[ AI IN REGULATED ENVIRONMENTS ]

Get past the compliance review with controls you can show.

In finance, health, legal and the public sector, AI ideas stall in review because nobody can show where the data goes. We build the controls: masking, residency decisions, audit trails and a usable policy. Your counsel decides what they mean legally.

PII masking before promptsAudit trailsNo legal advice

[ 01 — WHERE IT GOES WRONG ]

Why regulated teams get stuck on AI.

The rules are not the blocker. The missing evidence is.

  • [ 01 ]

    Shadow AI

    While the review drags on, staff use personal accounts on public tools. The risk you wanted to avoid is already there, unseen.
  • [ 02 ]

    A policy nobody can follow

    Thirty pages of principles do not tell an adviser what she may paste into which tool today. Rules have to be short and role-based.
  • [ 03 ]

    Masking that was never tested

    A masking layer that has not been run on real documents misses names in odd places. Its gaps have to be measured, not assumed.
  • [ 04 ]

    No record

    When a supervisor or auditor asks who used which model on which data, an answer from memory does not count. Logs have to exist before the question.

[ 02 — WHAT YOU GET ]

Technical controls and clear paperwork.

Rules such as revDSG, GDPR, the EU AI Act and sector expectations (for example from FINMA) shape what is allowed. We translate your legal team's decisions into working guardrails.

  • [ 01 ]

    AI use inventory

    A list of where AI is or will be used, which data it sees, the model and provider, and who owns each use.
  • [ 02 ]

    PII masking and redaction

    Names, account numbers and other identifiers are replaced before a prompt reaches a model, and restored only where allowed.
  • [ 03 ]

    Data residency and provider choice

    Documented decisions on where processing runs and which providers may be used for which data class.
  • [ 04 ]

    Audit trails

    Who asked what, which model answered, what the human decided. Retained for the period your rules require.
  • [ 05 ]

    Policies and training

    A short, usable AI policy and role-based training so staff know what is allowed with which data.

[ 03 — HOW WE DE-RISK IT ]

How niivo takes the risk out.

We work next to your compliance, legal and IT roles, not around them.

  • [ 01 ]

    Your counsel decides

    We prepare options for each use: provider, region, masking, retention. Legal interpretation and sign-off stay with your counsel and compliance function.
  • [ 02 ]

    Controls tested on your documents

    Masking runs on your real samples, and we report what it misses. It is combined with access rules and provider choice, because no single control is enough.
  • [ 03 ]

    Records from day 1

    Logs, an inventory and documented decisions exist before the first question from an auditor.
  • [ 04 ]

    Data handled in your environment

    We work on samples or masked data inside your environment, and agree the handling in writing before we start.

[ 04 — PROCESS ]

From inventory to working controls.

We work alongside your compliance, legal and IT roles.

  1. 01

    Inventory and data classes

    We list AI uses, including shadow use, and sort the data involved into classes with your compliance lead.1 to 2 weeks
  2. 02

    Decisions on paper

    We prepare the options for each use: provider, region, masking, retention. Your counsel reviews and decides.2 weeks
  3. 03

    Build the controls

    Masking layer, logging, access rules and approval steps, implemented for one pilot workflow.4 weeks
  4. 04

    Review routine

    A periodic check of logs, incidents and changes in rules or providers.Quarterly

[ 05 — USE CASES ]

Where controls make it possible.

Typical scenarios. None of these describe a specific client.

Client correspondence drafts

Today
Advisers cannot paste client mails into a chatbot.
With the workflow
Identifiers are masked, the model drafts, and the adviser restores names and checks the text before sending.

Case file summaries

Today
Summaries of long files are written manually.
With the workflow
A model in an approved region summarises with citations. Access and requests are logged.

Shadow AI clean-up

Today
Staff use personal accounts on public tools.
With the workflow
An approved tool with a clear policy replaces them, with usage visible to the AI owner.
EXAMPLE — ILLUSTRATIVE DATA, NOT A CLIENT RESULT

[ 06 — SCOPE & PRICE ]

An assessment before any build.

Compare the assessment with the cost of a stalled review: months of waiting, staff working around the rules on public tools and an incident nobody can reconstruct. The assessment gives your compliance team something concrete to decide on.

Regulated AI assessment · 3 to 4 weeks

from CHF 6,500fixed scope · excl. VAT

This is not legal advice. Implementing the controls is quoted separately. Extensions: CHF 2,200 per day.

  • AI use inventory and data classes
  • Data flow map
  • PII masking concept
  • Draft AI policy for your counsel to review

[ 07 — QUESTIONS ]

What people ask about regulated AI.

Is this legal advice?

No. niivo provides technical and organisational guidance. Legal interpretation and compliance decisions rest with your counsel and your compliance function.

Can you make us compliant?

No one can promise that from the outside. We help you build controls and records that your compliance team can assess.

Does masking remove all personal data?

It reduces exposure, but it is not perfect. We test it on your real documents, report what it misses and combine it with access rules and provider choice.

Do you cover the EU AI Act?

We cover awareness and practical steps such as an inventory and risk-level sorting of your uses. The legal assessment stays with your counsel.

Does our data end up training a provider's model?

Business API terms of the main providers generally exclude it, but terms differ and change. We read them with you per data class and record the result. For data that cannot leave, we use local models.

Where does our data go during this work?

We work on samples or masked data where we can, inside your environment. We agree the handling in writing before we start.

Start with the rules you have to meet.

Bring your compliance lead to the intro call. We map what can be built.

Book an intro call