AI Security & Governance · CISSP-led
Productised engagement · Fixed scope · 2 weeks

Know exactly where you stand on AI governance — in two weeks.

A fixed-scope review that maps your AI use against the EU AI Act and ISO/IEC 42001, finds the gaps, and hands you a prioritised 90-day roadmap your board, your auditors and your customers will accept.

Book a 30-minute scoping call Fixed scope · Fixed fee · 2 weeks
Why now

The obligations are already live. The evidence takes longest.

Prohibited-AI rules and AI-literacy duties have applied since February 2025; obligations for general-purpose AI since August 2025. The big one — high-risk system obligations — now lands on 2 December 2027, but the documentation, testing and conformity trail it demands takes 12–18 months to build properly. And your customers and procurement teams are already asking for AI assurance today. The organisations that start now set the timeline. The rest will be scrambling against it.

Feb 2025 — Prohibited practices & AI literacy live Aug 2025 — General-purpose AI obligations live Dec 2027 — High-risk system obligations apply
01

It starts with classification

The Act treats AI by risk tier. Your obligations depend entirely on which one each system falls into.

Prohibited
Banned outright. Penalties up to €35m or 7% of global turnover.
High-risk
Strict controls: documentation, testing, human oversight, logging.
Limited
Transparency duties — people must know they're dealing with AI.
Minimal
Few obligations, but governance still expected by buyers.

Most teams guess which tier they're in. The review tells you — for every system and agent you run — and that single answer drives everything that follows.

02

What you get

Five concrete deliverables. No 200-page binder no one reads.

01

AI inventory & risk classification

Every AI system and agent you use or build, mapped to its AI Act tier.

02

Gap assessment

Where you stand against EU AI Act obligations and ISO/IEC 42001 controls — what's covered, what's missing.

03

Prioritised 90-day roadmap

Sequenced by risk and effort, so you know what to fix first and what can wait.

04

Board-ready summary & evidence pack

A defensible position you can put in front of regulators, customers and your own leadership.

05

Live readout

A working session to walk the findings and decide next steps — not a PDF thrown over the wall.

03

The two weeks

Light-touch on your team's time. Most of the lifting is mine.

Week 01

Discovery & classification

  • Short interviews with your key people
  • Review of systems, agents and data flows
  • AI inventory built and risk-tiered
Week 02

Gaps & roadmap

  • Gap analysis against the Act and ISO 42001
  • Prioritised remediation roadmap drafted
  • Board summary delivered and walked through live
04

Who's doing the work

One of a small number of practitioners certified to lead both security and AI governance.

CISSP CISM ISO/IEC 27001 Lead Implementer ISO/IEC 42001 Lead Implementer MSc Computer Forensics
Stood up ISO 27001 from zero in under six months at a regulated fintech.
Delivered security and assurance work for central banks, defence ministries and critical national infrastructure.
Held Head of Cyber roles in FTSE 100 and fintech organisations.
Certified to lead both ISO 27001 and ISO 42001 — the rare overlap of established security practice and new AI governance.
Next step

An open question is a liability. A roadmap isn't.

Two weeks from now you could have a defensible answer on AI governance instead of an uneasy guess. Start with a 30-minute scoping call — no charge, no obligation.

Book a scoping call →
Cydentity · cydentity.co.uk
The review stands alone — and leads naturally into ongoing vCISO support or full ISO implementation if you want it.