SERVICES

AI Governance and Compliance

Organizations adopting AI to boost productivity must ensure safe, fair, and compliant use. We provide EU AI Act and ISO 42001 advisory, risk classification, conformity assessments, governance implementation, and AI compliance training.

Section 01 · AI governance services

What AI governance services have to establish

The AI Act regulates by role and by risk, not by technology. The first question is therefore not which model a system uses but which role the organisation holds — provider, deployer, importer, distributor, authorised representative, or product manufacturer — because the duties attach to the role. The same tool can place an organisation in one role when it is bought and a different one when it is rebranded or materially modified.

The timeline has moved. Prohibited practices under Article 5 have applied since 2 February 2025 and obligations for general-purpose AI models since 2 August 2025. The general applicability date of 2 August 2026 has now passed. Obligations for stand-alone high-risk systems under Annex III were deferred to 2 December 2027 by Regulation (EU) 2026/1744, which entered into force on 27 July 2026; high-risk AI embedded in products under Annex I moves to 2 August 2028. The deferral changed the deadline, not the substance of what has to be built.

ISO/IEC 42001:2023 supplies the management-system structure — 38 Annex A controls across nine areas, certifiable by an accredited body. It is a useful vehicle for AI governance and a credible signal in procurement, but certification is not a conformity assessment under the AI Act. The two answer different questions and require separate evidence, and a certificate will not shorten a high-risk conformity assessment by a single step.

Where AI processes personal data, the obligations overlap rather than stack. Article 22 of the GDPR governs automated decisions with legal or similarly significant effects, Article 35 may require an impact assessment, and Article 27 of the AI Act adds a fundamental rights impact assessment for certain deployers. One inventory and one set of decision records can serve all three; three parallel exercises usually produce three inconsistent answers about the same system, which is the version an auditor tends to find.

2 Dec 2027
Annex III high-risk obligations apply
2 Aug 2026
General applicability date, now passed
7%
Upper fine tier, global annual turnover
38
ISO 42001 Annex A controls
6
Operator roles defined by the AI Act
What the AI Act and ISO 42001 actually enumerate

Classification decisions are made against the text of the Regulation and the standard, not against a private taxonomy. Each cell represents one entry; point at a group to see the entries that most often decide a classification. Counts are the full published sets.

Article 5 bans: eight since Feb 2025, two more from Dec 2026

10 of 62
  • Subliminal or purposefully manipulative techniques
  • Exploitation of vulnerabilities due to age or disability
  • Social scoring leading to unjustified detrimental treatment
  • Predicting criminal offences from profiling alone
  • Untargeted scraping of facial images for recognition databases
  • Emotion inference in the workplace and in education
  • Biometric categorisation to deduce sensitive attributes
  • Real-time remote biometric identification for law enforcement
  • Non-consensual intimate imagery — new, from 2 December 2026
  • AI-generated child sexual abuse material — new, from 2 December 2026
Section 02 · Governance drivers

What forces an AI control model into existence

AI use spreads through purchased tools, embedded product features, and individual experiments long before any one team can describe it. The trigger for governance work is usually external: a customer questionnaire asking which role the organisation holds under the AI Act, a supplier that has quietly added a model to an existing product, a deployment that turns out to sit in an Annex III area, or the December 2027 high-risk deadline arriving with a conformity assessment attached.

  1. 01 Unclear role under the AI Act Duties attach to the role, and rebranding or materially modifying a bought system can turn a deployer into a provider. Strength 5 of 5
  2. 02 Deployment in an Annex III area Employment, credit, education, and essential-service use cases carry the full high-risk regime from 2 December 2027. Strength 5 of 5
  3. 03 Customer and procurement scrutiny Buyers now ask for role classification, model provenance, and oversight arrangements before signature. Strength 4 of 5
  4. 04 Opaque AI supply chain Vendor claims have to become contractual responsibilities, deployment constraints, and change notifications. Strength 3 of 5
  5. 05 Overlap with data protection Automated decisions under GDPR Article 22 and impact assessments duplicate effort when governed separately. Strength 2 of 5
Indicative strength on a 1–5 scale, based on Up Secure engagement patterns.
Deployers of bought AI systems

Most organisations sit here, and the exposure is that rebranding a system or materially modifying its intended purpose moves them into the provider role with the obligations that follow.

Providers of AI features in products

Software vendors embedding models take on provider duties for their own systems while remaining deployers of the models they build on.

Organisations in Annex III areas

Recruitment, credit scoring, education, and essential-service use cases carry the full high-risk regime, including conformity assessment and post-market monitoring.

Section 03 · Operating coverage

Where each service contributes

Governance has to preserve a traceable path from each use case to its role classification, risk decision, evidence, and monitoring. The matrix shows where each area attaches; the services that deliver them are listed further down.

