AI Governance & Risk Assessment

One assessment. Every framework you answer to.

Defensible AI-risk posture for organisations already using AI — without another year of spreadsheet audits.

Concrete atrium in black and white, looking up through nested frames toward a skylight
Mapped to NIST AI RMF ISO/IEC 42001 EU AI Act NIST CSF 2.0 CIS v8
The problem

AI is already in your environment. Your control set isn't.

ChatGPT, Copilot, vendor-embedded AI, agentic tools — adopted team by team, mostly without a control decision. Meanwhile NIST AI RMF, ISO 42001, the EU AI Act, and sectoral law each expect evidence you probably aren't collecting yet. And what could go wrong across prompts, models, or agents has no one good owner — and no one good answer.

Why one-off audits don't close the gap

Single-framework checklist

Passes the audit, misses jurisdictional exposure — EU AI Act, US state law, FDA, HIPAA.

Spreadsheet maturity audit

A snapshot only. No provenance, no evidence trail, no second-pass review — and it ages in weeks.

Vendor self-attestation

Misses the AI features your vendors quietly added — model changes, new sub-processors, agentic behaviour.

Internal working group

Stalls on "which framework do we map to first".

The approach

One assessment. Mapped to every framework you need to answer to.

Your team answers a question once. We tell you what it means under every regime that applies to you.

NIST AI RMF 1.0

Plus the NIST Generative AI Profile.

ISO/IEC 42001

The AI management system standard.

EU AI Act

Provider, deployer, and GPAI obligations.

Sectoral regulation

Clinical, life sciences, financial services, public sector.

Jurisdictional law

EU, UK, IE, US (federal + CA / CO / NY), Canada, Australia, Singapore.

NIST CSF 2.0 + CIS v8

The cyber underlay, where it touches AI.

10
AI domains
Governance to vendor AI
14
Industries
Tuned to your context
4
Model types
LLM · vision · predictive · agentic
11
Jurisdictions
On the bench

Cyber controls are assessed where they touch AI. A full cyber review can be added on request.

How it works

A structured engagement, not a survey

Every finding flows into a custom AI-powered Risk Register, configured for your organisation — owners, control mappings, and statuses, ready for the GRC process you already run.

01

Profile

Industry, size, scope, jurisdiction, model types in use — drives which questions you actually see.

02

Assess

A filtered question set across 16 sections. Existing policies and contracts pre-populate evidence via document analysis.

03

Review

Every finding is triaged by an assessor — accepted findings become Risk Register entries with an owner and a control mapping, carried over automatically.

04

Report & track

Scored findings, prioritised mitigations, and a 12-month roadmap — Word export for board and audit, register entries tracked to closure.

The assessment identifies. The register manages. Nothing falls through the gap.

What you walk away with

Findings tied to your business — not a report that sits on a shelf

Provenance on every question — each carries the frameworks and clauses it maps to.

Findings link to evidence — every conclusion points back to the document behind it.

Reviewer sign-off — nothing reaches the report without second-pass human review.

Document analysis does the heavy lifting — your policies are read for you, and cited where they count.

Where you stand

Scored maturity across the 7 executive domains your board cares about — Governance, Risk & Controls, Data & Privacy, Model Lifecycle, Workforce, Third-Party Risk, Responsible AI.

Where you're exposed

Every finding traced to the specific NIST / ISO / EU AI Act control that puts you on the hook — so legal, risk, and the business each know what they own.

What to do about it

Prioritised mitigations and a 12-month roadmap, sized to your risk appetite — register entries ready for the GRC tool your team already uses.

Credit for the work you've already done

Existing policies, contracts, and controls surfaced as evidence behind every relevant finding — no starting from zero.

A narrative your board will read

A Word document built for committee, audit, and regulator-facing use — a story about the business, not a spreadsheet of controls.

Next steps

What it takes to start

From you

A 30-minute scoping call, a nominated programme owner, and — optionally — your current AI policy, AUP, and a few representative vendor contracts to accelerate the assessment.

From us

A profile and question set tailored to your context within 48 hours of scoping, a confirmed engagement window, and a secure client link so your team can begin immediately.

Let's scope it. Book a scoping call