Services
Assessment, remediation and delivery. Engagements run from a two week gap assessment to embedded work alongside your team. Pick the one closest to your situation.
ISO/IEC 42001 readiness and assessment
For companies asked to prove AI is governed, or planning to certify.
ISO/IEC 42001 is the management system standard for artificial intelligence. It is to AI what 27001 is to information security. It is showing up in enterprise procurement faster than most companies expected. We assess where you stand against the Annex A controls, build the management system around your actual operations rather than a template, and prepare you for a certification body audit.
What we do
- Scope the AI management system to your real footprint
- Gap assessment against Annex A controls
- Draft the policy, role and review structure
- Run the AI risk and impact assessment process
- Internal audit and management review before certification
What you get
- Control coverage summary with ranked gaps
- Policy set written for your operations
- Risk and impact assessment templates in use
- Evidence pack organized for an auditor
- Readiness verdict before you pay a certification body
NIST AI RMF alignment
For boards and risk committees asking how AI risk is being managed.
The NIST AI Risk Management Framework is voluntary, which is exactly why it gets used as the common language between technical teams and the people asking the hard questions. We build your AI inventory, profile the risk of each use case, and put measurement in place so the answer to "is this under control" stops being a matter of opinion.
What we do
- Inventory AI in use, including unsanctioned tools
- Build risk profiles per use case
- Establish measurement and monitoring
- Map RMF functions onto existing controls
- Prepare board-level reporting
What you get
- AI system inventory you can maintain
- Risk profile per use case
- Measurement plan with owners and cadence
- Crosswalk to your existing 27001 or SOC 2 controls
- Reporting pack for the risk committee
Vendor security questionnaires
For sales teams with a deal sitting behind a security review.
A security questionnaire arriving late in a sales cycle is one of the most expensive delays in B2B. The questions are repetitive, the answers live in five people's heads, and the AI sections are new enough that most teams are guessing. We answer them accurately, flag the answers that are not true yet, and turn the whole thing into a maintained library so the next questionnaire is a review rather than a fire drill.
What we do
- Complete SIG Lite, SIG Core, CAIQ and custom questionnaires
- Handle the AI and subprocessor sections specifically
- Flag gaps between what is claimed and what is true
- Build a maintained answer library
- Prepare the supporting evidence buyers ask for next
What you get
- Completed questionnaire, source-referenced
- Gap list separating remediation from wording
- Reusable answer library
- Evidence pack for follow-up requests
- Faster turnaround on every questionnaire after the first
AI and automation delivery
For teams ready to build, who need it done inside their controls.
This is the build. We implement AI and automation inside your environment, against your identity, logging and data handling standards. The difference from a general AI consultancy is that the data path is designed first: what leaves your tenancy, what is retained, who can reach it, what a reviewer will see six months from now. Available as a delivery engagement or as an engineer embedded with your team.
What we do
- Use case selection and honest feasibility review
- Architecture with the data boundary defined up front
- Build against your identity, logging and DLP standards
- Human review and escalation paths where they matter
- Embedded engineer alongside your team where useful
What you get
- Working implementation in your environment
- Architecture and data flow documentation
- Access, logging and retention configured
- Runbook and handover to your team
- Evidence artifacts ready for the next audit
Audit preparation
For teams with an audit dated and evidence scattered.
Most audit pain is not control failure. It is evidence that exists but cannot be found, controls that are operating but undocumented, and a team that has never been asked these questions in this order. We organize the evidence, map it to the controls being tested, and run a mock audit so the first time anyone hears the hard question is not in the real session.
What we do
- Map controls to the evidence that proves them
- Collect and organize the evidence pack
- Identify gaps early enough to remediate
- Run a mock audit with your team
- Support you through fieldwork
What you get
- Organized, indexed evidence pack
- Control-to-evidence mapping
- Remediation list with time to close
- Mock audit findings before it counts
- A team that has rehearsed the questions
Not sure which one you need?
Describe the situation on a call and we will point you at the right starting place, even if that turns out not to be us.