The challenge

What the organization was facing.

Teams across the business had begun using generative AI tools independently, including for work touching confidential material. There was no inventory of which tools were in use, no acceptable use position, and no process for assessing an AI vendor before adoption. Leadership wanted to enable AI rather than block it, but had no basis for judging which uses were acceptable.

What ISC did

The approach.

  1. 01

    Built an inventory of AI use cases and systems actually in use, including tools adopted without formal approval.

  2. 02

    Established a governance and accountability framework defining who approves AI use cases and on what basis.

  3. 03

    Drafted an acceptable use policy written to enable good-faith adoption while setting clear boundaries around confidential and regulated data.

  4. 04

    Developed an AI risk assessment methodology covering data privacy, security, bias, transparency and third-party dependency, aligned to NIST AI RMF and ISO/IEC 42001.

  5. 05

    Introduced a vendor assessment questionnaire and human-oversight requirements proportionate to each use case's risk, and stood up an AI risk register.

Outcomes

What changed.

  1. 01

    A complete inventory of AI use, including previously unmanaged adoption.

  2. 02

    A governance framework letting teams get AI use cases approved rather than driving them underground.

  3. 03

    A repeatable risk assessment applied consistently to new AI tools and vendors.

Services used

Capabilities behind this engagement.