AI advisory & governance

Work out where AI actually fits.

Which tasks it would genuinely help with, which tools your people may use, and which data must never go into them. Written down, in words your staff can follow, by someone who is happy to tell you not to build anything.

Sound familiar?

The AI question, still open.

Most organisations don’t need an AI strategy. They need a few clear decisions, made on purpose and written down.

  • Staff already use ChatGPT or Claude on their own accounts, and nobody has said what’s allowed.
  • A board or a funder is asking what your plan for AI is.
  • A vendor is pitching an AI feature, and it’s hard to tell whether you need it.
  • You’d like AI to search your documents, but they hold client or personnel data.
  • Someone has asked for “an AI strategy”, and nobody knows what it should contain.

What I do

Decisions, not a slide deck.

  • Readiness assessment

    How work flows today, where AI would help and where it wouldn’t, and what to do first. For leadership who don’t want the jargon.

  • AI usage policy

    What staff may put into which tools, including their personal accounts, tied to which data leaves the organisation rather than to brand names.

  • AI on your documents

    Options for connecting an assistant to SharePoint or a file server, compared on permissions, separation of client folders, and where the data is processed.

  • Security awareness

    Plain guidance for staff on everyday risks, such as what to do when an email looks like phishing.

The one-week diagnosis

Five days, four deliverables.

A fixed price between €1,500 and €3,000, depending on scope. There is no obligation to continue, and the recommendation may well be that you don’t need a build at all. If you do go on to one with me, the fee is credited towards it.

  1. Current state

    How the work actually flows, which tools are already in use (officially or not), and where the data sits.

  2. Opportunity map

    Where AI would genuinely help, each option weighed on effort, risk and the time it would give back.

  3. Vendor comparison

    The realistic options side by side, including where each one processes your data.

  4. Recommendations

    A written plan for non-technical leadership: what to do first, what to wait on, and what not to do at all.

What an AI usage policy covers

Eight sections, and the open decisions.

The structure of the last policy I drafted, with the client’s specifics taken out. Where a decision belongs to your leadership, the draft says so in a “to decide” box with a suggested answer, rather than deciding for you. I draft; your leadership, and your DPO or counsel where you have one, sign off.

  1. Front matterWhy now, who and what it covers, what’s out of scope, the different kinds of work and material it applies to, and what counts as an approved tool.
  2. 1 · PrinciplesHuman judgement stays with people, no decisions left to AI, personal responsibility, confidentiality, impartiality.
  3. 2 · Tools and accountsOrganisation, personal and own-business accounts; AI features inside other software; what is checked before a tool is approved; where data is processed; connections to internal systems.
  4. 3 · What may be enteredA green, amber and red table of what may and may not go into an AI tool, with guidance on anonymisation.
  5. 4 · Controlled useWhen sensitive material may be used anyway: written authorisation, and what it must state.
  6. 5 · Use in core workWhat’s permitted and what isn’t, recording and transcription, checking results.
  7. 6 · Good practiceOne conversation per piece of work, memory off, noting where AI was used, deleting at the end.
  8. 7 · MistakesWhat counts as an incident, who to tell, and no-blame reporting.
  9. 8 · ResponsibilitiesWho owns what, awareness before use, and an annual review.
  10. ClosingThe minimum next steps for a pilot, and the internal documents and legal framework it builds on.

How I advise

Sometimes the answer is don’t build it.

If a clear process and the spreadsheet you already have will solve it, I’ll say so. Advice that always ends in a build isn’t advice.

  • Rules about data, not brands. Tools change every few months. What may leave your organisation changes far less often.
  • Written for the people who follow it. Short, plain, and in English or French.
  • Built to be checked. Each rule says what it protects, so it can be tested and revised rather than taken on faith.

Recent advisory work

Where I’ve done this.

Through Relief Applications, a technology consultancy for international and humanitarian organisations. Clients are not named.

Humanitarian accreditation body · 2026

AI usage policy and security guidance

Drafted the AI usage policy in eight sections, including what consultants and auditors may put into personal AI accounts, tied to what data leaves the account rather than which tool is used, and a green, amber and red table of what may be entered. Revised the phishing-response guidance. Compared options for connecting Claude to SharePoint and NAS document stores: permissions, separation of client folders, and where data is processed.

AI usage policyData protectionSecurity awareness
International institutions · 2026

AI readiness assessments

For institutions working in conservation, development and disaster-risk financing: current-state audit, opportunity mapping, vendor comparison, and recommendations written for non-technical leadership.

Readiness assessmentVendor comparison

All recent work →

How it runs

Short, fixed, and written down.

First step
A 30-minute call. Free.
Diagnosis
One week, fixed price between €1,500 and €3,000. No obligation to continue.
Policy work
Quoted after a call, depending on how many teams and tools it covers.
Format
Written deliverables you keep and can circulate. Workshops where they help.
Language
English or French.

Start with one question.

What your staff are allowed to do with AI, or whether a particular tool is worth it. A 30-minute call is usually enough to tell whether you need a week of work or a page of rules.