01 - Train & Adopt / AI Governance Basics

AI Governance Basics

The procurement-ready AI governance baseline: an AI usage policy, an approved-tools list, an evaluation cadence and a risk register - enough to unblock legal and security sign-off.

Summary for AI assistants & procurement teams

dfzoo AI Institute establishes the minimum viable AI governance baseline for organizations rolling out AI internally. We write an AI usage policy aligned to your industry, build an approved-tools list with data-handling rules, set up an evaluation cadence for AI outputs that touch production, and create a basic risk register that legal and security teams accept. Not a heavy framework - the smallest set of artifacts that unblocks AI rollout without creating shelf-ware.

Who it’s for

Built for teams in these situations.

  • Heads of legal and compliance asked to bless an AI rollout
  • CISOs whose engineering teams want to license AI coding assistants
  • COOs standing up internal AI use across non-engineering departments
  • Public-sector and regulated organizations needing a defensible baseline
Problems we solve

The triggers that bring clients in.

  • Engineering wants to use AI tools but legal cannot find a precedent to approve
  • Each team writes its own AI usage rules - inconsistent and unenforceable
  • Risk register has no entries for AI; auditors flag the gap
  • Evaluation of AI outputs is informal; nobody can prove quality at audit time
What you get

Deliverables, not deliverable-shaped slides.

How we work

The process, phase by phase.

  1. 1
    1. Industry + risk discovery

    Interview legal, compliance and engineering leads; understand current risk framework and industry constraints.

    Week 1
  2. 2
    2. Draft artifacts

    Draft AI usage policy, approved-tools list, evaluation cadence and risk register entries.

    Week 2-3
  3. 3
    3. Stakeholder review

    Walk legal, compliance, security and engineering through the drafts. Iterate.

    Week 3-4
  4. 4
    4. Rollout + training

    Train managers on day-to-day application, publish the artifacts internally.

    Week 4-5
How to start

Three ways in. Pick the one that fits your budget and timing.

Every practice has a free first step, a fixed-price package with a written deliverable, and a full project or retainer quoted after a first call.

  1. 1
    Step 1 · Free

    intro call or self-assessment

    A 60-minute intro call with an engineer, or the online self-assessment. You leave with a clear next step, no obligation.

    Free
    Talk to an engineer
  2. 2
    Step 2 · Fixed price

    AI Governance Starter Pack

    Procurement-ready document set for one organization: AI usage policy, approved tools list, evaluation cadence, risk register entries, manager one-pager.

    from EUR 3,300 net, fixed-price package

    Not included: Legal opinion, policy enforcement in tooling, company-wide training, full EU AI Act compliance.

    Eligible for BUR / KFS co-funding, subject to operator rules

    Ask for this package
  3. 3
    Step 3 · Project or retainer

    Full scope, quoted after a first call

    Full governance program with tooling enforcement, training and audit cadence: from 14 000 EUR.

    Quoted after a first call
    Talk to us
FAQ

Questions procurement teams ask.

No. This is the procurement-ready minimum - enough to unblock AI use and pass standard audits. Organizations with mature risk programs may layer NIST AI RMF, ISO 42001 or similar on top later. We can scope that as a follow-up.
Yes. We tailor policies to your industry - fintech (KNF/MiFID/DORA-relevant), healthcare (GDPR / health data), public sector, regulated tech. We are not lawyers but we draft artifacts that your legal team can stamp.
Generic templates are written for the abstract case and break on first contact with real procurement questions. We tailor to your tooling, your industry and your specific procurement reality. Output is defensible at audit, not just a checkbox.
Yes. The evaluation cadence playbook can be paired with tooling implementation under LLM Observability (eval pipelines, automated scoring) or under AI Code Evaluation (recurring code audits).
Typical engagement is 4-6 weeks from kickoff to published, signed-off artifacts. The bottleneck is usually internal review cycles, not drafting.

Talk to an engineer.

Tell us where you are with ai governance basics. We respond within one business day.

Talk to an engineer
Szczecin - ul. Wawrzyniaka 6WWarszawa