The process
How it works
Every engagement follows the same shape: a free scoping call, a proposal at the published price, focused fieldwork, then deliverables a board can act on. Governance assessments and AI security tests differ only in what the fieldwork involves.
Six steps
From first call to finished roadmap
Steps three and four are the two lanes: a governance engagement takes one, a testing engagement takes the other, and a combined engagement takes both.
Step 1
The scoping call
Free, 45 minutes. We ask three things: how your business uses AI, which systems should be in scope, and what is driving the work, whether that is the EU AI Act, ISO 42001, a client questionnaire or a board that wants answers.
Step 2
Proposal and setup
You receive a written proposal carrying the published price for your band, never a mystery quote. Accept it and we agree the practicalities together: who we speak to, what evidence you share and what access the fieldwork needs.
Step 3
Governance fieldwork
For governance engagements: we review your policies and evidence, interview the people who own AI decisions day to day, and map what we find against the framework you are working towards.
Step 4
Testing fieldwork
For AI security testing engagements: controlled adversarial testing of the systems in scope, run within agreed windows and rules of engagement, so weaknesses surface in our hands rather than someone else's.
Step 5
Board-ready deliverables
Depending on the lane: a prioritised roadmap, a scored AI risk register, a policy pack or a full test report, all written to be read by directors as comfortably as by engineers, and walked through with you line by line.
Step 6
Ongoing support, if you want it
Most engagements stand alone. If you want AI governance run continuously rather than revisited annually, the AI Responsible Officer retainer keeps our team accountable for it, priced openly like everything else.
One shape, two lanes
Governance and testing follow the same path
Governance engagements answer the organisational question: are your policies, oversight and risk management fit for how you actually use AI? The fieldwork is evidence review, interviews and framework mapping, and the deliverables lean towards roadmaps, risk registers and policy packs.
Testing engagements answer the technical question: can the AI systems you rely on be manipulated, leaked from or abused? The fieldwork is hands-on adversarial testing under agreed constraints, and the deliverable is a test report with findings you can reproduce. Same scoping call, same published pricing, same standard of reporting, different work in the middle.
The exchange
What we need from you, and what you get back
What we need from you
- A sponsor who can make decisions about scope and receive the findings.
- An hour or two from the people closest to your AI use: whoever builds with it, buys it or manages the teams using it.
- An inventory of AI systems if one exists. If it does not, the engagement builds it, and that alone is worth having.
- Access appropriate to the lane: documents and interviews for governance work, agreed technical access to in-scope systems for testing.
What you get back
- A prioritised roadmap: what to fix, in what order, and why each item earns its place.
- A scored risk register covering the AI systems in scope, ready to live in your existing risk process.
- A policy pack or test report depending on the lane, written for the audience that has to act on it.
- A debrief where every finding is explained and challenged before anyone commits budget to it.
Quick answers
Process questions, answered
Can governance and testing run as one engagement?
Yes, and they often should. One scoping call covers both, the proposal prices each lane separately against the published bands, and the deliverables land together, so the board sees the paperwork risk and the technical risk in a single picture.
Who from our side needs to be involved?
A sponsor to own the engagement, plus short conversations with the people nearest your AI use. We deliberately keep the demand on your team light: the fieldwork is ours to do, not yours to host.
Do you need access to our systems?
It depends on the lane. Governance engagements run on documents, interviews and evidence you already hold. Testing engagements need technical access to the systems in scope, agreed in writing beforehand, with rules of engagement that say exactly what we will and will not do.
What happens once the deliverables are with us?
The roadmap is yours to run at your own pace, with or without us. If you would rather AI governance were owned continuously, the AI Responsible Officer retainer covers that, and its price sits with the rest on the pricing page.
It starts with a conversation
Book the scoping call
Bring how you use AI and what is prompting the question. We will bring the band your engagement fits, its published price and a view on which lane to run first.