Published, in full
What our AI governance and testing services cost
Every figure published before you speak to anyone: a readiness assessment priced by scope, ISO 42001 compliance delivered and then run for you as a monthly service, engineering projects with fixed quotes, per-system AI security testing, and a monthly officer retainer. No quote theatre.
Line one
Governance and readiness, per organisation
Three ways in: assess where you stand, have ISO 42001 compliance delivered and run for you end to end, or bring us in to engineer secure AI directly. Every figure is on the card.
AI Readiness Assessment
Secure AI readiness and ISO 42001 compliance, assessed
£8,500 to £16,700
one-off, fixed by scope, ex VAT
- AI system inventory and use-case register
- Security and risk assessment of each AI use case
- Readiness scored against ISO 42001, NIST AI RMF and the EU AI Act
- AI policy pack, written for your business
- Prioritised roadmap and board debrief
The managed route
AI Compliance as a Service
ISO 42001, certified and then run for you, end to end
From £1,850
per month, ex VAT
- AI management system built and documented
- Carried through ISO 42001 certification
- Then run ongoing: register current, controls operated, evidence kept
- Regulation tracked and translated as it moves
- Surveillance audits fronted, year after year
Secure AI Engineering
Hands-on engineering for AI systems that must be secure
From £12,000
per project, ex VAT
- Guardrails, isolation and permission design for AI systems
- Secure architecture for RAG, tools and agent deployments
- Hardening delivered with your engineers, in your stack
- Scoped as a defined project with a fixed quote before work starts
Line two
AI security testing, per system
One fixed fee per AI system tested, banded by complexity. Every band includes a report your engineers can act on and a free retest once the fixes land.
Single System
One chatbot or LLM application
£5,600
per system, fixed, ex VAT
- OWASP LLM Top 10 coverage
- Prompt injection, jailbreak and leakage testing
- Report with reproduction steps and fixes
- Free retest of remediated findings
Most tested
Integrated System
An application with RAG, tools or integrations
£7,900
per system, fixed, ex VAT
- Everything in Single System
- Retrieval pipeline and data-source testing
- Tool-calling and integration abuse cases
- Architecture review with your engineers
Agentic Estate
Agents and multi-model estates
From £13,500
per estate, ex VAT
- Everything in Integrated System
- Per-agent permission and constraint testing
- Autonomy, escalation and misuse scenarios
- Scoped per estate, priced before work starts
Line three, ongoing
AI Responsible Officer as a service
A named consultant who runs your AI governance month to month: register kept current, new use cases reviewed before launch, regulation tracked, board reported. The role your business needs before it can justify the hire, delivered as a retainer and priced like everything else here: in the open.
Assumptions, stated plainly
Every figure excludes VAT and covers scoping, the engagement itself, the report and the debrief. Testing happens in controlled conditions agreed with your engineers, never against systems we lack authority to touch. Where a group structure or an unusually complex estate genuinely exceeds the bands, we quote it and tell you that is what happened. Classic infrastructure and web-app penetration testing is delivered by CyPro directly.
For comparison
What the market charges for this
No direct competitor in this market publishes a package price, and most publish no figures at all. The public numbers that do exist are consultant day rates on the government's Digital Marketplace, where AI governance and assurance suppliers list between roughly £300 and £1,450 per consultant day, reached only after you register, search and ask.
Published certification-market guides put a typical ISO 42001 project between £8,000 and £50,000 depending on organisation size, and UK LLM penetration tests commonly run £3,000 to £12,000 per system. We think the figure a buyer would eventually be quoted should have been on the page all along.
Before you ask
Pricing questions, answered
Why publish prices at all?
Because quote-only pricing suits the seller, not the buyer. Governance readiness and per-system testing are bounded, well-understood engagements: we know the effort each band takes, so the cost belongs in front of you before anyone books a call. Every CyPro specialist service publishes its prices the same way.
What sets the readiness assessment fee within its range?
The number and complexity of AI use cases in scope. Each use case brings its own owner, data, risks and controls to assess, so a business with two straightforward use cases lands at the bottom of the £8,500 to £16,700 range and an estate of agents and integrations lands at the top. The figure is fixed at scoping, before work starts.
What does AI Compliance as a Service actually include?
The whole ISO 42001 journey, end to end, and then its upkeep: we build the AI management system, carry you through certification, and keep running it afterwards, register current, controls operated, evidence maintained, regulation tracked and surveillance audits fronted. One monthly fee from £1,850, instead of a certification project that decays the day the certificate arrives.
Why is testing priced per system?
Because complexity lives at the system level. A standalone chatbot, an application with retrieval and integrations, and a fleet of agents with real permissions are different engagements, and pretending otherwise produces either padded quotes or corners cut. Each system gets a band, each band has a published price.
What does the AI Responsible Officer retainer include?
A named consultant running your AI governance month to month: the register kept current, new use cases reviewed before they launch, regulation tracked and translated, and a standing report to the board. It is the DPO-as-a-service model applied to AI, priced as a monthly retainer with no long lock-in.
What kind of work is Secure AI Engineering?
Defined engineering projects, from £12,000, for AI systems that must hold up in production: guardrail and permission design, secure architecture for retrieval and agent deployments, and hardening delivered alongside your engineers in your own stack. Each project is scoped and quoted as a fixed piece of work before it starts.
The price is already on the page
Settle your band in one call
One free 45 minute scoping call settles which use cases and systems are in scope, and the work is booked at the fee already published. Nobody negotiates because nothing needs negotiating.