ISO 42001 requires an AI system impact assessment. UK GDPR requires a Data Protection Impact Assessment. Article 22 governs automated decision-making, and the EU AI Act adds a Fundamental Rights Impact Assessment for certain high-risk deployments. These are four obligations pointing at overlapping sets of systems, and in most organisations they land on one desk.
That desk usually belongs to the Data Protection Officer, because they are the nearest available function with a governance remit and an independence requirement. It is a reasonable default and it is increasingly not working. A DPO is a privacy professional. Model risk, training data lineage, bias testing methodology, and human oversight design are not privacy questions, and asking a privacy function to answer them is asking for an answer that will not survive scrutiny.
The Fractional AI Governance Lead takes that layer. Your DPO keeps their statutory role and the privacy programme. Goldline owns the AI Management System, the AI inventory, the risk classification, and the impact assessments that sit on the AI side of the line. Where a DPIA and an AI impact assessment cover the same system, we run them as one exercise with your DPO rather than duplicating the work.
Goldline does not provide a Data Protection Officer service. Where the privacy function needs strengthening, that is a conversation about your DPO, not a service we sell.