top of page
Blue Light Gradient

AI Governance and Compliance
Support for Firms Deploying AI

We provide AI governance and compliance support for firms building, buying and selling AI, either alongside an existing compliance function or as outsourced senior support.

Why firms work with us

wired-gradient-457-shield-security (2).gif

Specialist focus

We advise on ISO/IEC 42001, the EU AI Act, SOC 2 and ISO 27001, and the client and buyer security reviews that decide enterprise deals.

wired-gradient-204-chat-message-heart.gif

Experience since 2013

We have advised regulated firms on authorisation, compliance and regulator engagement for over a decade.

Senior-led compliance support

Every engagement is led by senior specialists with decades of regulatory practice behind them. Clients work directly with the people doing the work, supported by the judgement that comes from taking firms through certification, examination and client scrutiny.

AI governance services built for firms deploying AI

AI governance readiness

We assess your AI systems, policies and evidence against the standard you are being measured on, identify gaps and set out what certification or a client review will require.

AI inventory and classification

We build a complete register of the AI systems you develop, buy and embed, classify each one by the risk it carries and assign accountable owners.

ISO/IEC 42001 implementation

We design and stand up your AI management system, from scope and risk methodology through to the statement of applicability, controls and supporting evidence.

Internal audit

ISO 42001 and ISO 27001 both require an annual internal audit that your certification body cannot perform. We conduct it independently and report findings for management or board review.

Certification support

We prepare your evidence and your people for Stage 1 and Stage 2, and attend the audit alongside you through to certification.

EU AI Act scoping

We determine which of your systems fall in scope, classify them by risk category and map the obligations and documentation each one attracts.

Buyer and client security reviews

We answer CAIQ, SIG, DDQ and bespoke AI questionnaires from your approved evidence, and prepare reusable answers so each review is faster than the last.

AI policies and procedures

We prepare and review AI policies and procedures, covering governance, risk assessment, human oversight, data governance, third-party AI and incident handling.

Continuous assurance

We keep your evidence current between audits, covering control re-testing, evidence refresh, regulatory change monitoring and ongoing client questionnaire response.

bottom of page