Governance that
withstands public
scrutiny.

Public institutions are accountable for how they protect citizen data, secure their systems, and govern AI. We deliver the governance infrastructure that satisfies auditors, meets mandatory legal obligations, and protects public trust — under one relationship.

Pillar 01

Data Governance

Mandatory DPO function for public authorities: citizen data mapping, DPIAs, breach protocols, and regulator liaison under GDPR Article 37.

Insurance add-on available

Pillar 02

Cybersecurity

24/7 monitoring, detection, and incident response protecting public systems and citizen data — with disaster recovery and continuity planning.

Insurance add-on available

Pillar 03

AI Governance

EU AI Act compliance for government AI deployments: risk classification, human oversight, conformity documentation, and accountability frameworks.

Insurance add-on available

The accountability challenge

Accountability that
holds up under scrutiny.

Regulated organisations are required to govern data and AI, face escalating cyber risk, and cannot easily access affordable, integrated protection. Competitors address one layer — a DPO service, a managed-security provider, or a cyber insurer — but not the full governance-plus-protection stack as one relationship.

⚖️

Audit and regulatory scrutiny

Internal auditors, the Court of Auditors, supervisory authorities, and parliamentary committees all scrutinise data and AI practices. Documented governance evidence is the only defensible response — and most public institutions lack it.

🔗

Mandatory legal obligations without in-house capacity

GDPR Article 37 mandates DPO appointment for all public authorities. The EU AI Act imposes governance duties on every government body deploying AI. Skilled data protection and AI governance professionals are scarce and expensive to hire in-house.

🏢

Political and reputational risk from AI and data failures

Existing managed-security and cyber-insurance offerings are priced and scoped for large enterprises, leaving the SME majority exposed. Our delivery model changes that cost structure fundamentally.

Three governance pillars

Built for public sector
accountability requirements.

Public institutions cannot separate data governance from cybersecurity from AI oversight — auditors and regulators examine all three. Our three pillars are designed to work together: the DPO function produces the documentation that satisfies data protection authorities; the security layer provides the incident-response capability that auditors require; and the AI governance pillar addresses the growing scrutiny of algorithmic decision-making in public services.

01

Data Governance

DPO-as-a-Service

Mandatory DPO function for public authorities under GDPR Article 37. Covers citizen data mapping, record of processing activities, DPIA support for high-risk processing, breach notification protocols, and liaison with supervisory authorities. Structured to meet the independence requirements that apply to public sector DPOs.

Data mapping & registers DPIA support Breach response NDPA / GDPR Regulator liaison
Live — Phase 1

Insurance referral available

02

Cybersecurity

Managed Security

Continuous monitoring, threat detection, incident response, and business continuity for public sector environments. Covers NIS2 obligations for operators of essential services, critical infrastructure protection, and in-country data sovereignty requirements. Structured around the auditability requirements that public institutions face.

24/7 monitoring & detection Incident response Disaster recovery Forensics In-country hosting
Live — Phase 1

Insurance referral available

03

AI Governance

AI Governance-as-a-Service

Government AI systems — benefits assessment, permit processing, fraud detection, resource allocation — frequently fall into the EU AI Act's high-risk category. We deliver the AI system inventory, risk classification, human oversight documentation, and fundamental rights impact assessments that public institutions are required to produce and maintain.

EU AI Act readiness Annex IV documentation Risk classification ISO 42001 gap assessment Algorithmic red team
Phase 3

Insurance referral available

Enterprise & Government Entry Wedge

Governance Diagnostic — Entry Engagement

Every government engagement opens with a scoped, fixed-fee governance diagnostic — a structured review of data processing activities, AI systems in use, and cybersecurity posture. The diagnostic produces a written report that satisfies procurement requirements and surfaces gaps the three pillars address. The fee is credit-backable against the resulting service agreement, removing budget risk and providing immediate audit-ready evidence of due diligence.

How we work with public institutions

Fixed-scope.
Audit-ready.
No open-ended billing.

Every engagement begins with a fixed-scope, fixed-fee agreement — no open-ended billing, no surprises at budget review. Deliverables are defined before work starts, making engagement costs predictable for procurement and approvable through standard government purchasing channels. All outputs are structured for auditability: documented, version-controlled, and ready to present to supervisory authorities or internal auditors on request.

DPO retainer

Mandatory under GDPR Art. 37 for all public authorities — recurring, documented, independent

Managed security

Continuous monitoring with NIS2 alignment and audit-ready incident logs

Governance diagnostic

Fixed-fee scoped entry engagement — credit-backable against full agreement

Incident response

72-hour breach notification support, regulator liaison, forensic documentation

AI governance

EU AI Act compliance for high-risk government AI systems — Phase 3

Government procurement pathway

The governance diagnostic

Every government engagement opens with a scoped, fixed-fee governance diagnostic — approvable through standard procurement channels and producing audit-ready evidence of due diligence before the full agreement begins.

01Fixed-fee diagnostic scoped and priced upfront — predictable, procurement-approvable
02Diagnostic reviews data processing, AI systems, and security posture — produces written gap report
03Diagnostic fee credited against the full service agreement — no double-budget commitment
04Full governance agreement signed; ongoing documentation and audit-readiness maintained

Free governance assessment

Know your audit
exposure before
auditors do.

Written governance summary — delivered within 24 hours

A professional written assessment — not an automated score. Your regulatory obligations, compliance gaps, and the top three risks a supervisory authority or auditor would identify.

