Pattern guide

AI governance and regulatory evidence

Building the evidence as a by-product of the work, rather than assembling it under deadline.

ways these programmes stall
4
steps in how we would address it
5
questions answered in full
5
In one paragraph

AI governance for regulated organisations means maintaining a defensible, current record of what AI systems exist, what they do, who is accountable, how risk was assessed and how that is evidenced, against frameworks including the EU AI Act, ISO/IEC 42001 and existing model risk governance. The EU AI Act's obligations for stand-alone high-risk systems were originally due to apply from 2 August 2026. An amendment approved by the European Parliament in June 2026 moves that to 2 December 2027, and to 2 August 2028 for high-risk systems embedded in regulated products. The prohibitions and the AI literacy duty have applied since 2 February 2025 and the general-purpose model obligations since 2 August 2025, so the extra time buys preparation rather than exemption, and the inventory is still the part that takes longest.

James Rooney, Founder

Updated

Our approach

We have not delivered this at enterprise scale, and here is exactly what we are drawing on

This is how we would approach it, grounded in a decade of delivery inside regulated organisations including HSBC, not a write-up of an EU AI Act conformity programme we have completed. We are not a law firm and we do not give legal advice; we design the operating model and the delivery discipline that produces the evidence your legal and risk functions need. Where you need formal legal interpretation, we will say so and work alongside whoever provides it.

Why this matters now

The forcing function moved and did not disappear, which is the most common thing to get wrong about this. Article 113 of the EU AI Act set 2 August 2026 as the general application date, with product-embedded high-risk systems following in August 2027. The Digital Omnibus amendment, agreed in May 2026 and approved by the European Parliament in June, postpones stand-alone high-risk obligations to 2 December 2027 and product-embedded ones to 2 August 2028. Nothing about what a high-risk system has to evidence changed: conformity assessment, technical documentation, risk management, data governance, human oversight, registration and post-market monitoring. If your plan assumed August 2026 you have more time than you thought, and if your plan assumed the obligations went away, it did not.

Ask a technical questionanswers from all 12 guides
Ask anything technical about ai governance and regulatory evidence and I will answer from this guide, and tell you first whether this is work we have delivered or an approach we would be taking.

Prefer to talk it through? Ask us on a discovery call →

Diagnosis

Where these programmes actually stall

Not the risks a vendor lists. The ones that stop the work.

01

The board wants an AI plan, and nobody can list the AI already running

The inventory is the first deliverable and the one that reliably takes three times as long as planned, because AI has entered the organisation through tool purchases, embedded vendor features and individual initiative rather than through a single programme. You cannot classify what you cannot enumerate, and you cannot write a credible plan for a board on top of an estate nobody has counted. Plans written before the count are the ones that get quietly rewritten two quarters later.

02

Governance is written as policy, not as process

A policy that says agent decisions must be auditable does not make them auditable. Where the requirement is not embedded in how work actually flows, evidence has to be reconstructed later from people's memories, which is expensive, thin, and exactly what an assessor is trained to notice.

03

Accountability does not resolve to a person

Under existing regimes such as SM&CR a named individual is accountable for outcomes, and 'the system decided' is not a defence. Where the operating model has not mapped which agent decisions sit under whose accountability, the governance framework has a hole in exactly the place a regulator looks first.

04

Second line arrives at the end

Risk and compliance are brought in to review rather than to design, so they see a finished system and the only lever available is to block it. This is experienced as friction and is usually a sequencing failure rather than an obstruction.

Prescription

How we would address it

Grounded in The Tenhaw Way and the engagements written up in our case studies.

  1. 01

    Inventory first, and treat it as real work

    Enumerate every AI system, including embedded vendor capability and tools bought outside procurement, before classifying anything. We scope this as a distinct piece of work rather than a precursor, because underestimating it is the most common reason a governance programme is late before it starts.

  2. 02

    Make risk and compliance co-authors, not reviewers

    Second line is in the room during operating-model design, defining the control points rather than assessing them afterwards. In our experience this is the single highest-leverage sequencing decision in a regulated agentic programme, and it costs nothing except being early.

  3. 03

    Map accountability onto people before deployment

    Every class of agent decision is mapped to a named accountable individual with matching authority, with the human-in-the-loop boundary defined by consequence and reversibility. This is the accountability mapping in our operating-model work, applied to the question a regulator will ask first.

  4. 04

    Generate evidence as a by-product

    Audit trails, evaluation results, approval records and change history are outputs of the delivery process rather than a separate documentation exercise. If producing the evidence requires a project, the evidence will be late and thin; if it falls out of how the work already runs, it is close to free.

  5. 05

    Govern it on a cadence

    Inventory, classification and post-market monitoring are reviewed on a fixed rhythm with named owners, in the same way as any other operating cadence. Governance that is reviewed annually describes an organisation that no longer exists.

