AI Governance & Compliance

Practical AI governance for SMEs.

Unknown or inconsistent AI use can raise data-protection, confidentiality and security questions. We map the agreed starting point, help shape internal guardrails and review selected Microsoft 365 settings. Scope and deliverables are agreed in advance; this is not a blanket compliance or security guarantee.

Shadow AI Audit

We map known AI use and review which data flows and risks should be examined within the agreed scope.

FADP Policies

Within the agreed scope, we draft internal AI-use guidelines and identify relevant Swiss data-protection questions for the specific use.

Microsoft Hardening

We review and configure agreed Microsoft 365 safeguards to help reduce unintended disclosure risk.

Our Governance Services

Security Philosophy

Freedom through clear boundaries.

Clear guidance helps teams use AI tools thoughtfully. We review actual usage, discuss suitable alternatives and document responsibilities, open privacy questions and next steps.

From a live engagement

We are writing the AI usage rules for a Swiss client rolling out Copilot right now.

Is your IT Governance ready for AI?

Let's clarify in 15 minutes what security gaps Copilot could open for you and how to close them quickly.

Book governance call

Four steps to clear AI usage rules

01

Audit & Inventory

We scan your logfiles and identify anonymously which tools your team uses and what data flows there.

02

Policy & Releases

We write your AI employee guidelines and define clear release paths for sensitive data.

03

Technical Hardening

We activate and configure your Microsoft security settings (Sensitivity Labels, DLP).

04

Training & DPIA

We train your team and hand over the complete Data Protection Impact Assessment for your files.

Governance Deliverables

01
Shadow AI Inventory (list of all used AI tools)
02
Draft AI usage policy within the agreed scope
03
Documented configuration of your Microsoft 365 tenant security
04
DPIA documentation when required and included in scope
05
Employee training log & sensitization presentation
06
Approved list of secure alternative tools for your team
Laura Hähni - Hähni Büro
Laura Hähni
CFO & Compliance Officer, bdlh.ch
“We knew our employees used ChatGPT, but had no idea that sensitive financial data flowed there. The governance sprint closed this gap in 4 weeks. We now have clear policies, Microsoft Purview is active, and our team knows exactly what is allowed.”

Why schnellstart.ai?

Data
understand flows for the agreed use
Rules
document responsibilities for your team
Next steps
prioritize open questions

Governance Stack: Microsoft + Swiss Additions

We activate what you already have in your M365 license, and add Swiss-hosted where it truly matters for compliance.

Microsoft 365 Copilot logo

Microsoft 365 Copilot

FADP-compliant Configuration

Microsoft 365 Copilot with Sensitivity Labels, DLP rules and tidy SharePoint permissions. Productive without oversharing risk.

Microsoft Purview logo

Microsoft Purview

DLP & Compliance

Microsoft Purview for Sensitivity Labels, Data Loss Prevention and audit logging. Already included in most M365 licenses, just not activated.

Azure OpenAI (Swiss) logo

Azure OpenAI (Swiss)

Swiss-region OpenAI

Azure OpenAI in the Swiss region (Zurich), GPT models without data flowing to the US. For critical use cases with data residency requirements.

Infomaniak logo

Infomaniak

Swiss Hosting

Swiss cloud provider for AI models and workflows that don't run through Microsoft. 100% in Switzerland, B-Corp certified.

n8n (Swiss-hosted) logo

n8n (Swiss-hosted)

Workflow Automation

n8n on Swiss servers for governance workflows: audit trails, approval flows, vendor onboarding. Self-hosted, no vendor lock-in.

Entra ID & Defender logo

Entra ID & Defender

Identity & Shadow AI

Entra ID app audit, Conditional Access and Defender for Cloud Apps, the identity and monitoring layer that makes shadow AI visible.

Regulated Industries

AI Governance for highest confidentiality.

Especially in law, fiduciary, and finance sectors, data protection is vital. We adapt your governance setup to your professional secrets.

Automated document processing, client portals and FADP-compliant data systems. We connect your existing tools (Bexio, Abacus, KLARA) into a seamless workflow.

View governance industry example

Project management dashboards, automated quoting processes and document management. Digitalization for construction projects: from proposal to final billing.

View governance industry example

Patient portals, appointment management and secure data systems. EPD integration and FADP-compliant AI solutions for practices, home care and clinics.

View governance industry example

Automated document analysis, client management and FADP-compliant communication. AI tools that reduce routine tasks in law firms.

View governance industry example

ERP integration, digital project management and AI-powered process optimization. Software for manufacturing SMEs, from order to delivery.

View governance industry example

Shop integration, inventory automation and customer analytics. We connect online and offline channels into a seamless customer journey.

View governance industry example

Your auditors

Lukas Huber
Lukas Huber
AI governance & privacy questions
Florian Witschi
Florian Witschi
Microsoft 365 Tenant Hardening
Request AI Governance Audit now
“Schnellstart built our entire digital backbone. We went from a concept to a fully automated inbound machine in weeks.”
Viktoria
Viktoria
Alventis
Read Full Story
Alventis – Case study detail view
Alventis

Let's talk straight

Direct with me. No funnel, no sales pitch.

Or go direct: Call · WhatsApp

You'll usually reach Lukas by phone Mon⁠–⁠Fri, 10 am⁠–⁠12 pm and 1⁠–⁠6 pm Swiss time. If he's with a client, he'll call you back, usually by the next working day.