An elephant standing in an empty boardroom, the AI risk nobody in the business is naming
AI Risk & Compliance · Greater Manchester

Know exactly where you stand.
Prove it when asked.

A clear view of your obligations under the EU AI Act and UK GDPR, and the guardrails to meet them. We work with firms across Greater Manchester and the North West, from those answerable to the SRA, the FCA or the ICO, to any business that handles client data.

Book a free intro call
5★ Google Rated
2.0 → 4.3 AI knowledge score in one session
+64 NPS from training attendees
CPD Certified

In short

Nobody wants to teach this one. There is little payoff in it for the consultant and the legislation is genuinely dull.

That is exactly why it gets skipped, and it is one of the most important things a leadership team can get right before AI use spreads any further through the organisation.

Let me be straight about scope. I am not a qualified compliance officer and I will never pretend to be one in front of your team. What I do is risk assess your organisation, inventory those risks against the workflows your people actually use, work with you on a safe AI usage policy, cover Token Economics, meaning what these tools really cost to run once a team uses them properly, and give you factual, current information on UK GDPR and data protection.

That extends to the EU AI Act, which a lot of UK businesses have written off because of the first two letters. Major provisions come into force on 2 August, and plenty of firms who assumed it was somebody else's problem are going to find they are in scope.

We finish on hallucination, bias, citation failures and sycophancy, where the model simply agrees with whatever you put in front of it, and what governance realistically looks like at your size. That might mean NIST alignment. It might mean ISO 42001. It might mean neither.

My network includes the specialists needed to take this further. They get brought in when the work genuinely calls for it, never by default.

AI regulation is here. This is what it costs to get it wrong.

71%

Using AI you never approved

Your team is already using tools you have not sanctioned. That is a data breach waiting to happen.

79%

Feel exposed using AI at work

The EU AI Act makes staff training mandatory. The UK will follow. Most organisations are not ready.

35,000,000

The ceiling for getting it badly wrong

The EU AI Act's highest fines, up to €35m or 7% of global turnover, are reserved for prohibited AI practices. Everyday misuse sits far below that ceiling, but it is the same law, and knowing where your firm stands on it is the whole point of an assessment.

£17,500,000

The fine is rarely the worst part

The ICO can fine up to £17.5m or 4% of global turnover for the most serious UK GDPR breaches. For most firms the real damage is smaller and closer to home: the client who leaves, the insurer who asks questions, the reputation that took years to build.

What it is

A clear view of your obligations, and the guardrails to meet them.

AI Risk & Compliance covers the whole picture in one engagement: the EU AI Act, UK GDPR, AI risk, bias and hallucinations, how to spot them and how to manage them. Everything we build aligns with the core principles of ISO 42001, the international standard for AI management systems, and the NIST AI Risk Management Framework, the American framework that has quietly become the global common language for AI risk.

It starts with a proper assessment. In almost every business we visit, AI use is bigger than the leadership thinks. The marketing manager has a ChatGPT habit. A fee earner found a summarising tool. Someone switched on Copilot because it appeared in the ribbon one morning. None of it was signed off, none of it is written down anywhere, and every bit of it carries your firm's name and your clients' data. The gap between what leadership believes and what is actually happening is the single biggest AI risk in most organisations. This work closes it.

First, some honesty

What we will never claim, and why that should reassure you.

Plenty of consultants will happily tell you they can make you "compliant". Be careful with that word. ISO 42001 certification can only be issued by an accredited third-party auditor working to ISO/IEC 42006. The NIST framework is voluntary and has no certification mechanism at all: an organisation can be aligned with it, but nobody on earth can certify you against it.

So here is our position, in writing: Safer Haven aligns your organisation to the core principles of these frameworks. We do not issue certifications or compliance sign-off, because we are not a certification body. If your firm needs that formal final step, we introduce you to a qualified associate who takes you the rest of the way, with all the groundwork already done and paid for once, not twice.

Why it matters

One incident. Two enforcement regimes.

An AI-related data breach does not stop at the ICO. For the most serious UK GDPR breaches, the ICO can fine up to £17.5m or 4% of global turnover. If the same incident touches the EU AI Act, a second regime applies on top: its highest fines reach €35m or 7% of global turnover for prohibited practices. Two regulators, two fine structures, one mistake.

Those are the ceilings, and most firms will never go near them. The real damage is usually smaller and closer to home: the client who quietly moves their files elsewhere, the insurer who asks questions at renewal you cannot answer, the reputation that took 20 years to build and one screenshot to dent. Compliance work is not really about avoiding the headline fine. It is about being able to answer the client-data question without flinching.

The programme

Single full day, or modular sessions.

A practical programme covering the regulatory landscape, data protection obligations, and the real-world fines organisations face when they get AI wrong. It covers what the law actually requires, where the enforcement happens, and how to build systems that protect both your organisation and your people.

01

Spotting Hallucinations, Bias and Fake Citations

AI systems generate convincing lies. This session covers how hallucinations happen, where bias enters the system, and what fake citations look like in practice, along with the systems and processes you can put in place to catch these before they damage client relationships or expose your organisation to liability.

02

Data Compliance and GDPR

What GDPR actually requires when you use AI. ICO scope, enforcement, and the fines that have already landed on organisations that got this wrong. The practical question: if you are using consumer tools like ChatGPT, where is your data going, what happens to it, and does it break any laws? For enterprise tools, how to maintain data sovereignty and keep your information under your control.

