the pack and recommend your counsel confirm it. That keeps the legal judgement with a qualified professional, where it belongs.
Acceptable use covers AI tools directly: what may be shared with them, and how staff tell the difference in the moment. It is one section inside the same pack, so nobody treats it as a special case.
A conversation first, then a written scope.
Discuss this engagement