A fixed-scope review that maps your AI use against the EU AI Act and ISO/IEC 42001, finds the gaps, and hands you a prioritised 90-day roadmap your board, your auditors and your customers will accept.
Prohibited-AI rules and AI-literacy duties have applied since February 2025; obligations for general-purpose AI since August 2025. The big one — high-risk system obligations — now lands on 2 December 2027, but the documentation, testing and conformity trail it demands takes 12–18 months to build properly. And your customers and procurement teams are already asking for AI assurance today. The organisations that start now set the timeline. The rest will be scrambling against it.
The Act treats AI by risk tier. Your obligations depend entirely on which one each system falls into.
Most teams guess which tier they're in. The review tells you — for every system and agent you run — and that single answer drives everything that follows.
Five concrete deliverables. No 200-page binder no one reads.
Every AI system and agent you use or build, mapped to its AI Act tier.
Where you stand against EU AI Act obligations and ISO/IEC 42001 controls — what's covered, what's missing.
Sequenced by risk and effort, so you know what to fix first and what can wait.
A defensible position you can put in front of regulators, customers and your own leadership.
A working session to walk the findings and decide next steps — not a PDF thrown over the wall.
Light-touch on your team's time. Most of the lifting is mine.
One of a small number of practitioners certified to lead both security and AI governance.
Two weeks from now you could have a defensible answer on AI governance instead of an uneasy guess. Start with a 30-minute scoping call — no charge, no obligation.
Book a scoping call →