Service · AI Risk
An AI risk assessment your board can act on.
We turn a sprawling, half-known AI estate into a defensible register of systems, owners, exposures and controls.
The problem
Shadow AI, embedded model features and quietly renewed vendor contracts mean most organisations cannot answer a basic question: which AI systems are we running, and who is accountable for each?
Without that inventory, an AI readiness assessment is guesswork and third-party risk stays invisible until it fails.
Why it matters
A single unassessed model, in credit, hiring, safety or customer service, can create regulatory, legal and reputational exposure at once. Boards across the GCC are increasingly expected to show the assessment happened before the deployment did.
How the engagement runs
Discover
Inventory AI systems across business units, including embedded and third-party AI vendor features.
Classify
Tier each system by impact, autonomy and data sensitivity.
Assess
Evaluate model, data, vendor and third-party risk against the NIST AI RMF and ISO/IEC 42001.
Prioritise
Rank exposures by likelihood and consequence into a treatment plan.
Report
Deliver a board-ready register with owners, gaps and recommended controls.
What you receive
- AI system register: every system inventoried with owner, purpose and risk tier.
- Risk assessment report: model, data, vendor and third-party risks with severity ratings.
- AI readiness view: where you stand against the controls a regulator would expect.
- Treatment plan: prioritised, costed actions with owners and target dates.
Frequently asked questions
How is this different from a cyber risk assessment?
It focuses on AI-specific failure modes, model drift, bias, hallucination, autonomy and vendor opacity, that traditional security assessments are not built to catch.
Can you assess third-party and vendor AI?
Yes. AI third-party and vendor risk is a core part of the engagement, including embedded model features inside SaaS you already run.
What do you need from us to start?
An initial list of known AI use cases and the right people to interview. We uncover the rest, including shadow AI, during discovery.
How often should this be repeated?
At least annually, and whenever you deploy a high-impact system or change a major AI vendor. We can help you make it a standing process.
Executive briefing
Find the AI risk you cannot yet see.
A 45-minute briefing on scoping your first assessment.
Related services
Independent assurance over models, data pipelines and third-party AI, with a tested evidence trail.
View service Service · AI Risk NIST AI RMF, implemented as a working assurance framework.The NIST AI Risk Management Framework operationalised into controls, mapped to ISO 42001.
View serviceRelated insights
Decompose an AI agent into goals, tools, memory and autonomy, and control the risk each part introduces.
Agentic AI Risk Agentic AI governance: a clever prompt is not a control.Why a prompt is not a control, and what it takes to govern autonomous AI agents that act on their own.