Skip to content
AI assurance

Governance is the line item that unblocks the rest of your AI budget.

Your buyer now gates the purchase on kill switches and audit trails. The EU AI Office has held enforcement powers since 2 August 2026. Both of them want the same thing, which is evidence. We produce it in one to three weeks, at a published price, and we are precise about what we can and cannot attest to.

Eight engagements, $2,500 to $8,900, every price on this page. No scoping fee in front of any of them.

$492M
AI governance platform market in 2026, Gartner
$1B+
the same market by 2030, Gartner
25%
of planned 2026 enterprise AI spend deferred into 2027
60%
of the Fortune 100 to appoint a head of AI governance in 2026, Forrester

Analyst figures, published by Gartner and Forrester. They are market context, not our results. Numbers describing our own work appear elsewhere on this site with a source attached to each one.

Why now

Three separate people started asking for the same evidence in 2026.

The regulator, the enterprise buyer and your own CFO converged on one question this year: show me what this system does, on what basis, and who can stop it. None of them will accept a demo as the answer.

  1. 01

    The regulator has powers now, not a timetable

    EU AI Act Article 50 transparency obligations have been in force since 2 August 2026. From that same date the AI Office and member-state authorities can request technical documentation, evaluate general-purpose AI models, require corrective measures and issue fines. Systems already on the market before 2 August 2026 have until 2 December 2026 for Article 50(2).

  2. 02

    The buyer has a checklist now

    Enterprise procurement asks for six things by name: kill switches, evidentiary audit trails, human-in-the-loop boundaries, model change control, outcome-based SLAs, and an ISO/IEC 42001 or SOC 2 attestation. They arrive as gating conditions, not preferences. Missing one does not lose the deal loudly; it stalls it in diligence.

  3. 03

    The CFO wants evidence before the spend

    A quarter of planned enterprise AI spend for 2026 is being deferred into 2027, because CFOs want ROI evidence and security teams flag governance gaps. Forrester expects 60% of the Fortune 100 to appoint a head of AI governance during 2026, so the person whose job is to ask now exists and has a title.

What buyers gate on

Six conditions, and the engagement that answers each.

These are the six things enterprise buyers now name in AI procurement. They are not a maturity model to grow into; each one is a yes or no question asked before signature. Below each condition is the question as it is actually asked, and the work that produces an answer.

  • 01

    Kill switches

    Show me how a human stops this system mid-task, and who is allowed to.

    Agent governance review (T2-08). We map every action the agent can take, the blast radius of one compromised step, and where the stop control is missing rather than merely undocumented.

  • 02

    Evidentiary audit trails

    Reconstruct for me what the system did on 14 March, and on what basis.

    Agent governance review (T2-08) and EU AI Act readiness assessment (T2-01). We check whether the trail records the input, the retrieved context, the decision and the human override, or only the final output.

  • 03

    Human-in-the-loop boundaries

    Which decisions can this system take alone, and who signed off on that line?

    Agent governance review (T2-08). The boundary comes back written down as an authority matrix, rather than living in the head of the engineer who built it.

  • 04

    Model change control

    Your provider updated the model last night. What is your process?

    Agent governance review (T2-08) and ISO/IEC 42001 gap assessment (T2-05). Version pinning, a change log with an owner, and a regression gate that runs before a swap reaches production.

  • 05

    Outcome-based SLAs

    Put a number on accuracy and put that number in the contract.

    Hallucination and grounding audit (T2-03). You cannot sign an SLA against a metric nobody has measured. We build the evaluation set from your own corpus, measure groundedness against it, and hand back the baseline the SLA has to be written around.

  • 06

    ISO/IEC 42001 or SOC 2 attestation

    Send me the certificate, or tell me your date.

    ISO/IEC 42001 gap assessment (T2-05), NIST AI RMF alignment review (T2-06) and attestation readiness scoping (T2-09). We produce the control design and the evidence. The certificate is issued by an accredited certification body and the SOC 2 report by a licensed CPA firm, never by us.

Frameworks

The four frameworks we work against

One control set, read four ways. The EU AI Act carries the legal obligation, ISO/IEC 42001 supplies the management system, NIST AI RMF supplies the risk method, and data protection law sits under all three. Most vendors present the middle two as a choice. They are complementary, and published crosswalks exist.

Booked engagements

Eight assessments. Every price published, every duration fixed.

Fixed scope and a slot on a calendar. A deposit reserves the week and the balance is invoiced against delivery. If your problem is not one of these, we will say so on the first call rather than three invoices in.

Book an engagement

Not sure which one? Describe the system in two sentences and we will name the right assessment, including when the answer is none of them.

Stated plainly

What we hold, and what we do not.

An assurance firm that overstates its own credentials has answered the only question that mattered. The list on the right costs us deals with buyers who wanted a badge, and it is the reason the ones who read carefully call back.

What we hold

  • OWASP Top 10 and MITRE ATT&CK as working method
  • EC-Council CEH
  • ISO/IEC 27001 trained
  • VAPT across 50+ government web assets
  • Critical CVE exposure reduced 65% across that estate

Offensive security is in-house rather than subcontracted, which is why the security review that stalls most AI projects is where we start instead of where we finish.

What we do not hold

SOC 2 Type II: not yet held
We do not have an attestation report. A SOC 2 report is issued by a licensed CPA firm after a defined observation window and it names the auditor, which is exactly why it cannot be self-asserted. We publish our actual posture instead.
ISO/IEC 42001: we cannot certify you, or ourselves
Certification requires an external audit by an accredited certification body. We are not one. We sell gap assessment, readiness, control design and evidence preparation for the auditor who does issue it. Any firm offering to certify you against ISO/IEC 42001 itself is telling you something useful about the firm.
We do not give legal advice
We describe obligations, gaps and the evidence that closes them. Anything with legal effect should be reviewed by counsel qualified in the relevant jurisdiction, and our reports say so on the page where it matters.
We do not guarantee compliance
No consultancy can, and a firm that offers the guarantee has either misread the regulation or is relying on you not reading it.

The full posture, including where data lives and what we will sign, is on our security page.

How it runs

Four commitments that apply to every engagement on this page.

  • Published price, fixed scope, fixed duration

    Every engagement above lists its price, its deposit and its length. There is no scoping fee and no discovery retainer in front of it.

  • A deposit reserves the slot

    The deposit holds the week on the calendar. The balance is invoiced against delivery, not before it.

  • Written for two readers

    Findings go to your engineers with enough detail to act on, and to your board with enough context to decide on. One engagement, both documents.

  • The section most reports leave out

    Every deliverable ends with an explicit list of the things you do not need us for, wherever that is true. It costs us follow-on revenue and it is the reason these convert.

Start here

Name the system a buyer or a regulator will ask about first.

Thirty minutes with the engineer who would run the assessment. We will tell you which engagement fits, what it will find, and where you can do the work yourself.

Assurance engagements $2,500 to $8,900, fixed price · Typical reply within one business day