AI governance · AIMS · assurance · regulatory readiness

Governance, built on regulation.

Varai helps regulated organisations govern AI with confidence. We design the management systems, evaluation frameworks and oversight that turn ISO 42001 and the EU AI Act from obligations into something your board, your auditors and your regulators can rely on.

Aligned to
ISO/IEC 42001 ISO/IEC 42005 ISO/IEC 23894 EU AI Act NIST AI RMF FCA & PRA expectations

The approach

Regulation sets the obligation. We build the system that meets it.

Much AI governance work stops at a policy document. Ours starts with the obligations that apply to you, and ends with an operating system your auditors, regulators and board can rely on.

First

Understand the obligations

We work alongside your legal, risk and compliance teams to turn the obligations they identify, across ISO 42001, the EU AI Act and FCA and PRA expectations, into a clear view of where your AI practice stands today.

Then

Build the management system

We design and implement the AI management system that closes the gap: policies, controls, risk and impact assessments, evaluation criteria, and a clear trail of evidence.

And sustain it

Evaluate and embed

We set the oversight and evaluation frameworks that keep AI performing as intended, then leave you audit ready, with the reviews that hold as regulation evolves.

What we do

Five disciplines, one governance backbone.

Engaged together as an end to end programme, or individually where you need a specific capability.

AI governance & AIMS

Design and implementation of an AI Management System to ISO/IEC 42001, from gap analysis and scope through to controls, the Statement of Applicability and certification readiness. This is where accountability, fairness, transparency and human oversight are embedded across the organisation, not left to chance.

  • ISO 42001
  • Gap analysis
  • Controls & SoA
  • Trust & accountability
  • Certification readiness

AI assurance & evaluation

Independent evaluation of whether AI systems perform as intended, and the assurance evidence to prove it. We design the evaluation and oversight frameworks that test systems against your AI policy and the standards that apply, working alongside your technical teams rather than replacing them.

  • Evaluation frameworks
  • Assurance evidence
  • Performance & robustness
  • Model documentation

AI risk & impact assessment

Two complementary disciplines, done properly. AI risk assessment identifies and treats the operational, technical and compliance risks a system carries, aligned to ISO/IEC 23894. AI impact assessment examines how a system affects the people and communities it touches, aligned to ISO/IEC 42005 and EU AI Act expectations for high-risk systems.

  • Risk assessment (ISO 23894)
  • Impact assessment (ISO 42005)
  • High-risk systems
  • Lifecycle coverage

Regulatory readiness

One programme, mapped across many frameworks. We bring the EU AI Act, ISO 42001 and FCA and PRA expectations together into a single, coordinated readiness programme, so your teams prepare once rather than separately for each. We align your governance to these frameworks; your legal and compliance functions own the final regulatory interpretation.

  • EU AI Act readiness
  • Multi-framework mapping
  • Coordinated programme
  • Conformity preparation

Regulatory programme delivery

Bringing AI governance from board mandate to operating reality takes more than a framework. It takes someone who has run large, regulated programmes before. Behind Varai are fifteen years of leading complex change inside banking, payments and standards bodies, and that delivery discipline, the stakeholders, workstreams, milestones and audit ready evidence, is what now carries an AI governance initiative through to something that actually operates.

  • Programme leadership
  • Stakeholder management
  • Workstream delivery
  • Audit preparation
  • Board reporting

Forged in regulation

Built in regulated environments.

Varai's approach is shaped by years of assurance and regulatory delivery inside some of the most heavily governed sectors. That grounding is what makes the AI governance work credible, and what lets it speak the language of a regulator, a board and an engineering team in the same room.

Core grounding

Financial services

Investment banking, corporate banking, wealth management and payments, where regulatory scrutiny is highest.

Standards & certification

Years inside a national standards body, on AI regulatory and product certification programmes.

Energy & utilities

Large scale transformation and assurance delivery across regulated operational estates.

Life sciences

Governance and validation work in highly regulated, evidence driven biotechnology settings.

Half a decade in AI governance, built on fifteen years in regulated industry. Governing AI before the questions arrived.

Varai brings together two things regulated organisations rarely find in one place: real depth in governing AI, and the delivery discipline to make that governance operate. The arc below is how that combination was built.

The practice

Deep in AI governance. Disciplined in delivery.

Varai is led by its founder and draws on a trusted network of specialists, assembled around each engagement and matched to the work. You get senior, hands on involvement, with the right team built around it.

2010–2012

Public sector & utilities

National-scale programmes Smart infrastructure Risk-based assurance
2012–2019

Banking & financial services

Capital markets & payments Global onboarding & KYC Enterprise transformation Regulatory delivery
2019–2021

AI & regulation

FinTech & AI study Standards bodies Regulatory transformation Responsible AI
2021–present

AI governance, AIMS & assurance

ISO 42001 advisory AI assurance & evaluation AI risk & impact assessment EU AI Act readiness CAIP, OXETHICA Research: AI & cognitive autonomy

Credentials

The expertise behind the practice.

Varai is backed by formal study across AI, finance and assurance, from institutions recognised in each.

AI & governance

University of Oxford

Artificial Intelligence & AI governance

ISO/IEC 42001

Lead Implementer, AI management systems

MSc Psychology

AI & Cognitive Autonomy

Finance & technology

HarvardX

Financial Technology with AI

MBA Information Systems

Trinity College

Certified AI Professional

CAIP, awarded by OXETHICA

Assurance & delivery

ISTQB

Certified assurance and quality discipline

Programme & portfolio governance

University of Washington

Why Varai

The bridge between the rulebook and the AI.

Governance and assurance together

Many bring one or the other. Varai designs the governance system and sets the evaluation framework that proves the AI inside it, so the controls and the evidence line up.

Fluent with your second line

We work alongside legal, risk and compliance, not around them. We turn their interpretation of the rules into a working management system and the evidence to support it.

Built to survive an audit

Fifteen years inside banking, finance and standards bodies. We know how regulated organisations actually work, and what holds up when an auditor asks for the evidence.

Frameworks & standards

ISO 42001AI management systems
ISO 42005AI system impact assessment
ISO 23894AI risk management
EU AI ActRisk classification & readiness
NIST AI RMFAI risk management framework
FCA / PRAUK financial regulation

Bring your AI under control, before the regulator asks you to.

Whether you are starting an ISO 42001 programme, preparing for the EU AI Act, or need an evaluation framework for a system already in production, let us talk about where you are and what comes next.