Straight answers
Frequently asked questions
What UK businesses ask before commissioning AI governance work or an AI security test, answered by the consultants who deliver both. Anything not answered here, the scoping call handles.
Does the EU AI Act apply to UK companies?
It can, despite the UK sitting outside it. The Act applies extraterritorially: if you place an AI system on the EU market, serve EU customers with one, or the output of your system is used inside the EU, obligations can attach to your UK business. A UK-only firm with UK-only customers is generally out of scope, but the boundary turns on facts worth checking properly rather than assuming.
Our applicability assessment gives you a documented answer for every AI system you run, with the evidence to show customers and regulators.
Is ISO 42001 worth it for a business our size?
It depends on who is asking you for it. Certification earns its keep when enterprise customers, regulators or procurement frameworks demand evidence of responsible AI management; it is rarely the right first step for a small firm with no such pressure. Many businesses get most of the value from aligning with the standard without certifying: the management system, risk process and policies, minus the certification body.
A gap analysis tells you the distance to either destination before you commit to the journey.
Do we need ISO 42001 certification, or just alignment?
Certification means an accredited certification body audits your AI management system and issues a certificate; alignment means you build and run the same system without the external audit. Choose certification when a contract, tender or regulator will ask for the certificate itself. Choose alignment when you want the discipline and the evidence but nobody is demanding the badge.
We deliver the readiness work for both. Certification itself is always issued by an independent certification body, never by us.
Do we need an AI policy if we only use ChatGPT and Copilot?
Yes, and arguably that is exactly when you need one most. Staff using public AI tools without rules is how client data ends up in training sets, how confidential documents leave the business and how nobody can answer what the board asks after an incident. A short, enforceable policy that says what may be used, for what, with what data, closes most of that exposure in a few pages.
Our policy template covers the ChatGPT-and-Copilot case as the baseline, not the afterthought.
What does AI governance consulting cost?
Our prices are published in full on the pricing page: governance and readiness work is a fixed fee per organisation, banded by how many AI use cases are in scope; AI security testing is a fixed fee per system, banded by complexity; and the AI Responsible Officer service is a monthly retainer. You will know the number before you speak to us, which is not how this market usually behaves.
What is AI red teaming, and how does it differ from a penetration test?
An AI penetration test probes a specific system for exploitable weaknesses: prompt injection, jailbreaks, data leakage, insecure integrations. AI red teaming is broader and scenario-driven: structured adversarial exercises that explore how the system can be misused, what harms it can produce and how it behaves under pressure, mapped to frameworks like MITRE ATLAS and NIST AI RMF.
Buy the pentest to prove a system before launch; buy red teaming when the question is what could go wrong in the world, not just in the code.
How do you test an LLM application?
In a controlled harness against the failure modes that matter: prompt injection direct and indirect, jailbreak resistance, sensitive data leakage, insecure output handling, retrieval poisoning where there is a RAG pipeline, and excessive agency where the model can call tools. Findings come back with reproduction steps and fixes, and we retest the fixes at no charge.
How do you secure AI agents?
Treat them like powerful new joiners with system access, because that is what they are. Inventory every agent and what it can touch, cut permissions to the minimum the task needs, put human approval in front of irreversible actions, test how the agent behaves when its inputs are hostile, and log everything it does so you can answer questions afterwards.
Our agent security assessment does exactly that, per deployed agent.
How often should AI systems be risk-assessed?
On change, not just on calendar. Reassess when the model, the data, the provider or the use changes, when a new system enters the estate and when regulation moves; underneath that, an annual formal review keeps the register honest. AI systems drift faster than the applications your existing risk process was built for, which is why the cadence needs to be event-driven.
What is an AI management system (AIMS)?
The AI equivalent of the management system behind ISO 27001: the documented roles, policies, risk processes and controls through which an organisation governs its AI, as a running system rather than a binder. ISO 42001 is the standard that defines what a certifiable AIMS must contain. If your business already runs an ISMS, the shape will feel familiar and much of the machinery can be shared.
Who should own AI governance: IT, legal or the board?
Accountability belongs to the board; the operating work needs a named owner with reach into IT, legal, data protection and the business units actually using AI. In practice that is a senior leader with a cross-functional group behind them, or an appointed AI Responsible Officer where nobody internal has the time or the expertise. The failure mode to avoid is everyone assuming somebody else owns it.
Do you work alongside our DPO and legal advisers?
Yes, by design. AI governance overlaps data protection and contract law without being either, so we stay in our lane: we bring the AI-specific risk method, technical testing and framework knowledge, your DPO keeps data protection accountability and your lawyers keep legal advice. Deliverables are written to slot into the structures they already run, not to compete with them.
How long does an AI governance readiness assessment take?
It scales with the number of AI use cases in scope and how quickly we can reach the people who own them, which is why scoping comes first and is free. Most engagements move in a handful of working sessions rather than months: evidence gathering, interviews, then the roadmap. You will have the shape and the schedule in writing before anything starts.
What happens after the assessment? Can you run it ongoing?
The roadmap is yours either way: many clients implement it themselves and come back annually. Where you want continuity, the AI Responsible Officer service runs your AI governance month to month: keeping the register current, reviewing new use cases, tracking regulation and reporting to the board, as a retainer rather than a hire. It pairs naturally with a CyPro virtual CISO where one is already in place.
Still wondering about something?
Ask a consultant directly
The free 45 minute call exists for exactly this: what your AI estate actually needs, what it would cost and what you would receive, answered by a practitioner whether or not you book anything.