AI Usage

How Sovereign GRC uses artificial intelligence — transparently, responsibly, and in alignment with the governance standards we advise on.

Practising What We Advise

Sovereign GRC helps clients design and operate AI management systems aligned with frameworks such as ISO 42001. We believe that any organisation advising on AI governance must apply the same transparency standards internally. This page is our own disclosure — not a marketing page, not legal boilerplate.

A Perspective on Tools

Every generation of professionals has faced a moment when a new category of tool arrived — and with it, a debate about whether it would replace human judgement or merely reshape how that judgement gets exercised.

Spreadsheets automated calculation. Email accelerated correspondence. Search engines compressed research cycles from days to minutes. SIEM platforms aggregated millions of signals into a single pane. GRC software systematised what had previously lived in folders and spreadsheets. In each case, the tool changed the workflow. The professional remained responsible for the outcome.

1980s

Spreadsheets

Risk registers & financial modelling

1990s

Email

Client communication & document exchange

2000s

Search engines

Regulatory & case law research

2000s

SIEM platforms

Log aggregation & threat detection

2010s

GRC software

Control tracking & audit evidence

Today

AI / LLMs

Drafting, research & code generation

We take the same view of AI. It is a capable, fast, and occasionally unreliable drafting and research instrument. It does not hold professional qualifications. It cannot sign an audit opinion. It does not bear regulatory liability. It cannot be held to account by a client, a regulator, or a court.

“The accountability has always sat with the practitioner. At Sovereign GRC, it still does.”

AI-Assisted Development

This website was substantially built with the assistance of large-language-model (LLM) coding tools. Specifically:

  • Code generation — UI components, page layouts, and utility functions were drafted using AI coding assistants and reviewed by a human developer before deployment.
  • Copy drafting — Initial page copy was AI-assisted; all final text was reviewed, edited, and approved by the founding team.
  • Design iteration — AI tools were used to propose layout patterns and component structures; all design decisions were made and validated by humans.

No sensitive client data, proprietary frameworks, or confidential materials were submitted to any external AI system during the creation of this site.

Human Oversight Applied

Every AI-generated output — whether code, copy, or structural decisions — was subject to human review before it reached production. We treat AI assistance as a drafting tool, not a decision-maker. Sovereign GRC principals bear full responsibility for the content and accuracy of this site.

AI in Our Advisory Practice

We use AI tools selectively to support research, analysis, and documentation tasks within our practice. Our operational principles:

  • No client data in AI tools without consent — Identifiable client information, audit artefacts, and confidential materials are not submitted to commercial AI APIs unless we have explicit written authorisation and a reviewed data-handling agreement in place.
  • Humans make risk and compliance judgements — AI outputs are treated as research support. All risk ratings, control assessments, and compliance recommendations are reviewed and signed off by a qualified practitioner.
  • Residency and sovereignty considerations — Where data residency requirements apply to an engagement, we evaluate whether any AI tooling involved meets those constraints before use.

What AI Is Not Used For

For the avoidance of doubt, AI-generated outputs are not used to:

  • Produce final audit opinions, certification recommendations, or risk-acceptance decisions.
  • Draft or interpret legal agreements, regulatory submissions, or formal compliance attestations.
  • Automate client communication without human review and approval.

How We Apply ISO 42001 Principles Internally

ISO 42001 — the international standard for AI management systems — establishes requirements for responsible AI development and use. We align our internal AI use with its core principles:

  • Transparency — We disclose where AI is used, as evidenced by this page.
  • Accountability — Named individuals are responsible for reviewing AI outputs used in client-facing work.
  • Robustness — AI-assisted work is subject to the same quality and accuracy checks as non-AI work.
  • Privacy and data minimisation — We apply the principle of using the minimum necessary data when working with AI tooling.

This is not a claim of ISO 42001 certification. We support implementation of these principles and are building toward a more formalised AI management system as our practice grows.

Living Disclosure

AI tooling changes quickly. We commit to reviewing and updating this page whenever our AI usage changes materially — at minimum on an annual basis. If you have questions about a specific tool or use case, contact us directly at advisory@sovereigngrc.com.

Last reviewed: July 2026