Control effectiveness testing
Sample-based testing of governance, oversight and technical controls as operated, not as documented.
Governance & Trust
An independent opinion your risk committee can rely on.
The problem we solve
Boards increasingly need assurance that is not written by the team that built the system. We review models, vendors and controls against a published methodology and report findings plainly, including the ones nobody wanted.
Sample-based testing of governance, oversight and technical controls as operated, not as documented.
Performance, bias, robustness and documentation quality assessed against intended use.
Third-party AI supplier review covering security, data use, model change management and exit.
Gap assessment against EU AI Act, ISO 42001, sector rules and internal policy.
How the engagement runs
Systems in scope, methodology and reporting lines agreed in writing.
Evidence collection, control testing, interviews and model review.
Draft findings, management response and committee readout.
Common questions
Related practices
Model registry, risk classification, documentation and audit trails mapped to the EU AI Act, ISO 42001 and internal policy.
ViewPrompt-injection defence, data exfiltration testing, agent abuse scenarios and adversarial evaluation before attackers get there.
ViewPII handling, retention, minimisation and EU/North American residency designed in rather than retrofitted.
ViewA 45-minute briefing with the people who would run the work — scope, timeline and a straight answer on whether it is the right next step.