Govern · pillar 3 of 3
Senior technical oversight without a full-time hire.
Govern is the advisory and governance pillar. Fractional CTO, AI sizing, compliance advisory, security and AI retainers, annual reviews. The strategic layer that sits above the build and the run.
Day-rate, monthly retainer, or fixed-fee one-off. We do not require a long lock-in. The right engagement starts when you need one and ends when you do not.
What we provide
Fractional CTO
£5,500/m (1 day/wk), £10,500/m (2 days/wk), or £1,100/day ad hocStrategic technology leadership for organisations that need a senior technical decision-maker but not a full-time hire. Retainer covers 1 day per week, with a 2 days/week tier for organisations needing deeper coverage, both with named monthly deliverables. Day-rate available for scoped engagements without a retainer.
AI Sizing Scope
£750 (one-off)A 2-hour workshop and a written recommendation. Right-sized model selection, deployment mode, cost projection, lawful-basis check. Often the honest answer is you do not need AI for this — it is an automation workflow. We will say so before you have spent the money.
Sovereignty & Compliance Audit
£8,500 fixed, 2-3wk (up to £15,000 multi-site/complex)Full estate review, framework-mapped gap analysis (GDPR, DSPT, Cyber Essentials, ISO 27001, NIS2, DORA), risk register, and a costed exit roadmap — ending in a findings session with your team. See the dedicated Compliance Audit page for the full scope.
DSPT V8 Advisory
from £2,500 per annual cycleGap assessment and evidence review for the Data Security and Protection Toolkit, V8 schema. Aimed at NHS supply-chain organisations — the June 2026 audit deadline has passed, so this is urgent for anyone not yet submitted. Output is a remediation plan you can hand to your team or to us. A distinct, recurring SKU from the one-off Sovereignty & Compliance Audit above.
ISO 27001 Readiness
£9,500 fixed (orgs under 50 staff)Gap assessment, policy framework, audit-readiness review. Fixed fee for organisations under 50 staff; certification body fees are excluded. Larger orgs are scope-dependent.
AI Monthly Retainer
£300/m starter, £1,200/m activeOngoing oversight on a deployed AI system: prompt and model monitoring, drift checks, lawful-basis maintenance, periodic red-team probes. Starter for scheduled review. Active for organisations changing prompts and models on a recurring cadence.
Security Posture Retainer
£750/m advisory, £2,000/m activeAdvisory tier is a monthly review and a quarterly written report. Active tier includes ongoing exposure-surface monitoring, dependency upgrades, and incident-response support.
Annual Security Review
£1,500 (one-off)A written report once a year. Targeted at organisations that do not need an ongoing retainer but need an independent attestation for their board, their insurer, or their auditor.
AI Governance
scope-dependentLawful-basis frameworks, AI risk register, EU AI Act readiness for in-scope deployments. Aimed at organisations preparing internal policy for staff use of AI or external policy for AI-driven services.
Compliance Advisory
scope-dependentSOC 2 readiness, NIS2 in-scope assessment, FCA SYSC mapping, sector-specific frameworks. Scoped per engagement.
When Govern fits
You do not have a CTO and need one
Board reporting, vendor selection, architecture decisions, hiring support — without a full-time hire. Fractional CTO retainer covers it.
You have an audit coming
DSPT V8 (NHS supply chain), ISO 27001, SOC 2, NIS2 in-scope. We map what you have against what the audit asks for, and produce a written remediation plan.
You are evaluating AI and want an honest read
AI Sizing Scope is £750. Two hours of conversation, a written recommendation, and a clear answer on whether AI is even the right tool for the job. Sometimes the answer is no.
You need ongoing oversight, not another project
AI Monthly Retainer or Security Posture Retainer — recurring oversight that keeps lawful basis, prompts, models, and dependencies in good standing.
What we will not do
- · Sell you a long lock-in. Fractional engagements end when you no longer need them.
- · Recommend AI when an automation workflow is the right answer. The Sizing Scope is the place we say that out loud.
- · Audit your accounts or your governance — we are non-practising on legal and finance, and we will route you to a solicitor or accountant where the question is theirs.
- · Speak in marketing language to your regulator. Outputs are written for the audit, the auditor, or the board.
Need an honest read?
A 30-minute scoping call is free, with no obligation. We will tell you whether the engagement is the right shape — and where it is not, we will say so.
Book a scoping call →Or look at Generate for fixed-fee projects, or Operate for managed infrastructure.