Model inventory & registry
Every model, prompt and agent registered with owner, purpose, risk class and lifecycle state.
Governance & Trust
Turn the supervisory review from a fire drill into an export.
The problem we solve
Regulators, auditors and boards are now asking the same question: which models are running, who owns them, and what evidence do you hold? We build the register, the controls and the evidence trail that answers it in a single export.
Every model, prompt and agent registered with owner, purpose, risk class and lifecycle state.
EU AI Act tiering, impact assessments and control requirements proportional to risk.
Acceptable use, human oversight, disclosure and procurement standards written to be followed, not filed.
Automated evidence collection, control testing and reviewer sign-off workflows.
Bias testing, explainability, contestability and incident response procedures.
How the engagement runs
Shadow AI sweep, model inventory and current control assessment.
Risk framework, policies and control mapping to EU AI Act and ISO 42001.
Tooling, workflows and training so governance runs without a consultant in the room.
Common questions
Related practices
Prompt-injection defence, data exfiltration testing, agent abuse scenarios and adversarial evaluation before attackers get there.
ViewPII handling, retention, minimisation and EU/North American residency designed in rather than retrofitted.
ViewThird-party review of models, vendors and controls — an objective read for boards and risk committees.
ViewA 45-minute briefing with the people who would run the work — scope, timeline and a straight answer on whether it is the right next step.