AI governance and regulatory evidence

Building the evidence as a by-product of the work, rather than assembling it under deadline.

AI governance for regulated organisations means maintaining a defensible, current record of what AI systems exist, what they do, who is accountable, how risk was assessed and how that is evidenced, against frameworks including the EU AI Act, ISO/IEC 42001 and existing model risk governance. The EU AI Act's obligations for stand-alone high-risk systems were originally due to apply from 2 August 2026. An amendment approved by the European Parliament in June 2026 moves that to 2 December 2027, and to 2 August 2028 for high-risk systems embedded in regulated products. The prohibitions and the AI literacy duty have applied since 2 February 2025 and the general-purpose model obligations since 2 August 2025, so the extra time buys preparation rather than exemption, and the inventory is still the part that takes longest.

Theme
Proving it and controlling it
Read time
13 minutes
Questions answered
18 in full
Updated
Evidence basisOur approach, not a case study
Usually engaged as
Agentic Design Team. 2–4 months, £35k–£55k / month.
see the engagement →
Evidence basis

This is our approach, not a programme we have already run.

This is how we would approach it, grounded in a decade of delivery inside regulated organisations including HSBC, not a write-up of an EU AI Act conformity programme we have completed. We are not a law firm and we do not give legal advice; we design the operating model and the delivery discipline that produces the evidence your legal and risk functions need. Where you need formal legal interpretation, we will say so and work alongside whoever provides it.

On this page

The demand signal

The forcing function moved and did not disappear, which is the most common thing to get wrong about this. Article 113 of the EU AI Act set 2 August 2026 as the general application date, with product-embedded high-risk systems following in August 2027. The Digital Omnibus amendment, agreed in May 2026 and approved by the European Parliament in June, postpones stand-alone high-risk obligations to 2 December 2027 and product-embedded ones to 2 August 2028. Nothing about what a high-risk system has to evidence changed: conformity assessment, technical documentation, risk management, data governance, human oversight, registration and post-market monitoring. If your plan assumed August 2026 you have more time than you thought, and if your plan assumed the obligations went away, it did not.

Why it stalls

4 failure modes we keep meeting

The board wants an AI plan, and nobody can list the AI already running

The inventory is the first deliverable and the one that reliably takes three times as long as planned, because AI has entered the organisation through tool purchases, embedded vendor features and individual initiative rather than through a single programme. You cannot classify what you cannot enumerate, and you cannot write a credible plan for a board on top of an estate nobody has counted. Plans written before the count are the ones that get quietly rewritten two quarters later.

Governance is written as policy, not as process

A policy that says agent decisions must be auditable does not make them auditable. Where the requirement is not embedded in how work actually flows, evidence has to be reconstructed later from people's memories, which is expensive, thin, and exactly what an assessor is trained to notice.

Accountability does not resolve to a person

Under existing regimes such as SM&CR a named individual is accountable for outcomes, and 'the system decided' is not a defence. Where the operating model has not mapped which agent decisions sit under whose accountability, the governance framework has a hole in exactly the place a regulator looks first.

Second line arrives at the end

Risk and compliance are brought in to review rather than to design, so they see a finished system and the only lever available is to block it. This is experienced as friction and is usually a sequencing failure rather than an obstruction.

How we approach it

5 moves, in order

  1. 01

    Inventory first, and treat it as real work

    Enumerate every AI system, including embedded vendor capability and tools bought outside procurement, before classifying anything. We scope this as a distinct piece of work rather than a precursor, because underestimating it is the most common reason a governance programme is late before it starts.

  2. 02

    Make risk and compliance co-authors, not reviewers

    Second line is in the room during operating-model design, defining the control points rather than assessing them afterwards. In our experience this is the single highest-leverage sequencing decision in a regulated agentic programme, and it costs nothing except being early.

  3. 03

    Map accountability onto people before deployment

    Every class of agent decision is mapped to a named accountable individual with matching authority, with the human-in-the-loop boundary defined by consequence and reversibility. This is the accountability mapping in our operating-model work, applied to the question a regulator will ask first.

  4. 04

    Generate evidence as a by-product

    Audit trails, evaluation results, approval records and change history are outputs of the delivery process rather than a separate documentation exercise. If producing the evidence requires a project, the evidence will be late and thin; if it falls out of how the work already runs, it is close to free.

