An independent reading of your AI and LLM integrations against genuine governance requirements, in writing, by someone with no AI platform to sell you.
Your teams are using Azure OpenAI, AWS Bedrock, Anthropic, or some combination — for RAG-based internal tools, customer-facing features, or increasingly autonomous agentic workflows. What you likely don’t have is a genuine governance layer behind it: audit logging that actually captures what a system did and why, traceability for agentic actions, and a responsible-use policy that reflects what’s actually being built, not a generic template.
That is what this engagement is.
€15,000. Three to four weeks. Delivered in writing, with a presentation to whoever needs to hear it.
Fixed fee. No implementation work. No commissions. No product recommendations influenced by suppliers.
Why clients commission this review
- Several teams have adopted AI tooling independently, and no one has a consolidated view of what’s actually in production.
- An agentic workflow has been given meaningful autonomy — taking actions, not just generating text — and the board wants confirmation the traceability actually holds up.
- A responsible-use policy exists but was drafted before the current AI footprint existed, and no longer reflects reality.
- A customer or investor has asked for evidence of AI governance maturity as part of their own due diligence.
- The business wants a genuine governance baseline before expanding AI use further, rather than retrofitting governance after the fact.
Who this is for
Boards and technology leaders at organisations with genuine AI and LLM integration in production or active development, wanting independent confirmation the governance layer is real.
Compliance and risk functions needing a defensible responsible-use policy grounded in what’s actually deployed, not a template.
Who this is not for
Organisations specifically needing EU AI Act risk classification and Article 9 readiness ahead of enforcement — that’s the more tightly scoped EU AI Act Readiness & AI Governance review.
Organisations wanting AI systems built, integrated, or fine-tuned. We identify and recommend; we do not implement.
What you receive
The Review tells you three things in writing: what AI and LLM integration actually exists across the business, where the governance gaps sit, and what to fix first. Five artefacts, delivered together, in plain language.
An AI and LLM integration inventory. Every system in production or active development, internally built and vendor-supplied, mapped by function and level of autonomy.
An audit logging and traceability assessment. Whether the logging actually captures what a system did, why, and on what input — genuinely reconstructable after the fact, not just present in principle.
A responsible-use policy gap analysis. Where existing policy, if any, diverges from what’s actually deployed, and what a genuinely current policy needs to cover.
A prioritised roadmap. What to close first, second, third, sequenced by risk and by how consequential each system’s autonomy actually is.
A board presentation. A one-hour session with your board or risk committee, findings presented, challenged, and discussed in the room.
How the Review runs
Three to four weeks, in four phases: scoping and inventory across every team using AI tooling, interviews and evidence gathering, synthesis and writing, then presentation and revisions around your board cycle.
Everything is written before it is said. Nothing is presented to your board that you have not read first.
What this is not
A formal EU AI Act conformity assessment. For that specific regulatory scope, see EU AI Act Readiness & AI Governance.
A remediation engagement. We identify and recommend; we do not implement or build governance tooling. Ongoing governance advisory can be discussed separately as a retainer if that’s what the Review surfaces a need for.
Proof
References available on request. Anonymised excerpts from prior reviews available on request.
What happens next
Start a ConversationThirty minutes. We confirm fit, scope, and timing. You decide whether to proceed. No proposal is sent unless you ask for one.