Acuity AI Advisory

Governance · Updated June 2026

AI Governance Advisory

Acuity is an independent AI governance consultancy working with Irish boards, regulated firms and state bodies. AI governance is the set of policies, accountability structures, and risk controls that determine how AI is used and held to account in your organisation. We build ISO/IEC 42001-aligned governance frameworks and deploy them — typically operational within four to six weeks, fixed fee. Ireland's AI Office takes up its enforcement powers on 1 August 2026.

Ungoverned AI creates regulatory exposure, reputational risk, and operational fragility. Governed AI outperforms it on every dimension that matters. The difference is not the quality of the policy document — it is whether the accountability structures are actually in place and working.

Ger Perdisatt presenting at Danske Bank

ISO/IEC 42001:2023 — Lead Auditor certified

Acuity governance frameworks are aligned to ISO/IEC 42001:2023, the international management system standard for AI. Lead Auditor certification independently verified by Mastermind Assurance. What that means in practice →

Most organisations don't know what AI they're running. Governance starts there.

When AI governance fails, it's rarely because the policies were wrong. It's because no one knew which systems were in use, who owned them, or what decisions they were making. The diagnostic work almost always precedes the governance work.

Scope

What AI governance means in practice

An AI governance engagement with Acuity starts with how your organisation actually uses AI — not with a generic framework applied from the outside. We map what is in use, identify the risks and obligations that apply, build the accountability structures and policies that hold, and deploy them. The output is operational infrastructure, not a shelf document.

What gets built and deployed

AI use inventory across the organisation
Risk classification against EU AI Act categories
Accountability structures — who owns what, at what level
Oversight policies and escalation mechanisms
Tool assessment process for AI before deployment
Board-level and operational-level governance addressed together
Regulatory alignment across EU AI Act, GDPR, and sector-specific obligations (DORA where applicable)

Regulation

Why this matters now

Ireland's AI Office reached its statutory opening date on 1 August 2026. Prohibited AI practices and the Article 4 AI literacy obligation are enforceable now. High-risk conformity deadlines were extended by the EU Digital Omnibus to 2 December 2027 (standalone) and 2 August 2028 (regulated products) — but for organisations deploying high-risk AI in HR decisions, credit, insurance, and customer-facing automated processes, documented governance is a legal obligation, not best practice, and the inventory and policy work cannot wait until then.

Boards and executives are being asked to sign off on AI systems without the frameworks to evaluate them. Organisations that build governance now are separating themselves from those that will be forced to retrofit it later under regulatory pressure.

AI Office of Ireland — 1 August 2026. Enforcement powers active. High-risk AI systems require documented governance and oversight. The time to build the framework is before the inspection, not after.

€560k
Margin recovered in seven days
Food distributor — existing systems, no new software
85%
Reporting time reduction
Finance team — 39 hrs monthly to 3–5 hrs
1,525
Automatable hours identified per year
Professional services firm — revenue debt recovery

Proof

What this has looked like in practice

Energy investment firm

Three business functions, no consistent governance, two days of monthly manual effort to produce the management board report. Acuity ran five stakeholder sessions under Chatham House rules, ran governance and opportunity assessment in parallel, redesigned the reporting cycle, and delivered a full governance framework — AI policy, three-stage tool assessment toolkit, regulatory alignment across EU AI Act, DORA, and GDPR — operational within four weeks.

Newly-established state regulator

Seventeen people, no CIO, hard statutory deadline (compulsory information powers from December 2026). Adversarial risk was the real concern: submissions engineered to exhaust processing capacity. Acuity designed and delivered a full board and senior leadership session, stress-tested a 2027 enforcement scenario in the room, and produced three frameworks — all adversarially tested through competing AI systems before delivery. Three frameworks adopted into the IoD Ireland national director education programme.

PRA/FCA-regulated Nordic bank

Six intelligence gaps mapped, single architecture designed to address all of them. Head of Communications: “You couldn’t have done better. Absolutely nailed it.”

