Skip to content

ESD Resources

AI
Governance
& Compliance

Enterprise-grade AI. Built for responsible deployment.

Responsible AI is not a badge added at the end of a project. It begins with the purpose of the system, the data it uses, the decisions it can make and the points where people remain in control.

ESD’s architecture and deployment methodology are designed to support organisations working across leading international AI and data-protection frameworks.

PrivacySecurityHuman oversightResponsible AI governance

01 International frameworks

One deployment.
Multiple jurisdictions.

Each framework has a different legal or governance role. Our language reflects that distinction: laws may impose obligations, voluntary frameworks guide risk management, and certification applies only to the organisation and scope shown on a valid certificate.

GDPR

Privacy-conscious architecture and data-handling controls designed to support GDPR-compliant deployments.

Official regulation

EU AI Act

Designed to support organisations in meeting applicable AI governance, transparency, oversight and risk-management requirements.

European Commission overview

NIST AI Risk Management Framework

AI governance practices aligned with internationally recognised principles for trustworthy and responsible AI risk management.

Official NIST framework

Canadian Privacy Requirements

Architecture designed to support deployments subject to applicable Canadian privacy and data-protection requirements, including PIPEDA where applicable.

Privacy guidance for businesses

ISO/IEC 42001

Our underlying AI technology provider is currently progressing toward ISO/IEC 42001:2023 certification for its Artificial Intelligence Management System.

Official ISO standard overview

One Digital Employee. Enterprise-ready governance across multiple jurisdictions.

02 From principles to deployment

Governance becomes real
through controls.

A responsible deployment is shaped around the actual process, risk level, data and systems involved. The appropriate controls are defined before implementation and reviewed as the role evolves.

01

Purpose and scope

A defined business purpose, role, authorised actions and clear limits.

02

Data and access

Access controls, data minimisation and handling rules appropriate to the deployment.

03

Human oversight

Approval points, exception routes and a named person responsible for the process.

04

Activity and review

Logging, monitoring and review requirements agreed for the work being delegated.

05

Risk and change

Assessment of material risks, testing and review when the role, systems or data change.

06

Deployment documentation

Relevant system, data-flow, oversight and governance information for client review.

03 Clear language, accurate claims

What our wording means.

AI compliance depends on the specific deployment and on both supplier and client responsibilities. We therefore avoid language that could imply an automatic legal guarantee or a certification that has not yet been awarded.

“Designed to support compliance”

The architecture and deployment controls are intended to help an organisation meet relevant requirements. The final compliance position depends on the use case, configuration, data, contracts, jurisdiction and how the organisation operates the system.

“Aligned with”

The governance approach draws on the principles and practices of the named framework. For NIST AI RMF, this refers to a voluntary risk-management framework rather than a certification.

“Progressing toward certification”

The certification process is underway, but certification has not yet been awarded. Once completed, any claim must identify the certified legal entity and remain within the scope shown on the certificate.

04 Responsible deployment

Start with the process.
Then design the controls.

The same Digital Employee can carry very different risks depending on what it does, whose data it handles and whether it can act independently.

Before implementation, ESD works with the client to define the role, permissions, approval points, exception handling and practical governance requirements appropriate to the proposed deployment.