Data flows
Where data comes from, where it goes, who can see it — mapped so there are no surprises.
The data flows, retention rules, approval steps and checks that let you explain your AI to a board, a donor, or a ministry — and show the people you serve that their data is handled with care. Not a slide deck. An operating guide your team actually uses.
Governance is the right first step when the constraint on your AI isn't the tech — it's being able to answer for it.
A funder or grant requires documented data handling before they'll release money.
You handle sensitive data about vulnerable people and need to prove it's protected.
A board or regulator is asking how your AI decisions are made and who signs off.
You're about to build or deploy AI and want the guardrails in place first, not after.
Where data comes from, where it goes, who can see it — mapped so there are no surprises.
What you keep, for how long, and how it's deleted — matched to the rules you answer to.
Who signs off on what, and where a human has to stay in the loop on a decision.
What your AI tools and providers can and can't do with your data — in writing.
Simple, repeatable ways to test that the AI is behaving — and catch it when it isn't.
A short, readable set of documents your team runs by, and can hand to a board or auditor.
A small organization needs less than a multi-country programme. We scope it to what you actually answer to — and price it up front.
No. The output is short and meant to be used day to day — clear rules, clear approvals, simple checks. If it just sits in a drawer, we've failed.
Often it's wiser to set the guardrails first, especially with sensitive data. But governance and building can run together — we'll advise on the order that fits your situation.
We write it to answer the questions funders and boards actually ask. If your funder has a specific framework, tell us and we'll map to it.
Tell us who's asking the hard questions, and we'll scope what it takes to answer them.