Dextily

For compliance leaders who need to prove their AI is governed

Your AI is already running. Can you prove it's governed?

We help compliance and security leaders move from "we have an AI policy" to "here is the evidence." Practical AI governance, ISO/IEC 42001 readiness and ongoing support-without turning it into another endless compliance project.

No obligation · Practitioner-led · We'll tell you what the next step could look like

Dextily

AI Governance Overview

Active

AI Inventory

12

systems identified

Risk & Impact

9/12

assessments complete

Governance Owners

12/12

assigned

Evidence Items

46

documented

ISO/IEC 42001 Readiness

68%

AI Inventory

Complete

Risk Assessment

In progress

Evidence

Ready

Dear Compliance Leader...

You probably didn't ask to become the AI person.

But now you're getting the questions.

A customer sends a security questionnaire with a new AI section. Your board asks who is accountable for AI risk. Legal asks what the latest regulation means. Engineering names three models-and another team mentions an AI assistant nobody told you about.

Then someone asks:

"Can you show us how your AI is governed?"

You know your organisation uses AI. You know people are trying to manage it.

But can you prove what is governed, who owns it, what risks have been assessed and what evidence exists?

That's the gap Dextily is built to close.

The Cost of Not Knowing

Don't let AI governance become another compliance project that never ends.

The customer questionnaire arrives. Sales needs an answer. The board wants to understand accountability. Legal is asking about regulatory exposure. Someone wants to know whether ISO/IEC 42001 certification is necessary.

And suddenly you're trying to work out what AI systems exist across the business-while still doing the job you were hired to do.

AI governance shouldn't mean building a giant programme before you can answer a simple question.

Start with a free 30-minute conversation.

The Dextily Approach

We'll turn your AI governance from a policy into something you can actually prove.

We help you discover what exists, assess what matters, build practical governance and create evidence that stands up to customer, executive and audit questions.

Fixed-price entry engagement · No certification guarantees

Why our approach works where policies, templates and generic consulting fall short.

AI governance isn't a document problem. It is an operating problem. The work has to connect security, product, engineering, legal, compliance and leadership.

01

Not Just a Template

Governance has to fit the way your business operates. We focus on ownership, decision-making, risk, controls and evidence-not just documents sitting in a folder.

02

Not Just Software

A platform doesn't make the judgement for you. Tools can support evidence and workflows. They don't replace the governance decisions your organisation needs to make.

03

Not an Endless Project

Start with the question you need answered now. The diagnostic gives you a practical picture of where you stand before you commit to a larger readiness programme.

The Dextily Governance Method

From "we're not sure" to "here's the evidence."

Four steps that turn AI governance from an abstract requirement into an operating system your organisation can use.

01

Discover

Find what exists.

AI systems, use cases, agents, owners, data and existing governance.

02

Assess

Understand the gaps.

Risk, impact, requirements, governance maturity and commercial exposure.

03

Build

Put governance in place.

Policies, roles, controls, assessments, processes and evidence.

04

Prove

Be ready to show it.

Customers, executives and auditors can ask. Your team has a defensible answer.

What "Provable" Looks Like

Not another policy. A governance system you can show.

The exact evidence depends on your organisation and scope. The point is that governance becomes visible, owned and reviewable.

Dextily

AI Governance Evidence

AI Inventory

12

systems

Owners Assigned

12/12

complete

Risk Assessments

9

documented

Evidence Items

46

on record

Dextily

Executive Readiness

Governance Scope

Defined

AI Accountability

Assigned

Priority Gaps

7 identified

Next Review

In 30 days

Illustrative example - dashboard figures are mock data for the page design, not Dextily client results.

The Dextily Offer

Start with the problem you have today.

Choose the level of support that matches your current governance question.

Start Here

3 weeks

AI Governance Diagnostic

$15,000

Find out where you actually stand.

  • ›AI system inventory
  • ›ISO/IEC 42001 gap assessment
  • ›Regulatory & commercial exposure map
  • ›Prioritised roadmap
  • ›Executive readout
  • ›Fixed-price readiness quote

3–5 months

AIMS Readiness Programme

$60K–$75K base

Build the management system.

  • ›Full ISO/IEC 42001 gap analysis
  • ›AI management system design
  • ›Policy & control framework
  • ›Risk & impact assessments
  • ›Evidence documentation
  • ›Readiness audit preparation

6-month minimum

Fractional AI Governance Officer

$10K/month

Keep governance moving.

  • ›Ongoing governance oversight
  • ›Board & executive reporting
  • ›Incident & change response
  • ›Supplier & customer support
  • ›Regulatory monitoring
  • ›Governance programme management

1–2 days

Executive AI Governance Briefing

$20,000

Give leadership a clear picture.