Governance that is reviewed annually describes an organisation that no longer exists.
Where this usually starts

Agentic Design Team

A pair who design the agentic systems, and the infrastructure to run them at scale. £35k–£55k / month · 2–4 months.

What that engagement covers

AI governance and regulatory evidence: your questions

When do the EU AI Act's high-risk obligations actually apply?

Later than the date most plans were written against, and the obligations themselves are unchanged. Article 113 originally set 2 August 2026 for stand-alone high-risk systems and 2 August 2027 for high-risk systems embedded in regulated products. The Digital Omnibus amendment, agreed between the Council and the Parliament in May 2026 and approved by the Parliament in June, moves those to 2 December 2027 and 2 August 2028 respectively. What has been in force since 2 February 2025 is the prohibited-practice list and the AI literacy duty, and the general-purpose model obligations have applied since 2 August 2025. For a high-risk system the obligations still include conformity assessment, technical documentation, risk management, data governance, human oversight, registration and post-market monitoring, so the practical implication has not moved either: a current inventory, a defensible classification of each system, and evidence generated by your process rather than assembled retrospectively. Tenhaw designs the operating model and delivery discipline that produce that evidence; we are not lawyers, formal legal interpretation should come from counsel, and you should check the dates against the Official Journal rather than against us.

The board wants an AI plan. What should actually be in it?

Five things, and they are all answerable in weeks rather than quarters. An inventory of the AI already running, including embedded vendor features and anything bought outside procurement, because a plan written before the count gets rewritten later. A classification of that inventory by consequence, so the board can see which systems carry real risk rather than a flat list. A named accountable individual per class of decision, which is the first thing a regulator tests and the first thing a board should. A sequence with dates, showing which processes go first and what evidence each one produces as a by-product of the work. And an honest statement of what you cannot yet evidence, because the plans that survive board scrutiny are the ones that name their own gaps before somebody else does. If a stalled pilot is what prompted the board to ask, say so, and say whether it stalled on evidence, on ownership or on the data underneath it, because those three need different money and different people.

Where do AI governance programmes usually go wrong?

Four places. The inventory takes far longer than planned because AI entered the organisation through tool purchases and embedded vendor features rather than one programme. Governance is written as policy rather than embedded in process, so evidence has to be reconstructed. Accountability does not resolve to a named person, which is the first thing a regulator tests. And second-line risk arrives to review a finished system rather than to co-design it, so their only available lever is to block.

How do you make agent decisions auditable?

By designing the audit trail into the workflow rather than adding logging afterwards: what the agent was asked, what it retrieved, which tools it called, what it decided, which human approved or overrode it, and against which version of the system. The test is whether you could reconstruct a specific decision from six months ago without asking anyone what happened.

Who is accountable when an AI agent makes a mistake?

A named individual, and that has to be established before deployment rather than after an incident. Under regimes such as SM&CR accountability cannot rest with a system. In practice this means mapping each class of agent decision to a person with matching authority, and defining explicitly which decisions require human approval based on how consequential and how reversible they are.

Sources

Where the checkable claims came from

Every source below was opened and read before it was attached. Where nothing survived that check, the claim on this page was softened rather than given a plausible-looking link.

  1. 01
    EU AI Act, Article 113: entry into force and application

    The original staged dates as enacted in Regulation (EU) 2024/1689: general application from 2 August 2026, Article 6(1) from 2 August 2027, Chapters I and II from 2 February 2025.

  2. 02
    European Parliament Think Tank, Digital Omnibus on AI: adoption in plenary

    The Parliament's own note that the Omnibus postpones the application of certain parts of the AI Act while keeping its core provisions and risk-based approach.

  3. 03
    Morgan Lewis, EU Approves Delays and Other Amendments to Certain EU AI Act Obligations (June 2026)

    Source of the new dates, 2 December 2027 and 2 August 2028, and of the caveat that until publication in the Official Journal the Act in its current form remains the law. A law firm note, not the legislation: check the Official Journal before relying on it.

  4. 04
    Gibson Dunn, EU AI Act Omnibus Agreement: postponed high-risk deadlines and other key changes

    Second independent account of the same dates, and the source for what was already in force: prohibitions and AI literacy from 2 February 2025, general-purpose model obligations from 2 August 2025.

  5. 05
    FCA, the Senior Managers and Certification Regime

    The regime behind the accountability argument above: it exists to make individuals accountable for their conduct and competence, which is why 'the system decided' is not a defence.

Talk to us about ai governance and regulatory evidence.

A 30-minute call with James Rooney. We'll tell you honestly which parts of this we have done before and which we would be doing for the first time, and you'll leave with a rough scope either way.

30 minutesWith James personallyNo obligation

Most organisations start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks