Service — AI Governance and Compliance
AI Governance and Regulatory Compliance
We help public sector organisations implement robust AI governance frameworks aligned to EU AI Act, NIST AI RMF, and ISO 42001. Our open-source governance platform provides 48 tools for risk classification, bias auditing, compliance monitoring, and audit-ready reporting. We are Cyber Essentials certified and hold ISO 27001-aligned information security controls.
What We Deliver
"EU AI Act compliance is not a compliance exercise — it is a governance design challenge. The organisations that get it right will have a structural advantage in public sector AI procurement."
— Dr Stylianos Kampakis, Managing Director, Tesseract Academy
AI governance is now a legal obligation, not an optional enhancement. Regulation (EU) 2024/1689 (the EU AI Act) — the world's first comprehensive AI law — classifies AI systems by risk level and imposes mandatory requirements for high-risk systems, including algorithmic impact assessments, human-in-the-loop controls, bias monitoring, and technical documentation. For UK public sector bodies procuring or developing AI systems that interact with EU citizens or are placed in EU markets, compliance is mandatory. UK government guidance on algorithmic transparency and the ICO's Explaining Decisions Made with AI create parallel obligations under UK law.
Tesseract Academy delivers end-to-end AI governance programmes covering the full compliance lifecycle. We begin with a risk classification assessment — mapping AI systems against EU AI Act Annex III categories and NIST AI RMF risk dimensions — and produce a governance roadmap with prioritised remediation actions. We then support implementation of algorithmic transparency disclosures aligned to the UK AI Framework, bias audit protocols, Data Protection Impact Assessments (DPIAs), and human-in-the-loop control design. The Department for Science Innovation and Technology (DSIT) and the UK AI Safety Institute set the policy context within which our governance programmes operate.
Our open-source AI governance platform (open-governance, available on GitHub) provides 48 governance tools covering automated risk classification, compliance matrices against EU AI Act, NIST AI RMF, and ISO 42001, bias and hallucination monitoring, policy enforcement gates, and audit-ready reporting. The platform is designed for public sector use and can be self-hosted to avoid data leaving organisational boundaries — an important consideration for systems handling personal or classified information. The Alan Turing Institute and NESTA have both called for open, auditable governance tooling of precisely this kind; our platform directly responds to those recommendations. Crown Commercial Service (CCS) and Cabinet Office procurement teams have engaged with this tooling as a reference implementation for algorithmic transparency.
We contributed expert analysis to the Financial Conduct Authority's consultation on stablecoin regulation in 2025, demonstrating our capability to engage at the frontier of AI and financial technology regulation. We are Cyber Essentials certified and operate ISO 27001-aligned information security controls, meeting the security baseline required for contracts involving personal data or government OFFICIAL classification. Our services are procurable via Crown Commercial Service (CCS) RM6200, and NHS England, HM Treasury, and Office for National Statistics (ONS) clients can access our governance services through standard framework routes.
Service Comparison
| Capability | Tesseract Academy | Legal / Compliance Firm | Large Technology Vendor |
|---|---|---|---|
| EU AI Act compliance | Technical + regulatory — integrated | Legal framing — limited technical depth | Own product focus — not independent |
| Bias auditing | Statistical bias testing across demographics | Policy review only | Proprietary tools — limited transparency |
| Open-source tooling | 48 tools — self-hostable, auditable | Not offered | Proprietary SaaS — data leaves org |
| NIST AI RMF alignment | Govern, Map, Measure, Manage — all four functions | Awareness only | Partial — product-centric mapping |
| Cyber Essentials certification | Certified | Varies | Typically ISO 27001 only |
| Regulatory consultation experience | FCA stablecoin consultation — 2025 | Yes — legal submissions | Lobbying — not independent analysis |
Frameworks We Implement
EU AI Act
Risk classification, Annex III high-risk assessment, conformity assessment preparation, technical documentation, algorithmic transparency disclosures, and human oversight design under Regulation (EU) 2024/1689.
NIST AI RMF
Full implementation across all four functions: Govern (policies, culture, accountability), Map (risk identification), Measure (testing, monitoring), and Manage (risk response, continual improvement).
ISO 42001
AI management system design, gap analysis against the 2023 standard, implementation roadmap, internal audit preparation, and integration with existing ISO 27001 information security management systems.
Bias Auditing
Systematic statistical testing of AI model performance across demographic groups (age, gender, ethnicity, disability status). Bias audit reports suitable for submission to public sector clients and inclusion in algorithmic transparency returns.
DPIA and AIA
Data Protection Impact Assessments (DPIA) required under UK GDPR for high-risk processing, and Algorithmic Impact Assessments (AIA) required for high-risk AI systems. Both delivered to ICO-compliant standards.
Cyber Essentials
Tesseract Academy is Cyber Essentials certified, meeting the UK government baseline for information security. We can advise public sector bodies and suppliers on achieving Cyber Essentials or Cyber Essentials Plus certification.
Case Studies
Open-Source AI Governance Platform
48 Governance Tools Across EU AI Act, NIST AI RMF, and ISO 42001
We developed and maintain an open-source AI governance platform (open-governance, available on GitHub under fabio-rovai/open-governance) that helps organisations discover, assess, and monitor AI systems against major governance frameworks. The platform provides automated risk classification, compliance matrices, bias and hallucination monitoring, policy enforcement gates, and audit-ready reporting through 48 governance tools. It is self-hostable, enabling public sector organisations to use it without sending data outside their network boundaries.
48
Governance tools in the platform
3
Frameworks: EU AI Act, NIST, ISO 42001
Self-host
Data stays within your network
Financial Conduct Authority — Stablecoin Consultation Response
Expert Regulatory Analysis for FCA Consultation on Crypto Asset Oversight
In 2025, Tesseract Academy contributed expert analysis to the FCA's consultation on stablecoin regulation and the future of crypto asset oversight in the UK. Our submission provided evidence-based commentary on regulatory framework design, consumer protection mechanisms for stablecoin holders, and systemic risk considerations for digital assets. This engagement demonstrates our capability to operate at the intersection of AI, financial technology, and regulatory compliance.
FCA
Official regulatory consultation
2025
Stablecoin regulation response
FinTech
AI and financial regulation intersection
How to Commission This Service
AI governance and compliance services can be commissioned through:
- 1
CCS RM6200 — Management Consultancy Three
The primary route for AI governance strategy, compliance programme design, and regulatory advisory. Covers EU AI Act compliance assessments, NIST AI RMF implementation, and ISO 42001 gap analysis.
- 2
Direct Award (below £10,000)
Rapid bias audits, DPIA reviews, algorithmic transparency disclosures, and governance platform demonstrations can be commissioned directly for contracts below threshold.
- 3
Embedded Governance (within AI delivery)
All Tesseract Academy AI consulting engagements include governance as a default component — bias auditing, DPIA, and AIA are integrated into every ML and LLM delivery engagement at no additional procurement step.
To discuss your AI governance requirement or request a platform demonstration, contact fabio@thetesseractacademy.com. We will provide a free initial risk classification assessment within five working days.
