How it works
We establish how your business actually works, then examine what AI is doing inside it against the standards that apply — recording what evidence exists, what does not, and a professional view on each. The result is a documented position on your AI use, and a clear sequence for closing what is missing.
Architecture first
We model the business before the AI: the areas it operates across, the people and roles within them, the certifications and assurances already held, and the regulatory regimes that apply given your sector. This is business architecture applied to an assurance problem.
Operations and their steps
Each operation is then modelled in sequence: the objective it serves, its constituent steps, the roles performing and approving each, the classes of data moving through them, the systems and AI products they run on, and the points at which a human reviews output before it has effect. Operations with no AI in them are modelled too.
The standards that apply are raised
Drawn from ISO/IEC 42001, the EU AI Act, UK GDPR, the NIST AI Risk Management Framework, the UK's AI principles and OWASP guidance — plus questions no framework asks but every business should. Which apply depends entirely on what you told us. Nothing is raised that does not fit your business and how it operates.
Each standard is worked through
Three positions are possible for any applicable standard. It is met, with an artefact that evidences it — we review the artefact and record our acceptance of it, with the basis on which we accepted it. It is believed to be met, but nothing evidences the claim — we identify what would, and help obtain or produce it. Or it is not met, in which case the remedy is either operational work we can carry out, or a specialist we name and describe.
The record stands on its own
Every fact carries its provenance — how it is known, and from whom. Every closure carries the name of the person who accepted it, the date, and the basis. Every gap that remains carries what closing it would require. The result is a position that can be produced on request, understood by someone who was not in the room, and defended two years later.
Purpose-built tooling
The method is supported by an assessment platform built specifically for this work. It holds the map of your business, the standards that apply, the evidence recorded against each, and every judgement made — with its date and its basis.
That matters for three reasons. The same questions get asked every engagement, in the same way, so nothing depends on what anyone remembered to raise. Evidence gathered once answers every future use that relies on it. And the record is auditable long after the engagement ends.
The platform surfaces evidence and tracks its state. It produces no score, no rating and no conclusion. Every judgement in it carries a named person and a date.
The answers accumulate
Evidence gathered once — a supplier agreement, a policy, a training record — answers every future use that relies on it. The fifth AI tool you adopt costs a fraction of the first to assure.
Progress is visible and evidenced, without resorting to a score.
What the tool does, and what we do
Shows what is there, what is missing, and how it knows. It asks the same questions every time, sees absence that human review misses, and never forgets. It never scores, never ranks, never concludes.
Decides what it means, what matters most, and what to do next — and records it. Accountability for your compliance stays with you; the judgement on the evidence is ours, named and dated.