  • ›Leadership-ready briefing
  • ›AI risk landscape overview
  • ›Regulatory & commercial exposure
  • ›Accountability framework
  • ›Readiness priorities
  • ›Facilitated board discussion

Everything Included in the Governance Foundation

Six things your organisation needs to move from policy to proof.

01

AI Inventory

Understand every AI system, use case and agent in your organisation.

02

Risk & Impact

Assess which AI use cases carry genuine risk and what controls are needed.

03

Accountability

Assign governance ownership for every AI system and decision.

04

Policies & Controls

Build a framework that fits how your business actually operates.

05

Evidence

Create a record that stands up to customer, executive and audit scrutiny.

06

Readiness

Know exactly where you stand for ISO/IEC 42001 and regulatory questions.

The Difference Between Policy and Proof

What Provable AI Governance Looks Like

Having an AI policy is a starting point. Provable governance means you can show what AI you have, who owns it, what risks you've assessed, what controls are operating, and what evidence supports your answer.

01

AI Inventory

Know what you have.

A documented view of your AI systems, use cases, vendors, and ownership.

02

Risk & Impact

Know what needs attention.

Identify and assess the risks, impacts, and obligations associated with your AI.

03

Accountability

Know who owns what.

Clear responsibilities and decision-making across security, compliance, product, legal, and leadership.

04

Operational Controls

Show governance in practice.

Connect policies to the processes and controls used to introduce, assess, approve, and monitor AI.

05

Evidence

Be ready to prove it.

Bring policies, ownership, risk assessments, controls, and records together so governance can be demonstrated when questions arise.

From "we have an AI policy" to "here is the evidence."

Who Dextily Is Built For

You may recognise yourself here.

"Customers have started asking."

Your enterprise customers are sending AI governance questionnaires. Sales needs answers quickly. You need a process that scales.

"The board wants an answer."

Leadership is asking who owns AI risk. You need more than a policy statement. You need something you can actually show them.

"We have AI, but not enough visibility."

You know AI is running across the business. You're less certain exactly what, where and whether it's properly governed.

"ISO 42001 keeps coming up."

Customers and prospects are asking about ISO/IEC 42001. You need to understand what it involves and whether certification makes sense.

Free 3-Minute Assessment

How AI-Ready Is Your Organisation?

AI is already part of your business.

But can you clearly show: what AI you use, who owns it, what risks have been assessed, what controls exist, and what evidence you can produce?

Take the free Dextily AI Governance Readiness Assessment to see where your organisation currently stands.

3 minutes · No obligation · Work email required for your personalised result

Dextily

AI Governance Readiness Assessment

A structured diagnostic for compliance & security leaders.

01AI Inventory
02Risk & Impact
03Governance
04Evidence
05Readiness
~3 minutes

Your Free 30-Minute Call

What you'll get in your AI Governance Readiness Call.

01

Your governance reality check

We'll give you an honest view of where you stand based on what you tell us.

02

Your risk & readiness questions

We'll answer the specific questions you're being asked about AI governance.

03

Your next-step path

We'll outline what a sensible starting point looks like for your situation.

04

A straight answer on fit

We'll be direct about whether Dextily is the right partner for your needs.

Free30 minutes

Let's make AI governance practical.

  • No obligation
  • Practitioner-led conversation
  • Focused on your current situation
  • Clear discussion of possible next steps

Questions You May Have

Before you book.

Not necessarily. ISO/IEC 42001 is one framework for AI governance, and certification may be relevant if customers require it or if it provides competitive advantage. The more immediate question is whether you can demonstrate that AI in your organisation is governed, risk-assessed and accountable. A governance diagnostic will give you clarity on whether certification is the right path for your situation.

No. Certification under ISO/IEC 42001 is issued by an accredited certification body following an independent audit. Dextily builds the governance foundation and prepares your organisation for that process. We do not offer certification ourselves, and we make no guarantees about certification outcomes.

Your existing information security framework provides a strong foundation. AI governance has distinct requirements around risk assessment, accountability, impact management and evidence that sit alongside rather than inside a security management system. The diagnostic will show you exactly what gaps exist and what additional governance is genuinely needed given what you already have.

Approximately three weeks from kick-off to executive readout. The diagnostic is designed to give you a clear, actionable picture quickly-not to run on indefinitely. We work around your team's availability and time constraints.

The diagnostic is designed specifically for organisations that are not yet sure what they need. It gives you an honest assessment of where you stand and a clear prioritised roadmap before you commit to anything further. Many organisations start with the diagnostic and use the findings to make a case internally for the next step.

Dextily works with US mid-market software and fintech companies-typically those with AI already in production and compliance or security leaders responsible for answering governance questions from customers, boards and regulators. If you're getting questions you can't yet fully answer, you're the right fit for a conversation.

Ready to Know Where You Stand?

Your AI is already part of the business. Now make its governance provable.

Start with a free 30-minute conversation about what you have, what you're being asked and what needs to happen next.

No obligation · Practitioner-led · Clear next steps