Covers all three governance pillars

Data protection (GDPR mandatory obligations), cybersecurity posture (NIS2), and AI governance (EU AI Act Annex III) — one assessment, three accountability dimensions.

No commitment, no open-ended billing

You receive a substantive written output at no cost. If you want to proceed further, we provide a fixed-scope, fixed-fee proposal — fully costed before anything is signed.

Free Exposure Check

No cost · No commitment · Delivered within 24 hours

National and local public authorities

Request received.

Your written exposure summary will be in your inbox within 24 hours. For urgent questions email hello@align3.ai directly.

Get in touch

Start with a free
governance review.

Every engagement begins with a complimentary 30-minute call. We review your data processing activities, AI systems in operation, and cybersecurity posture — identify your mandatory obligations and audit gaps — and confirm the right scope and cost before anything is signed.

ResponseWithin 1 business day

Book a Discovery Call

Complimentary · 30 minutes · No obligation

Fixed-fee engagement letter within 48 hours

Message received.

We will be in touch within one business day to confirm your discovery call.

FAQ

Frequently asked questions.

We deliver the three governance functions that public authorities are legally required or expected to maintain: data protection (mandatory DPO under GDPR Article 37), cybersecurity (NIS2 and operational resilience), and AI governance (EU AI Act obligations for high-risk government AI systems). We provide these as a single integrated relationship rather than three separate vendors with no coherence between them.
Yes. We work with both national ministries and agencies and local and municipal authorities. The mandatory obligations are the same at both levels — GDPR Article 37 DPO requirement, EU AI Act obligations, NIS2 for relevant functions — but the resource constraints and procurement processes differ. We scope and price engagements accordingly.
Because we act as outsourced DPO while also providing security services the DPO is meant to assess independently, the DPO function is ring-fenced with documented conflict-of-interest controls, separate reporting lines, and clear client disclosures. This is a design requirement from day one, not a later fix.
Insurance is an optional add-on referred through a licensed partner — not a requirement to engage with Align3.ai. Clients who want matching insurance coverage for their data, cyber, or AI risk can access it through our partner network at any point in the engagement. Our services stand alone and deliver full value without insurance.
Every government engagement starts with a scoped, fixed-fee governance diagnostic — a structured review of data processing activities, AI systems in operation, and cybersecurity posture, producing a written gap report. This is approvable through standard public procurement channels and provides immediate audit-ready evidence of due diligence. The diagnostic fee is fully credit-backable against the subsequent service agreement, removing any risk of double budget commitment.
The AI governance pillar is deliberately sequenced as Phase 3 — the risk is still nascent and barely priced in insurance markets. However, EU AI Act advisory and readiness assessments are available now. The full AI-governance-as-a-service pillar, with optional insurance referral, launches when the risk becomes priceable at scale.

Free download

Public Sector AI & Data
Audit Readiness Checklist.

A one-page PDF covering the 14 checks every public institution should complete before an audit, supervisory authority review, or parliamentary inquiry. Covers GDPR DPO obligations, EU AI Act requirements for government AI systems, and cybersecurity minimum standards. Free — no conditions.

EU AI Act classification — identify which government AI systems are high-risk under Annex III
GDPR mandatory requirements — DPO appointment, ROPA, DPIA obligations for public authorities
Audit-readiness signals — what supervisory authorities, auditors, and parliamentary committees look for

Get the free audit checklist

One PDF · Instant download · No spam

No marketing emails — just the PDF.

Ready-to-use resources

Templates built for
public sector compliance.

Practical governance assets for public sector teams working under time and resource constraints. Each template is reviewed by our compliance team and mapped to current GDPR, EU AI Act, and NIS2 requirements for public authorities.

Free

Public Sector AI Act
Audit Readiness Checklist

14-point checklist for public institutions: GDPR DPO status, EU AI Act Annex III system identification, human oversight documentation, and fundamental rights impact assessment requirements. One page, printable.

Download free →

Template pack

Government AI System
Register Template

Pre-built XLSX template for public authorities to inventory AI systems, record Annex III classification, document human oversight mechanisms, and track compliance status. Designed for audit presentation.

Request template →

Guide

Fundamental Rights Impact
Assessment Guide

A practical guide to conducting the Fundamental Rights Impact Assessment required under Article 27 of the EU AI Act for public authorities deploying high-risk AI systems. Includes template and worked example. PDF format.

Request guide →

More resources in development. Subscribe to the newsletter to receive new releases first.

Fortnightly newsletter

The Align3 Brief.
Governance, accountability and AI.

A fortnightly briefing on EU AI Act implementation for public authorities, GDPR enforcement actions affecting the public sector, NIS2 updates, and AI governance developments. Written for DPOs, legal advisors, and senior officials — not IT departments. Read in under five minutes.

EU AI Act implementation for public authorities — delegated acts, GPAI guidance, supervisory signals
GDPR enforcement affecting public bodies — supervisory authority decisions and their implications
Practical governance actions — what public institutions should do this fortnight

Subscribe to The Align3 Brief

Fortnightly · Free · Unsubscribe any time

No spam. Unsubscribe any time.

Governance that
holds up.

Start with the free audit checklist, request a written governance assessment, or book a 30-minute review call. Know exactly where you stand before your next audit, supervisory review, or parliamentary inquiry.

Free checklist Exposure check Book a call