The process

How it works

Every engagement follows the same shape: a free scoping call, a proposal at the published price, focused fieldwork, then deliverables a board can act on. Governance assessments and AI security tests differ only in what the fieldwork involves.

Six steps

From first call to finished roadmap

Steps three and four are the two lanes: a governance engagement takes one, a testing engagement takes the other, and a combined engagement takes both.

Free scoping call mapping your AI estate to a published band

Step 1

The scoping call

Free, 45 minutes. We ask three things: how your business uses AI, which systems should be in scope, and what is driving the work, whether that is the EU AI Act, ISO 42001, a client questionnaire or a board that wants answers.

Proposal and setup for an AI governance engagement

Step 2

Proposal and setup

You receive a written proposal carrying the published price for your band, never a mystery quote. Accept it and we agree the practicalities together: who we speak to, what evidence you share and what access the fieldwork needs.

Consultant interviews with AI use case owners

Step 3

Governance fieldwork

For governance engagements: we review your policies and evidence, interview the people who own AI decisions day to day, and map what we find against the framework you are working towards.

Governance and testing fieldwork on AI systems

Step 4

Testing fieldwork

For AI security testing engagements: controlled adversarial testing of the systems in scope, run within agreed windows and rules of engagement, so weaknesses surface in our hands rather than someone else's.

Board-ready AI governance roadmap and deliverables

Step 5

Board-ready deliverables

Depending on the lane: a prioritised roadmap, a scored AI risk register, a policy pack or a full test report, all written to be read by directors as comfortably as by engineers, and walked through with you line by line.

Ongoing AI governance through the retainer service

Step 6

Ongoing support, if you want it

Most engagements stand alone. If you want AI governance run continuously rather than revisited annually, the AI Responsible Officer retainer keeps our team accountable for it, priced openly like everything else.

One shape, two lanes

Governance and testing follow the same path

Governance engagements answer the organisational question: are your policies, oversight and risk management fit for how you actually use AI? The fieldwork is evidence review, interviews and framework mapping, and the deliverables lean towards roadmaps, risk registers and policy packs.

Testing engagements answer the technical question: can the AI systems you rely on be manipulated, leaked from or abused? The fieldwork is hands-on adversarial testing under agreed constraints, and the deliverable is a test report with findings you can reproduce. Same scoping call, same published pricing, same standard of reporting, different work in the middle.

The exchange

What we need from you, and what you get back

What we need from you

  • A sponsor who can make decisions about scope and receive the findings.
  • An hour or two from the people closest to your AI use: whoever builds with it, buys it or manages the teams using it.
  • An inventory of AI systems if one exists. If it does not, the engagement builds it, and that alone is worth having.
  • Access appropriate to the lane: documents and interviews for governance work, agreed technical access to in-scope systems for testing.

What you get back

  • A prioritised roadmap: what to fix, in what order, and why each item earns its place.
  • A scored risk register covering the AI systems in scope, ready to live in your existing risk process.
  • A policy pack or test report depending on the lane, written for the audience that has to act on it.
  • A debrief where every finding is explained and challenged before anyone commits budget to it.

Quick answers

Process questions, answered

Can governance and testing run as one engagement?

Yes, and they often should. One scoping call covers both, the proposal prices each lane separately against the published bands, and the deliverables land together, so the board sees the paperwork risk and the technical risk in a single picture.

Who from our side needs to be involved?

A sponsor to own the engagement, plus short conversations with the people nearest your AI use. We deliberately keep the demand on your team light: the fieldwork is ours to do, not yours to host.

Do you need access to our systems?

It depends on the lane. Governance engagements run on documents, interviews and evidence you already hold. Testing engagements need technical access to the systems in scope, agreed in writing beforehand, with rules of engagement that say exactly what we will and will not do.

What happens once the deliverables are with us?

The roadmap is yours to run at your own pace, with or without us. If you would rather AI governance were owned continuously, the AI Responsible Officer retainer covers that, and its price sits with the rest on the pricing page.

See the published prices

Rocket launching above the AI Governance UK call to action

It starts with a conversation

Book the scoping call

Bring how you use AI and what is prompting the question. We will bring the band your engagement fits, its published price and a view on which lane to run first.