STAGE 2: DECIDE
AI Compliance and Assurance
Governance, documentation and controls for AI systems that have to stand up to a regulator, an auditor or a customer asking how the decision was made.


The problem
What this is
Most AI governance work produces a policy document nobody uses. The gap that matters is between what your policy says and what your live systems actually do.<br/><br/>Regulatory expectation is tightening across the UK and EU, and the burden falls hardest on organisations that automated decisions before anyone wrote down how those decisions get reviewed. When the question comes, you need to be able to show the control, not describe it.
Who this is for
Who this is for
Regulated businesses using AI in decisions<br/>Financial services, insurance, healthcare and utilities, where an automated decision affecting a customer has to be explainable.<br/><br/>Organisations preparing for audit or diligence<br/>You need your AI estate documented before someone else documents it for you.<br/><br/>Risk and compliance leaders<br/>You own the exposure and need to know what is actually running.
What we do
Inventory of AI and automated decisioning in use, including the systems nobody registered<br/>Risk classification of each use case against applicable regulation<br/>Gap assessment between current controls and what is required<br/>Human oversight design: where a person reviews, on what trigger, with what authority<br/>Documentation, model cards and decision records built to survive audit<br/>Monitoring and escalation design, including what gets logged and who sees it<br/>Third-party and vendor assurance, covering what your suppliers are liable for
What you get
Process mapping workshops with operational leads
Data availability and quality assessment per process
Benchmarking against comparable operational AI deployments
Technology landscape review for relevant use cases
Risk assessment including operational resilience and workforce impact
Written roadmap with implementation specifications
Reliability as a control
Governance that depends on periodic review misses everything that goes wrong between reviews. SignalCrux provides continuous evidence of system stability, which turns "we monitor our models" from an assertion into a record you can show.
Structured interviews with 4–8 stakeholders across functions. Review of existing data, tools, and governance documentation. Independent scoring against our readiness framework. Debrief session with leadership team. Written report delivered within agreed timeline.
Typically the first engagement with a new client. Outputs feed directly into Stage 2 compliance work, Stage 3 vendor selection, or Stage 4 functional deployment — depending on what the diagnostic reveals.
