First, some honesty

What we will never claim, and why that should reassure you.

Plenty of consultants will happily tell you they can make you "compliant". Be careful with that word. Formal certification against standards like ISO 42001 can only be issued by accredited bodies, and anyone who implies otherwise is telling you something about how they work.

So here is our position, in writing: we align you to the frameworks and get you into a genuinely healthy position. We do not sign you off as compliant, because we are not a certification body. If your firm needs that formal final step, we introduce you to a qualified associate of Safer Haven who takes you the rest of the way, with all the groundwork already done and paid for once, not twice.

What we align you to

Three frameworks, one coherent structure

These are the three reference points that matter for AI governance right now. They overlap heavily, which is good news: one properly built framework can serve all three.

01

ISO 42001

The international standard for AI management systems. It asks the questions a good manager would ask anyway: who is accountable, what could go wrong, how do you know, and what happens when it does. We build your policies, registers and review cycles around its pillars.

02

NIST AI Risk Management Framework

The American framework that has quietly become the global common language for AI risk: govern, map, measure, manage. Insurers and larger clients increasingly recognise it, which makes it a useful spine for your documentation.

03

The EU AI Act

The one with legal teeth. Risk categories, prohibited uses, and the Article 4 duty to keep your staff AI literate. We map your AI use against its requirements so you know exactly where you stand and what is coming as enforcement rolls out.

What we build with you

A framework people actually follow

The worst governance document in the world is the perfect one nobody reads. Everything we write is built around your real workflows and trained into your team, so it lives in the business rather than in a drawer.

  • An AI policy written in your firm's voice, covering the tools your people actually use.
  • An AI register with named accountability, so every tool has an owner.
  • Approval routes for new tools, so "can I use this?" has a fast, clear answer.
  • A review cycle that keeps pace as the rules and the tools change.
  • An evidence pack: the paper trail for insurers, regulators, clients and, if you go for certification, the auditor.

If you want certification

A healthy position first. Certification second, if you need it.

For most firms, a genuinely healthy governance position is the destination: your clients reassured, your insurer satisfied, your staff clear on the rules. For some, a formal certificate matters, usually because a large client or tender demands it.

When that is you, our qualified associate picks up exactly where we finish. No starting again, no re-explaining your business to a stranger, no paying twice for the same discovery work. It is the same path either way; certification is simply the optional last mile.

Free · 5 minutes · Instant result

Not ready to talk? Find out where you stand first.

Eighteen questions across risk, people, governance and cybersecurity. Answer honestly and you get an instant AI readiness score, the specific gaps most likely to cost you, and clear next steps built around your answers.

Start the free risk check

No obligation. Seen only by us, never shared.

Find out what a healthy position looks like for your firm.

Thirty minutes, free, and you will know exactly where your governance gaps are and what closing them involves.

Book a free intro call

Governance usually starts with an AI Risk Assessment. If you have not had one, start there.