A specialist service from CyPro
AI governance consulting for UK businesses, at fixed published prices
Your business already uses AI, with or without permission. We put the governance around it and test the systems themselves: ISO 42001 readiness, policies, risk assessments and AI penetration testing, all from one UK team.
- Every price published in full
- ISO 42001, NIST AI RMF, EU AI Act
- Governance and testing, one team
- Named UK consultants on every report
Trusted by
The services
AI governance services, from policy to penetration test
Two service lines, one practice: governance that makes your AI use defensible, and testing that proves whether your AI systems can be broken.
ISO 42001 Readiness
A clause-by-clause gap analysis against the AI management standard, with a costed roadmap to certification and support through implementation.
AI Governance Framework
A working framework that joins ISO 42001, NIST AI RMF and the EU AI Act into one set of decisions your business can actually operate.
AI Risk Assessment
Your AI systems inventoried, classified and scored with a method your auditors will recognise, from shadow ChatGPT use to production models.
AI & LLM Penetration Testing
Adversarial testing of your chatbots, LLM applications and integrations against the OWASP LLM Top 10, priced per system with a free retest.
AI Red Teaming
Scenario-driven adversarial exercises mapped to MITRE ATLAS and NIST AI RMF: harms, misuse and model behaviour under real pressure.
Agentic AI Security
AI agents act on your systems with real permissions. We assess, constrain and monitor them before autonomy becomes an incident.
What does AI governance consulting include?
AI governance consulting puts working controls around how your business builds and uses AI: an inventory of your AI systems, a risk assessment of each, policies your staff can follow, a framework that maps to ISO 42001, NIST AI RMF and the EU AI Act, and a roadmap the board can fund. Where the systems themselves need proving, AI penetration testing and red teaming supply the evidence. The same work is variously called AI governance services, AI assurance or responsible AI consulting: the substance is what matters.
Why this practice
AI governance without the mystery
Published fixed prices
Nobody else in this market publishes a single figure. Our fees are on the pricing page in full: per organisation for governance, per system for testing.
Practitioners, not policy theatre
The people who write your AI policy also test AI systems for a living. The governance advice survives contact with how models actually fail.
Mapped to the frameworks that matter
Everything we deliver traces to ISO 42001, NIST AI RMF, the EU AI Act and the UK's AI Cyber Security Code of Practice, so it stands up to scrutiny.
Governance and testing, one partner
Assess the paperwork and attack the systems with the same team. Findings from testing feed your risk register; your policies constrain what we test for.
Board-ready deliverables
Roadmaps, risk registers and policy packs written for the people who sign them off, with the technical evidence underneath for the people who act on them.
A path to ongoing ownership
When the assessment lands, the AI Responsible Officer retainer keeps governance running month to month, without hiring for a role that barely exists yet.
Your experts hold
Outcomes on record
Clients, in their own words
Good questions
Frequently asked questions
Does the EU AI Act apply to UK companies?
It can, despite the UK sitting outside it. The Act applies extraterritorially: if you place an AI system on the EU market, serve EU customers with one, or the output of your system is used inside the EU, obligations can attach to your UK business. A UK-only firm with UK-only customers is generally out of scope, but the boundary turns on facts worth checking properly rather than assuming.
Our applicability assessment gives you a documented answer for every AI system you run, with the evidence to show customers and regulators.
Is ISO 42001 worth it for a business our size?
It depends on who is asking you for it. Certification earns its keep when enterprise customers, regulators or procurement frameworks demand evidence of responsible AI management; it is rarely the right first step for a small firm with no such pressure. Many businesses get most of the value from aligning with the standard without certifying: the management system, risk process and policies, minus the certification body.
A gap analysis tells you the distance to either destination before you commit to the journey.
Do we need ISO 42001 certification, or just alignment?
Certification means an accredited certification body audits your AI management system and issues a certificate; alignment means you build and run the same system without the external audit. Choose certification when a contract, tender or regulator will ask for the certificate itself. Choose alignment when you want the discipline and the evidence but nobody is demanding the badge.
We deliver the readiness work for both. Certification itself is always issued by an independent certification body, never by us.
Do we need an AI policy if we only use ChatGPT and Copilot?
Yes, and arguably that is exactly when you need one most. Staff using public AI tools without rules is how client data ends up in training sets, how confidential documents leave the business and how nobody can answer what the board asks after an incident. A short, enforceable policy that says what may be used, for what, with what data, closes most of that exposure in a few pages.
Our policy template covers the ChatGPT-and-Copilot case as the baseline, not the afterthought.
Start here
Find out where your AI use actually stands
Take a free 45 minute scoping call about how AI is used across your business, and leave knowing what a governance assessment or a security test involves, what it costs and what comes back. No pressure at any point.