AI governance service coverage across the operating lifecycle
Where each capability contributes between discovering AI use and monitoring it in operation.
Capability InventoryClassifyControlMonitor
Discovery & classification
AI use-case inventory Covered during Inventory Covered during Classify Not covered during Control Not covered during Monitor
Role and risk classification Covered during Inventory Covered during Classify Not covered during Control Not covered during Monitor
Supplier and model provenance review Covered during Inventory Covered during Classify Covered during Control Covered during Monitor
Assessment
AI privacy and ethical risk audit Not covered during Inventory Covered during Classify Covered during Control Not covered during Monitor
Fundamental rights impact assessment Not covered during Inventory Covered during Classify Covered during Control Not covered during Monitor
ISO 42001 gap analysis Covered during Inventory Covered during Classify Covered during Control Not covered during Monitor
Implementation
Technical documentation and transparency records Not covered during Inventory Covered during Classify Covered during Control Covered during Monitor
Human oversight and escalation workflows Not covered during Inventory Covered during Classify Covered during Control Covered during Monitor
Operation
Post-market monitoring and change review Not covered during Inventory Not covered during Classify Covered during Control Covered during Monitor
Specialist role capacity Covered during Inventory Covered during Classify Covered during Control Covered during Monitor
Section 04 · Service portfolio

AI governance services matched to the control gap

The catalogue below groups the available services by expertise, keeping assessment, advisory work, specialist roles, and recurring managed activities as distinct choices. Most engagements start with inventory and role classification, because every later decision depends on which role the organisation actually holds.

Audits and Assessments

Systematic compliance audits, security assessments, and maturity evaluations across GDPR, ISO 27001, NIS 2, SOC 2, and AI Act frameworks for organizations in regulated industries.

AI System Privacy & Ethical Risk Audit

AI system audit covering data protection, ethical risks, bias assessment, and GDPR/AI Act compliance gaps.

AI ActISO 42001
Read more

AI Act Compliance Audit

EU AI Act compliance audit — risk classification, gap analysis, and conformity assessment for AI systems.

AI ActISO 42001
Read more

Consultancy and Advisory

Strategic consultancy and implementation advisory across GDPR, AI Act, ISO 27001, NIS 2, and cybersecurity for organizations building compliance programs or making security architecture decisions.

US Software Review for EU Regulatory Compliance

Review of US-built software against EU privacy and cybersecurity regulations — GDPR, NIS 2, and AI Act compliance.

AI ActNIS 2 DirectiveGDPR
Read more

Compliance and Risk Assessment Workshops

Compliance and risk assessment workshops — DPIA facilitation, risk analysis, and team capability building.

AI ActGDPR
Read more

AI Act Implementation Consultancy

AI Act implementation consulting — governance framework, policies, roles, and conformity roadmap for AI deployers.

AI ActISO 42001
Read more

Role Outsourcing

Dedicated specialist roles including DPO, Privacy Engineer, Security Engineer, vCISO, and AI Compliance Officer available on a fractional or full-time outsourced basis.

AI Security Officer

Outsourced AI Compliance Officer — AI Act oversight, risk monitoring, and governance coordination for AI deployers.

AI ActISO 42001
Read more
Start the conversation

Scope AI governance from an inventory, not from a policy.

The first conversation establishes where AI is actually in use, who owns each case, and which role that puts you in. Everything downstream — classification, impact assessment, documentation, monitoring — follows from that answer, and December 2027 is a deadline for having it built rather than for starting.

Why Up Secure
Role decides everything else Article 25 can turn a deployer into a provider through rebranding alone. That gets settled before the rest of the programme is scoped.
Post-Omnibus timeline Advice reflects Regulation (EU) 2026/1744, including the two further prohibitions arriving on 2 December 2026.
One record, three regimes AI Act duties, GDPR Article 22 decisions and ISO 42001 controls draw on the same inventory and decision records.
Section 05 · Frequently asked

Questions asked before an AI governance engagement is scoped

Yes. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It defers obligations for stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and for high-risk AI embedded in regulated products under Annex I to 2 August 2028. Prohibited practices, general-purpose AI model obligations, and the governance and penalty provisions were not deferred and continue to apply.

This page presents the services used to build and operate AI governance. The AI Act framework page explains the Regulation itself — its risk categories, roles, and obligations. They reference overlapping services because they answer different questions: what the law requires, and who does the work of meeting it.

With an inventory that records, for each use case, the owner, the supplier, the purpose, the people affected, the data involved, and the deployment context. Role classification follows from that, and everything else follows from the role. Starting with policy instead is the common mistake: a policy written before the inventory usually describes an organisation that does not exist.

Article 25 sets the triggers. Putting your own name or trademark on a high-risk system already on the market, making a substantial modification to it, or changing its intended purpose so that it becomes high-risk all transfer provider obligations to you. This matters commercially, because it is easy to cross that line by rebranding a purchased tool or repurposing it for a use the original provider never assessed.

No. ISO 42001 certifies a management system through its 38 Annex A controls and is credible evidence of governance maturity in procurement. The AI Act requires something different: a determination of the organisation's role, classification of each system, and the specific duties that follow — including conformity assessment and registration for high-risk systems. A certified management system makes that work easier to run, but does not substitute for it.

Where AI processes personal data, the two regimes overlap on the same facts. GDPR Article 22 governs automated decisions with legal or similarly significant effects, Article 35 may require a data protection impact assessment, and AI Act Article 27 adds a fundamental rights impact assessment for certain deployers. The efficient approach is one inventory, one risk record, and one supplier review feeding all three, rather than parallel exercises that reach different conclusions about the same system.