AI Governance & Readiness Audit

Map the surface before you defend it

With the world moving forward with new innovations there are lots of new technologies lined up to support the future.

Four weeks. We map your entire AI surface — every model in production, every agent with tool access, every dollar of spend, and the shadow usage nobody has inventoried — then hand you a prioritised remediation plan and a board-ready risk brief.

The deliverable is yours whether or not we continue. That is deliberate: an audit you cannot act on independently is not an audit.

01  /  Why Now

August 2026: high-risk AI obligations become enforceable.

The EU AI Act phases in by category. Prohibited practices bit in February 2025; general-purpose model obligations in August 2025. August 2026 is when the high-risk system rules activate — and that is the tier most enterprise AI deployments actually fall into once someone reads the definitions carefully.

Penalties reach €35 million or 7% of global annual turnover. Meanwhile ISO/IEC 42001 is becoming a procurement gate: it carries no regulatory fine, but losing certification means losing contracts.

WHAT MOST TEAMS DISCOVER LATE
  • Systems classified as low-risk internally meet the high-risk definition once the use case is written down honestly.
  • Shadow AI — models and agents adopted by individual teams — sits outside every inventory and every control.
  • The evidence trail required to demonstrate compliance was never designed in, so it has to be reconstructed retroactively from logs.
  • Model spend is untraceable to decisions, which makes proportionality arguments impossible to make.
THE FRAMEWORKS, HONESTLY
  • NIST AI RMF — voluntary, no direct enforcement, but it is the methodology federal buyers and procurement teams reference.
  • ISO/IEC 42001 — certifiable, externally audited, market-enforced. It gives you evidence a customer will accept.
  • EU AI Act — the one with fines attached.
  • They are complementary, not alternatives. NIST supplies method; ISO supplies structure; the Act supplies the deadline.
02  /  The Engagement

Four weeks. You keep the deliverable either way.

This is a paid diagnostic, not a sales exercise. If we are not the right firm to do the remediation, the plan is still yours and still executable by someone else. An audit you cannot act on independently is not an audit.

WeekWorkOutput
01Surface mapping. Every model in production, every agent with tool access, every integration, every team running something unofficially.AI system inventory with risk classification
02Cost and token forensics. Spend attributed to features and decisions rather than invoice lines. Model-intent versus actual-model reconciliation.Spend map + waste findings
03Control gap analysis against NIST AI RMF and EU AI Act high-risk obligations. Blast-radius review of agent tool permissions.Gap register, ranked by exposure
04Evidence-trail assessment: can you reconstruct why the system did what it did, six months later, for a regulator or a customer?Remediation plan + board-ready risk brief
ADLC MATURITY SCORECARDAlongside the gap register you get a scored assessment of where your lifecycle sits today across intent capture, verification, release control, cost governance and observability — so the remediation plan has a baseline to move from.
03  /  What Gets Found

The findings are usually not the ones expected.

Teams brace for a model-risk conversation. What surfaces is almost always operational: permissions granted early and never revoked, spend with no owner, and a record that cannot be reconstructed.

RUNAWAY COST

Agents run continuously, consuming tokens around the clock. Gartner names this the first of three reasons it expects 40% of agent projects to be cancelled by 2027.

GOVERNANCE GAPS

Autonomous agents misinterpret goals, violate policy, or create compliance exposure when guardrails are advisory rather than structural.

NO OBSERVABILITY

No real-time monitoring, no audit trail, no kill switch. Problems are detected after the spend or the incident, never before.

Token and cost forensics

Every model call attributed by team, service and prompt. Shadow usage surfaced, unowned spend named.

Control gap analysis

Existing controls mapped against NIST AI RMF and EU AI Act obligations. Gaps ranked by exposure, not by ease of fix.

ADLC maturity scorecard

Where your pipeline stands on agent-authored change: gates, provenance, rollback, evidence. Scored, with the next three moves.

Why Choose Us

Evidence you can act on without us

We go above and beyond to delight our customers. Our expertise mixed with your passion can do wonders and we are just getting started.