  5. 05

    Govern it on a cadence

    Inventory, classification and post-market monitoring are reviewed on a fixed rhythm with named owners, in the same way as any other operating cadence. Governance that is reviewed annually describes an organisation that no longer exists.

Governance that is reviewed annually describes an organisation that no longer exists.
Ask a technical questionanswers from all 13 guides
Ask anything technical about AI governance and regulatory evidence and I will answer from this guide, and tell you first whether this is work we have delivered or an approach we would be taking.

Prefer to talk it through? Ask us on a discovery call →

Sources

Every source below was opened and read before it was attached. Where nothing survived that check, the claim on this page was softened rather than given a plausible-looking link.

EU AI Act, Article 113: entry into force and applicationThe original staged dates as enacted in Regulation (EU) 2024/1689: general application from 2 August 2026, Article 6(1) from 2 August 2027, Chapters I and II from 2 February 2025.European Parliament Think Tank, Digital Omnibus on AI: adoption in plenaryThe Parliament's own note that the Omnibus postpones the application of certain parts of the AI Act while keeping its core provisions and risk-based approach.Morgan Lewis, EU Approves Delays and Other Amendments to Certain EU AI Act Obligations (June 2026)Source of the new dates, 2 December 2027 and 2 August 2028, and of the caveat that until publication in the Official Journal the Act in its current form remains the law. A law firm note, not the legislation: check the Official Journal before relying on it.Gibson Dunn, EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changesSecond independent account of the same dates, and the source for what was already in force: prohibitions and AI literacy from 2 February 2025, general-purpose model obligations from 2 August 2025.FCA, the Senior Managers and Certification RegimeThe regime behind the accountability argument above: it exists to make individuals accountable for their conduct and competence, which is why 'the system decided' is not a defence.
engage via

Talk to us about AI governance and regulatory evidence.

A 30-minute call with James Rooney. We'll tell you honestly which parts of this we have done before and which we would be doing for the first time, and you'll leave with a rough scope either way.

most start with a fixed-price AI Readiness Audit · £44,000 · 4 weeks · working prototypes

// pick a slot · cal.com/tenhaw/professional-servicesLIVE CALENDAR

Calendar not loading? Open it on cal.com or email hello@tenhaw.com.

Questions this guide answers

When do the EU AI Act's high-risk obligations actually apply?

Later than the date most plans were written against, and the obligations themselves are unchanged. Article 113 originally set 2 August 2026 for stand-alone high-risk systems and 2 August 2027 for high-risk systems embedded in regulated products. The Digital Omnibus amendment, agreed between the Council and the Parliament in May 2026 and approved by the Parliament in June, moves those to 2 December 2027 and 2 August 2028 respectively. What has been in force since 2 February 2025 is the prohibited-practice list and the AI literacy duty, and the general-purpose model obligations have applied since 2 August 2025. For a high-risk system the obligations still include conformity assessment, technical documentation, risk management, data governance, human oversight, registration and post-market monitoring, so the practical implication has not moved either: a current inventory, a defensible classification of each system, and evidence generated by your process rather than assembled retrospectively. Tenhaw designs the operating model and delivery discipline that produce that evidence; we are not lawyers, formal legal interpretation should come from counsel, and you should check the dates against the Official Journal rather than against us.

The board wants an AI plan. What should actually be in it?

Five things, and they are all answerable in weeks rather than quarters. An inventory of the AI already running, including embedded vendor features and anything bought outside procurement, because a plan written before the count gets rewritten later. A classification of that inventory by consequence, so the board can see which systems carry real risk rather than a flat list. A named accountable individual per class of decision, which is the first thing a regulator tests and the first thing a board should. A sequence with dates, showing which processes go first and what evidence each one produces as a by-product of the work. And an honest statement of what you cannot yet evidence, because the plans that survive board scrutiny are the ones that name their own gaps before somebody else does. If a stalled pilot is what prompted the board to ask, say so, and say whether it stalled on evidence, on ownership or on the data underneath it, because those three need different money and different people.

Where do AI governance programmes usually go wrong?

