Services · 03 - AI Assurance & Governance

Evidence, not adjectives.

The independent proof that your AI system isolates data, governs its models, and can be audited.

Most AI software arrives at procurement with a marketing deck.

We arrive with an isolation report, a governance review and an audit-trail design, written in the language a security team and a buyer actually use.


Who this is for

Organisations that have to answer for AI.

Adopting AI, whether ours or someone else’s, and answerable for it to a regulator, a security team, a board, or a public-sector buyer.

Buyers

About to deploy an AI vendor’s product and needing independent assurance before they sign.

Builders

Teams who’ve shipped AI and now have to defend it to their internal risk function or an external assessment.

Vendors

AI vendors who want a credible, independent isolation and governance report they can show to procurement.

What you get

A structured engagement with four outputs.

01 / 04

An isolation review.

Does the system actually separate data between tenants the way it claims? We test it. The centrepiece is an automated cross-tenant isolation report - generated, repeatable proof that data cannot cross between customers, table by table.

It’s the artefact almost no AI vendor can hand you.

A cross-tenant read, refused at the database, recorded as evidence.
02

A model-governance review.

Are the models and personas versioned? Are they tested before they go live? Can you show what was live on a given day? Are governance rules explicit and enforced, or only documented?

We assess against a clear maturity model, and produce a written report with specific findings and a remediation backlog.

03

An audit-trail design.

Are the right events logged, with the right attribution, in a form that’s actually auditable? If not, what should be? We design it, specify it, and - if helpful - implement it.

04

The Assurance Pack.

A structured evidence bundle mapped to the questions enterprise security and public-sector assessments actually ask.

The pack is the artefact you hand to a procurement team or a security reviewer, written to read like architecture documentation, not marketing copy.

Why it’s different

The centrepiece is the cross-tenant isolation report.

Generated, not asserted.

It runs against the system. It produces evidence, not claims.

Repeatable.

Re-run it after every release, every model change, every new tenant. The result is the same kind of artefact, every time.

Specific.

It tests the actual data-isolation guarantees at the database - not “we have access controls” in general.

For an AI buyer or builder operating in a regulated environment, it’s the piece of evidence that decisively changes the conversation with security.


How we engage

Four steps, two optional.

01 Scoping We agree what’s in scope - which system, which environment, which tenants - what assurance frameworks the output needs to map to, and who the audience is: procurement, internal risk, external assessor. 1 wk
02 Assurance Sprint We run the isolation tests, the governance review and the audit-trail analysis. We sit with engineering to confirm findings before we finalise. We produce the written report and the Assurance Pack. 2-4 wks
03 Optional remediation If findings need to be closed before the system can go live (or stay live), we can either advise your team through the remediation or implement it ourselves under a separate engagement. Variable
04 Optional periodic re-assurance For systems we’ve previously assured, we can run a periodic re-test to keep the evidence current. Quarterly / annual

Boundaries

What we don’t do.

We don’t issue certifications.

This is independent assurance and evidence, not accreditation. Where formal certification - ISO 27001, SOC 2, NHS DSPT - is the right next step, we’ll often be the preparation; the certification body is the certifier.

We don’t fix findings silently.

Findings are reported with the evidence behind them, in writing. Remediation is a separate, scoped workstream.

We don’t soften the report for the audience.

The point of independent assurance is that it’s independent.

Engagement shape

Typical entry point
Assurance Sprint · 2-4 weeks
Output
Isolation report, governance review, audit-trail design, the Assurance Pack
Team
Senior assurance lead · senior engineer · domain reviewer
Follow-on
Remediation, periodic re-assurance, or expansion to additional systems

Have an AI system you have to defend?

Evidence lands differently for a board, a regulator, a buyer. Tell us which one you’re facing.