Clarify the current position
Establish the scope, dependencies, risks, and evidence needed for a decision.
AI governance & readinessEstablish the AI inventory, responsibilities, and priorities for the systems in scope.
Your teams are introducing AI, but ownership, review criteria, or the current inventory are incomplete.
Work included
- Interview business, security, privacy, and technical owners to define use cases and affected stakeholders.
- Review existing policies, AI inventories, approval routes, and risk-assessment practices.
- Identify governance gaps and prioritize work against business needs and the organization’s risk tolerance.
What you receive
- Scoped AI inventory and use-case profiles
- Governance gap assessment and responsibility map
- Prioritized implementation roadmap
AI risk & impact assessmentReview potential effects on people, business operations, and the use of AI outputs.
An AI system influences decisions or services, and you need to understand its wider risks before adoption or expansion.
Work included
- Identify affected people, intended benefits, foreseeable misuse, and potential adverse effects in the application context.
- Review available evidence on reliability, privacy, harmful bias, transparency, and human oversight where relevant.
- Document impact scenarios, assessment limitations, control needs, and decisions requiring specialist or leadership review.
What you receive
- Scoped AI risk and impact assessment
- Stakeholder, impact, and control mapping
- Recommended mitigations and review triggers
AI security risk assessmentReview the architecture, data flows, permissions, and plausible threat scenarios.
You need a risk decision on a generative-AI application, agent, enterprise platform, or material system change.
Work included
- Map data sources, retrieval components, model services, tools, identities, and trust boundaries.
- Assess prompt injection, sensitive-data exposure, excessive permissions, insecure integrations, and relevant poisoning scenarios.
- Define risk-rating criteria, assess existing controls, and document assumptions and evidence gaps.
- Review findings with the responsible teams and recommend risk treatment and reassessment triggers.
What you receive
- System context and threat-model record
- Risk register with rating rationale and control gaps
- Technical findings, executive summary, and remediation recommendations
Vendor & system due diligenceExamine provider evidence before procurement, integration, or expansion.
A vendor demonstration or questionnaire leaves questions about data use, security, support, or your responsibilities.
Work included
- Compare documentation and available test evidence with the intended application and operating requirements.
- Review data handling, retention, model limitations, dependencies, access, incident processes, and shared responsibilities.
- Track unanswered questions and identify issues requiring security, privacy, legal, or engineering review.
What you receive
- Vendor assessment and evidence-request register
- Dependency and responsibility map
- Decision brief with adoption conditions and unresolved questions














