AI GOVERNANCE
AI governance must rapidly become fit for purpose to stay ahead of risks and controls.
AI governance is often treated as the quieter cousin of AI deployment. It should not be. The discipline required to know what algorithms exist, what they decide, who owns them and whether they remain compliant as they drift, is at least the equal of the effort spent building them in the first place.
Where Forbury Consulting is leading
Discovery and estate mapping
Defining what AI actually exists across the business, in code repositories, APIs, SaaS integrations, LLM access and shadow deployments, is the most consequential step in governance, and the one organisations most consistently get wrong. Self-declaration captures a fraction of it, automate the rest.
Risk classification and regulatory mapping
Not every algorithm carries the same risk and treating them as if they do wastes effort where it matters least and leaves it thin where it matters most. We classify each algorithm against the EU AI Act, FCA, PRA and internal policy, so governance effort tracks risk rather than guesswork.
Ownership and accountability
A register without an owner is a document, not a control. We assign business and technical accountability to every algorithm, with a full audit trail, so questions from the board or a regulator have an answer and a name attached to it.
Continuous monitoring and control
Governance done once at deployment is governance that expires the moment the model drifts, the data changes, or the regulation moves. We deploy tools that track performance, fairness and compliance on an ongoing basis, not as a point-in-time exercise.
Regulatory engagement and assurance
Particularly in regulated financial services, AI governance lives or dies by the credibility of the regulatory position. Explainability, data sensitivity, conduct and audit-readiness need to be designed for, not discovered after the fact.
Why James?
James experience includes leading and advising on complex multiple disciplinary global transformation change programmes, utilising leading technology and approaches, working with regulators in highly complex and often stressed organisations. He works extensively with risk, control and compliance functions and introduced rigorous governance frameworks and automated tooling environments. Assisting clients to apply a critical lens: find what exists, classify it honestly, assign it an owner, and give the board and the regulator acredible answer before they have to ask for one.