Governed productivity. Auditable, not accidental.
AI adoption is rising. Operating maturity is not. This outcome builds the guardrails that let departments realise productivity gains without creating obligations the business cannot answer for.
Register
Every AI use case has an owner, a benefit and a stated risk.
Govern
Guardrails, data boundaries and evidence that stand up to outside review.
Enable
Literacy tiered to the people actually using AI, department by department.

Use-case register
Owners, benefits, risks and lifecycle status in one governed view.
EU AI Act
Evidence management aligned to emerging obligations.
Literacy L1-3
Training tiered from awareness to departmental practitioner.
Inside the baseline
AI runs on governed identity and data, not around it.
AI is already in the business. The question is whether anyone can account for it.
Shadow adoption
Teams are pasting business data into consumer tools nobody approved and nobody can audit.
Data boundaries unset
Without configured tenancy and permissions, an assistant surfaces whatever a user could technically reach.
Pilots that never land
Enthusiastic trials stall because no owner, no measure and no path to production was agreed.
No evidence trail
When a regulator, insurer or acquirer asks how AI is governed, the answer is assembled from memory.
The standard the outcome is held to.
Every AI use case has an owner, a benefit and a risk. Teams using AI have the literacy to use it responsibly. Evidence is ready if a regulator, auditor or acquirer asks. Productivity gains land inside a governed baseline, not around it.
- An AI use-case register with owners, benefits and risks.
- Literacy in place for the teams actually using AI.
- Evidence management that satisfies emerging EU AI Act requirements.
- A path from awareness to governed departmental productivity.
A rehearsed sequence, not a bespoke project.
Assess
Current AI usage, data exposure and readiness against the maturity rating.
Register
Use cases captured with owners, benefits, risks and lifecycle status.
Govern
Policy, data boundaries and approval routes set inside the managed baseline.
Enable
Tiered literacy for the teams using AI, plus supported departmental pilots.
Evidence
Governance artefacts maintained and reviewed with leadership each quarter.
Coverage scales with the NumataOne service tier.
Each tier includes everything in the one before it.
Core
AI usage policy, Microsoft 365 Copilot data boundaries and awareness-level literacy for all staff.
Standard
Adds a maintained use-case register, approval routes and role-based literacy for active users.
Premium
Adds supported departmental pilots, benefit measurement and quarterly governance review.
Enterprise
Adds EU AI Act aligned evidence management, risk classification and packs ready for audit or diligence.
What leadership can review, and when.
- Use-case register with lifecycle status.
- Literacy coverage and incident record.
- Governance artefacts ready for external review.
- Data boundary and permission review results.
Nobody is asked whether they used AI. They are asked who approved it, what data it touched, and where that is written down.
Questions leadership teams ask.
Do we need AI governance if we only use Microsoft 365 Copilot?
Yes. Copilot inherits existing permissions, so it surfaces whatever a user could already reach, including content nobody realised was over-shared. Governance means fixing data boundaries first, then setting policy and literacy around use.
What does the EU AI Act require of a business like ours?
Obligations scale with risk classification, and most SME use is limited or minimal risk. Even there, the practical requirements are AI literacy for the people using these systems and evidence of how use cases are governed. Both are built here.
How do you stop shadow AI use?
By making the approved path easier than the unapproved one: sanctioned tools inside the managed tenancy, a clear approval route, and literacy that explains why a consumer tool is a data risk. Blocking alone drives usage underground.
What goes into the use-case register?
For each use case: a named owner, the business benefit, the data involved, the risk position, the approval decision and its lifecycle status from proposed through to retired. It is maintained continuously, not assembled for audits.
How quickly can this be in place?
Policy, data boundaries and awareness literacy typically land inside the first quarter. The register, departmental pilots and the first governance review follow in the quarter after.