See all case studies →

Your consultant

Who you actually work with

Ger Perdisatt

AI Governance Consultant · Founder, Acuity AI Advisory

Acuity is not a pyramid. The person who scopes your governance engagement is the person who runs the board session and writes the framework. That is a deliberate constraint on how many engagements run at once, and it is the reason the work lands at board level rather than stalling in a project team.

The perspective is operator-first. Governance designed by someone who has carried a P&L and sat on a board looks different from governance designed by someone who has only audited one — it survives the question “what does this cost us to run?” Full background →

Credentials

Former Chief Operating Officer, Microsoft Western Europe
Non-Executive Director, Dublin Airport Authority — €5bn capital programme
Non-Executive Director, Tailte Éireann
ISO/IEC 42001:2023 Lead Auditor — independently certified by Mastermind Assurance
Governance frameworks adopted into the IoD Ireland national director education programme
Based in Dublin — engagements delivered in person

Questions

Common questions

What is an AI governance framework?

An AI governance framework is the set of policies, accountability structures, oversight mechanisms, and risk controls that determine how AI is used, monitored, and held to account within an organisation. It covers who is responsible for AI decisions, how AI systems are reviewed before deployment, what happens when AI causes harm, and how compliance is maintained. A governance framework is not a one-off document — it is operational infrastructure. Acuity builds it and deploys it. The engagement ends when it is working, not when the document is filed.

What does an AI governance consultant actually do?

An AI governance consultant establishes who is accountable for AI decisions in your organisation and builds the structures that make that accountability real. In practice that means four things: inventorying the AI already in use (most organisations cannot produce this list), classifying each system against EU AI Act risk categories, designing the oversight and escalation mechanisms that match your regulatory exposure, and deploying them so they survive contact with the business. The distinction that matters when choosing one is whether they hand you a document or leave you with working infrastructure. Acuity's engagements end when the framework is operational — typically four to six weeks — not when the policy is filed. Independence matters too: a consultant who also sells you the AI systems they are governing has a conflict at the point where governance should bite.

Do Irish companies legally need an AI governance policy?

For organisations deploying high-risk AI systems — which includes AI in HR, credit decisioning, insurance, and customer-facing automated decisions — a governance policy is a legal obligation under the EU AI Act. Ireland's AI Office reached its statutory opening date on 1 August 2026 and prohibited practices and AI literacy obligations are already enforceable. The high-risk conformity deadlines were extended by the EU Digital Omnibus to 2 December 2027 (standalone) and 2 August 2028 (regulated products) — but the inventory, governance and AI literacy work needs to be done well before any of those dates. For lower-risk AI use, governance is a significant liability and reputational safeguard. The practical question is not whether to have governance — it is whether yours will hold up when tested.

How long does an AI governance review take?

A structured governance review typically runs four to six weeks from initial diagnostic to a deployed governance framework. The NTR engagement — three business functions, full framework including policy, tool assessment toolkit, and regulatory alignment — was operational within four weeks. Timeline depends on the complexity of your AI use and the number of systems in scope.

Can you build a governance framework for a non-technical organisation?

Yes — and most of our clients are non-technical organisations. Professional services firms, financial institutions, state bodies, regulated entities. Governance frameworks are built around your actual operations. The language, structures, and accountability mechanisms are designed for the people who will use them. Technical understanding is not a prerequisite.

Does my board need a dedicated AI governance committee?

For organisations with significant AI deployment, regulated sector status, or active AI development, a dedicated sub-committee of the audit and risk committee — quarterly, with defined terms of reference — is the minimum structure that provides credible governance evidence. For organisations with modest, low-risk AI use, a structured AI agenda item on the audit committee may be sufficient, provided the minutes reflect genuine challenge rather than a management update.

Preview of AI Governance Policy Template

Free download

AI Governance Policy Template

Seven sections covering what an AI governance policy has to account for: system inventory, risk classification, accountability, and review schedules. Written to be edited rather than adopted as is, so you can see the shape of the thing before deciding whether you want help building your own.

No spam. Unsubscribe at any time.

Request an AI Governance Assessment

A structured conversation about your current AI use, your regulatory exposure, and what governance would actually look like for your organisation.