Four places. The inventory takes far longer than planned because AI entered the organisation through tool purchases and embedded vendor features rather than one programme. Governance is written as policy rather than embedded in process, so evidence has to be reconstructed. Accountability does not resolve to a named person, which is the first thing a regulator tests. And second-line risk arrives to review a finished system rather than to co-design it, so their only available lever is to block.

How do you make agent decisions auditable?

By designing the audit trail into the workflow rather than adding logging afterwards: what the agent was asked, what it retrieved, which tools it called, what it decided, which human approved or overrode it, and against which version of the system. The test is whether you could reconstruct a specific decision from six months ago without asking anyone what happened.

Who is accountable when an AI agent makes a mistake?

A named individual, and that has to be established before deployment rather than after an incident. Under regimes such as SM&CR accountability cannot rest with a system. In practice this means mapping each class of agent decision to a person with matching authority, and defining explicitly which decisions require human approval based on how consequential and how reversible they are.

What should an AI inventory include, and why does it take so long?

Everything that behaves like AI in production, not just the systems a programme built: embedded vendor features, tools bought outside procurement, and anything adopted through individual initiative. It takes so long because AI rarely entered the organisation through one front door, so enumeration means going department by department rather than reading a project list. The inventory reliably takes three times as long as planned, so scope it as work rather than a precursor. Tenhaw's founder co-designed a target operating model across 500 teams at HSBC Global Payment Solutions, so the department-by-department pass is familiar ground. You cannot classify what you cannot enumerate. The effort pays for itself, because a governance plan written before the count is the one that gets quietly rewritten two quarters later.

Should risk and compliance review AI systems or help design them?

Help design them. The common failure is one of sequencing. Risk and compliance are brought in at the end to review a finished system, so the only lever left is to block it, which everyone then experiences as friction. Put them in the room during operating-model design, defining the control points rather than assessing them afterwards. In Tenhaw's experience this is the single highest-leverage sequencing decision in a regulated agentic programme, and it costs nothing except being early. Controls designed with the people who will have to defend them also change the evidence, producing records that hold up under assessment rather than documentation reconstructed after the fact.

The EU AI Act deadline moved. Should we pause our AI governance work?

No. The forcing function moved, it did not disappear, and treating the delay as an exemption is the most common thing to get wrong. The Digital Omnibus amendment postpones the stand-alone high-risk obligations to 2 December 2027 and product-embedded ones to 2 August 2028, but nothing about what a high-risk system must evidence has changed, from conformity assessment and technical documentation through to registration and post-market monitoring. The prohibitions and the AI literacy duty have been in force since February 2025, and the general-purpose model obligations since August 2025. Tenhaw's advice to clients whose plan assumed the old date is to spend the extra time on the inventory, the part that takes longest, not on waiting.

How often should AI governance be reviewed?

On a fixed rhythm with named owners, in the same way as any other operating cadence, and certainly more often than annually. Governance reviewed once a year describes an organisation that no longer exists, and three things need the cadence. The inventory, because new AI arrives continuously through vendor features and tool purchases rather than through a programme you control. The classification, because a system's consequence shifts as its scope and usage grow. And post-market monitoring, because the obligations on high-risk systems do not end at deployment. Run each review as a working session that updates the record, with a named owner per item, rather than a committee that receives a report.

What evidence should an AI governance programme produce?

Audit trails, evaluation results, approval records and change history, produced as outputs of the delivery process rather than as a separate documentation exercise. If producing the evidence requires a project of its own, it will be late and thin, and reconstructed documentation is exactly what an assessor is trained to notice. For a high-risk system under the EU AI Act the record needs to support conformity assessment, technical documentation, risk management, data governance, human oversight, registration and post-market monitoring. Build the requirement into how work actually flows, so the records accumulate as people deliver, and the evidence becomes close to free rather than assembled under deadline.

Is there an FCA AI governance framework we should be following?

There is no separate FCA AI rulebook, and the regulator has said it does not intend to write one. Tenhaw designs the operating model rather than the legal opinion, drawing on a decade of delivery inside regulated organisations including HSBC. Under the Senior Managers and Certification Regime, 'the system decided' is not a defence, so an FCA AI governance framework is the regimes you already answer to applied to AI, with individual accountability as its spine. It is four things: an inventory of the AI actually running, vendor features included; a classification of it by consequence; a named accountable individual for each class of agent decision, with matching authority and an approval boundary; and evidence generated by the delivery process rather than reconstructed for inspection.

