Why firms work with us

Specialist focus
We advise on ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001, and the client and buyer security reviews that decide enterprise deals.

Experience since 2013
We have advised regulated firms on authorisation, compliance and regulator engagement for over a decade.
Senior-led compliance support
Every engagement is led by senior specialists with decades of regulatory practice behind them. Clients work directly with the people doing the work, supported by the judgement that comes from taking firms through certification, examination and client scrutiny.
AI governance services built for firms deploying AI
AI governance readiness
We assess your AI systems, policies and evidence against the standard you are being measured on, identify gaps and set out what certification or a client review will require.
AI inventory and classification
We build a complete register of the AI systems you develop, buy and embed, classify each one by the risk it carries and assign accountable owners.
ISO/IEC 42001 implementation
We design and stand up your AI management system, from scope and risk methodology through to the statement of applicability, controls and supporting evidence.
Internal audit
ISO 42001 and ISO 27001 both require an annual internal audit that your certification body cannot perform. We conduct it independently and report findings for management or board review.
Certification support
We prepare your evidence and your people for Stage 1 and Stage 2, and attend the audit alongside you through to certification.
EU AI Act scoping
We determine which of your systems fall in scope, classify them by risk category and map the obligations and documentation each one attracts.
Buyer and client security reviews
We answer CAIQ, SIG, DDQ and bespoke AI questionnaires from your approved evidence, and prepare reusable answers so each review is faster than the last.
AI policies and procedures
We prepare and review AI policies and procedures, covering governance, risk assessment, human oversight, data governance, third-party AI and incident handling.
Continuous assurance
We keep your evidence current between audits, covering control re-testing, evidence refresh, regulatory change monitoring and ongoing client questionnaire response.


