Your AI governance framework is written.
Can you evidence it operating?
An independent readiness assessment of whether your AI risk controls exist inside your delivery process, or only inside your policy documents. Fixed scope, delivered remotely, mapped to the way your engineers actually ship.
45 minutes with whoever owns your delivery process. You receive a one-page gap sketch. No charge, no obligation.
The risk isn’t the framework. It’s the distance between the framework and the release process.
Policy is written by risk. Controls are implemented by engineering. The attestation is signed by you, which means the person carrying personal accountability is the one with the least direct visibility into whether the control is real.
Most organisations will be compliant on paper. Far fewer can evidence a control operating: a re-review actually triggering when a model changed, a human-oversight decision reconstructable from last quarter, a third-party model update noticed at the time rather than in hindsight.
Regulators and enterprise customers moved at the same time.
Every major jurisdiction now has an AI risk framework in force or in flight, and the transition windows are short enough that the work has to start before the final wording lands. Most of the pressure, though, arrives through procurement. Vendor security questionnaires now routinely ask about AI governance posture, and the answer is increasingly a condition of renewal.
The two elements that take longest don’t change with the final wording: a complete AI inventory, and a materiality assessment actually applied to it.
- ✓AI inventoryEvery model and AI-enabled process in production, including the vendor AI that arrived inside a tool procurement bought rather than something you built.
- ✓Risk materiality tieringApplied to the inventory across impact, complexity and reliance. Not documented as a methodology and left unused.
- ✓SDLC control mapWhere each governance obligation lands in your actual delivery process: intake, review, testing, release, change management.
- ✓Evidence gap assessmentFor each material control, one question: asserted, or demonstrable on request?
- ✓Third-party AI exposureWhich vendor models changed, when, and what mechanism noticed.
- ✓Costed remediation roadmapSequenced by exposure and effort, with named owners.
A framework engagement works top-down from policy and produces a governance model. That work is necessary, and you may already have it underway.
This works bottom-up from your release process, and answers a narrower question: did any of it actually get implemented in the way your engineers work?
It is designed to sit alongside existing advisory work rather than replace it. It takes weeks rather than months, and it costs a fraction of the programme it validates.
Start with a readiness read
Forty-five minutes with whoever owns your delivery process. You receive a one-page sketch of where your controls are asserted rather than evidenced, and what each would take to close.
No charge and no obligation. If the sketch is useful, we can talk about doing it properly.
Request a readiness read →