Do we need a separate AI framework, or can we extend model risk governance?

Extend what you have, then close the three gaps it leaves. Scope is the first. Model risk governance sees models that went through a model lifecycle, while AI has arrived through tool purchases, embedded vendor features and individual initiative, so the inventory is built department by department, not read off a register. Accountability is the second, because agents act, and each class of agent decision needs a named individual with matching authority and a human-approval boundary set by consequence and reversibility. Evidence is the third, so audit trails, evaluation results, approval records and change history have to fall out of how work runs. Tenhaw publishes that method in full, and you are free to adopt it without hiring anyone.

Will an AI governance platform give us the evidence a regulator wants?

It will store evidence. It will not create it. What an assessor asks for is audit trails, evaluation results, approval records and change history for specific systems and specific decisions, and those are produced by how the work runs rather than by the tool that holds them. Buy a platform and change nothing about delivery and you have a tidy home for documentation reconstructed from people's memories, which is expensive, thin, and exactly what an assessor is trained to notice. Tenhaw sells no platform; its own engineering handbook is 72 rules on GitHub, enforced by an agent rather than filed. Get the requirement embedded in the workflow first, then choose somewhere to keep the output. The order matters more than the product does.

What does it cost to get AI governance in place?

It is usually bought one of two ways, and Tenhaw publishes both prices rather than quoting on request. If nobody has counted the estate yet, the AI Readiness Audit is the entry point at £44,000 fixed over four weeks, with the first two weeks spent inventorying what is actually in use across the business, sanctioned or not, and ending in working prototypes rather than a slide pack. If the direction is already clear and what you need is the operating model, accountability mapped onto named people and delivery that generates its own evidence, that is Agentic Design Team work at £35,000 to £55,000 a month for two senior people. The audit is standalone with no obligation to continue, and a recommendation to stop is a valid outcome.

How do you decide which AI systems count as high risk?

In two passes. First, a practical triage of your own, classifying the inventory by consequence so a board can see which systems could genuinely harm a customer, a colleague or the firm, rather than reading a flat list of everything running. Second, the legal test against the EU AI Act's own categories, which is where counsel earns the fee, because the classification has to be defensible to somebody else rather than comfortable for you. You cannot classify what you have not counted, so enumerate before either pass. And keep the classification as a live record, because a system that was low-consequence at pilot scale rarely stays that way.

Does ISO 42001 certification cover us for the EU AI Act?

No, because they answer different questions. ISO/IEC 42001 certifies that you run a management system for AI: policies, roles, controls and review. The EU AI Act asks what a particular system evidences, and for a high-risk system that means conformity assessment, technical documentation, risk management, data governance, human oversight, registration and post-market monitoring. The certificate is genuinely useful, because the disciplines overlap heavily and both want a current, defensible record, but it does not discharge a per-system obligation. Firms running 42001 properly tend to find the per-system work smaller rather than unnecessary, because the inventory, the classification and the review cadence already exist.

Will AI governance slow our delivery down?

Built into the work it costs very little, and bolted on afterwards it costs a great deal. The expensive version is a policy saying agent decisions must be auditable while nothing in the workflow changes, so the records get assembled under deadline from memory. Where the audit trail, the evaluation results and the approval record are outputs of the delivery process, they accumulate while the team works. Tenhaw's work at Globelynx cut lead time by 60% inside six months, which is the direction disciplined delivery moves in. What people usually mean when they say governance slowed them down is second line arriving to review a finished build, with blocking as the only lever left. That is a sequencing failure rather than a control problem.

Do we need a law firm or a delivery partner for AI governance?

Usually both, doing different jobs. A law firm tells you how the EU AI Act and your own regulator's rules apply to your systems: the formal interpretation, the classification you can defend, the contractual position with vendors. That is not Tenhaw. It is not a law firm and it does not give legal advice. What Tenhaw designs is the operating model and the delivery discipline that produce the evidence your legal and risk functions need, which is the part no legal opinion delivers: the inventory, accountability mapped onto named people, and audit trails and approval records generated as a by-product of the work rather than assembled under deadline.