Pistaply
How We Work

Four disciplines. One accountable system.

AI governance isn't a policy document sitting in a shared drive. It's the structure that makes an AI decision explainable, a risk visible before it materializes, and a deployment defensible when someone asks hard questions.

G

Governance

The internal structures, roles, and decision rights that keep AI use accountable — before something goes wrong, not after the fact.

This means clear ownership of AI systems, defined escalation paths when something looks off, and documented sign-off at the points that actually matter — not governance as a slide in a deck, but as a working part of how decisions get made.

C

Compliance

Meeting the regulatory bar as it stands today, and staying ready as it shifts — the EU AI Act's risk-tiered obligations, ISO/IEC 42001's management system requirements, and the frameworks emerging alongside them.

Compliance here means being able to demonstrate alignment on demand, not scrambling to reconstruct it when a regulator or client asks.

R

Risk

Identifying where an AI system can fail — technically, ethically, or reputationally — who that failure would affect, and what it would actually cost the organization if it happened.

This is risk assessment grounded in the same discipline used for operational and model risk in regulated industries, applied to systems that behave less predictably than traditional software.

A

Assurance

Evidence you can hand to a regulator, a client, or a board — audit trails, documented testing, control evidence — not a policy that only exists on paper.

Assurance is what turns "we believe this is safe" into "here is how we know."

Grounded in the frameworks shaping AI worldwide

The standards we work from

EU AI Act

The world's first comprehensive AI regulation, establishing risk-tiered obligations for providers and deployers of AI systems operating in or affecting the EU market.

ISO/IEC 42001

The international standard for AI management systems — the operational backbone for building governance that can be certified and audited.

NIST AI Risk Management Framework

A voluntary but widely referenced US framework for identifying, measuring, and managing risk across the AI lifecycle.

OECD AI Principles

The closest thing to a global consensus on responsible AI, referenced by regulators and policymakers well beyond the OECD's member states.