Determination, then discovery. Never the other way round.
Most AI governance work starts by cataloguing systems and then asking which rules might apply. We start from the obligations, because that is what decides which questions are worth asking.
Five stages.
Determine
Thirty to fifty structured questions establish your entity, jurisdictions, licences, sector, data and AI use cases. A deterministic engine returns what applies, what conditionally applies, what does not, and what is on the watchlist — each line citing a clause.
Discover
We find the AI you are actually running. Declared through structured interviews across technical, functional and executive tracks; detected through read-only cloud connectors; inferred from the software estate, because most enterprise AI arrived inside products already bought.
Assess
Each system is risk-classified on five axes — impact on people, autonomy, reversibility, data sensitivity, scale — scored from answers you gave, never from our impression. Controls are then mapped to your obligations and tested against the evidence you hold.
Remediate
Every gap becomes a finding with an owner, a date, a target architecture and an effort band. Nothing is left as an observation.
Govern
Attestations expire. New systems appear. Regulations move. Continuous governance keeps the picture true and tells you which of your systems a regulatory change actually touches.
Five rules we hold to.
These are the parts that survive contact with a regulator.
No claim without a source
Every fact we report carries who said it, when, through what channel, and at what confidence. Where two people disagree, we surface it rather than pick one quietly.
Determination is deterministic
No language model participates in deciding what applies to you. The engine evaluates declared rules and shows the predicate behind every line.
Effectiveness is derived, never asserted
A control cannot be marked effective without dated, sourced evidence. Attestations expire on schedule and the control visibly reverts to unknown.
No benefit without a baseline
We will not state a saving or an improvement without your measured starting point, a target, a measurement method and a date. Assumed percentages are how business cases lose credibility.
We say what does not apply
Scoping a programme down is more valuable than scoping it up, and far rarer. If a regulator does not reach you, we will say so and show why.
Readiness, not compliance
We produce evidence, findings and gaps. Regulators determine compliance and certification bodies certify. We never claim either.
What we are, and what we are not.
Not a law firm
We provide regulatory information, applicability analysis and implementation guidance. Legal interpretation stays with your counsel.
Not a certification body
We prepare you for certification and produce the evidence pack. Accredited bodies certify.
Not a software vendor
We sell engagements. The tooling that makes them fast is ours and stays ours.