03

Protecting Organisational IP in the Age of AI

Your proprietary workflows, client information and strategic thinking can all end up in an AI model's training data if you are not careful. This covers what you should and should not share with any AI tool, and how to structure your use so you keep what matters to you.

04

The EU AI Act

Scope, enforcement, and the fines. The specific articles UK companies need to be aware of now, and why this matters even if you are not in the EU.

05

AI Governance

DPA, DPIA, AUP, risk assessment and tool inventory: the documentation and processes that prove you have done your due diligence.

06

What Ongoing Support Looks Like

A clear picture of what governance and oversight should look like in your organisation, how alignment to ISO 42001 or NIST AI RMF standards is smart, and how we can support you beyond the training day.

The session ends with Q&A.

How it works

Built with your people, in your building

We do this with the stakeholders who know the business best. The practice manager who knows every process. The senior administrator everyone actually goes to with questions. The IT lead who knows what is installed. They know how work really gets done, which is often quite different from how the org chart says it gets done.

01

Workflow walkthrough

We sit with your key people and walk through how work actually flows: where data enters, who touches it, which tools are involved and where AI has quietly crept in. People tell us things in these sessions they had never thought to mention to anyone.

02

The AI risk inventory

Every tool, every use, every data flow goes into a single inventory. Sanctioned and unsanctioned alike. This becomes a living document your firm owns, not a report that gathers dust in a drawer.

03

Regulatory mapping

Each entry is mapped against the rules your firm answers to: UK GDPR, your sector regulator's expectations, and the EU AI Act's risk categories, including the Article 4 duty on staff AI literacy. You see exactly which obligations each use touches.

04

Guardrails that hold

Then we build what the findings call for: an AI policy written in your firm's voice, an AI register with named accountability, approval routes so "can I use this?" has a fast clear answer, and a review cycle that keeps pace as the rules and the tools change.

Regulated sectors

Built around your regulator, not around ours

For law firms and conveyancers, the work maps against SRA obligations and COLP accountability. For FCA-regulated firms, it leads with the questions compliance is already asking: which tools touch client data, what has gone into them, and what record exists if anyone asks. For everyone, the ICO and UK GDPR set the floor.

The outcome

Documents that earn their keep

You know exactly where you stand, the policies and guardrails are in place, and when a client asks how their data is handled when your team uses AI, you have the answer in writing.

  • A complete AI risk inventory covering every tool and use across the business.
  • An exposure map tied to your specific regulatory obligations and the EU AI Act.
  • An AI policy, register and approval routes your people actually follow.
  • A prioritised action list: what needs attention now, soon and eventually.
  • An evidence pack for insurers, regulators, clients and, if you ever go for certification, the auditor.

Where this fits

One of three pillars

New to AI? Start with AI Enablement and get your team using the tools well before you formalise the rules around them.

Policy on paper is not enough if your people do not trust the tools. See The Human Risk of AI for the human side: confidence, over-trust and burnout.

Free · No sign-up · Instant

Put a number on what this work is worth.

Compliance is easier to justify to a board when you can show the maths. The calculator works out the exposure you avoid alongside the hours your team gets back, using your figures rather than ours.

Open the ROI calculator

Nothing is stored or sent anywhere. The numbers stay on your screen.

Pricing

Clear prices, from the first conversation.

Priced on the work, never per head. The free intro call tells us which route fits your firm.

Programme Price

One-off compliance session

The assessment, the regulatory mapping and the findings in plain English, with a prioritised action list your firm owns.

from £1,495

Ongoing compliance retainer

Support from A to Z: your acceptable use policy, data processing agreements with your AI vendors, data protection impact assessments when new tools arrive, and liaising with your IT team on the correct licence tiers. Availability is capped so response times hold up.

from £2,000per month

Take more than one pillar and the price per programme comes down.

Compliance pairs naturally with AI Enablement: the rules and the skills, built together. Adding the third covers what AI is doing to the people using it.

One pillar A single Full Programme.

£1,495

Two pillars £1,345 per programme.

£2,690 Save £300

The Full Training Programme £1,250 per programme. Enablement, Risk & Compliance, and The Human Risk of AI.

£3,750 Save £735

Bundle pricing applies to Full Programmes. Workshops and the monthly compliance retainer are priced separately.

Before you book a call

We are a good fit for some businesses and the wrong choice for others.

Five minutes of honesty now saves us both a wasted hour later.

This works well if

  • You are a CEO, MD, COO or senior leader who has decided AI matters and wants it done properly.
  • You want capability that is still there in six months, held by your own people.
  • You want someone who picks up the phone long after the invoice has cleared.
  • You work in a regulated environment and need someone who understands the obligations as well as the tools.
  • You are willing to hear that some of your team are quietly struggling with this.

This is probably the wrong fit if

  • You want one training day and a wave goodbye.
  • Price is the deciding factor and you are collecting quotes to compare.
  • You want a 200-slide strategy deck with nobody’s name against any of it.
  • You would rather hand over the thinking than build the judgement in-house.
  • You need a certificate for the wall more than you need the change.

Free · 5 minutes · Instant result

Not ready to talk? Find out where you stand first.

Eighteen questions across risk, people, governance and cybersecurity. Answer honestly and you get an instant AI readiness score, the specific gaps most likely to cost you, and clear next steps built around your answers.

Start the free risk check

No obligation. Seen only by us, never shared.

Find out what's really happening in your firm.

Thirty minutes, free, and you will know exactly where your gaps are and what closing them involves.

Book a free intro call