About to deploy an AI vendor’s product and needing independent assurance before they sign.
Services · 03 - AI Assurance & Governance
Evidence, not adjectives.
Most AI software arrives at procurement with a marketing deck.
We arrive with an isolation report, a governance review and an audit-trail design, written in the language a security team and a buyer actually use.
Who this is for
Organisations that have to answer for AI.
Adopting AI, whether ours or someone else’s, and answerable for it to a regulator, a security team, a board, or a public-sector buyer.
Teams who’ve shipped AI and now have to defend it to their internal risk function or an external assessment.
AI vendors who want a credible, independent isolation and governance report they can show to procurement.
What you get
A structured engagement with four outputs.
An isolation review.
Does the system actually separate data between tenants the way it claims? We test it. The centrepiece is an automated cross-tenant isolation report - generated, repeatable proof that data cannot cross between customers, table by table.
It’s the artefact almost no AI vendor can hand you.
A model-governance review.
Are the models and personas versioned? Are they tested before they go live? Can you show what was live on a given day? Are governance rules explicit and enforced, or only documented?
We assess against a clear maturity model, and produce a written report with specific findings and a remediation backlog.
An audit-trail design.
Are the right events logged, with the right attribution, in a form that’s actually auditable? If not, what should be? We design it, specify it, and - if helpful - implement it.
The Assurance Pack.
A structured evidence bundle mapped to the questions enterprise security and public-sector assessments actually ask.
The pack is the artefact you hand to a procurement team or a security reviewer, written to read like architecture documentation, not marketing copy.
Why it’s different
The centrepiece is the cross-tenant isolation report.
Generated, not asserted.
It runs against the system. It produces evidence, not claims.
Repeatable.
Re-run it after every release, every model change, every new tenant. The result is the same kind of artefact, every time.
Specific.
It tests the actual data-isolation guarantees at the database - not “we have access controls” in general.
For an AI buyer or builder operating in a regulated environment, it’s the piece of evidence that decisively changes the conversation with security.
How we engage
Four steps, two optional.
Boundaries
What we don’t do.
We don’t issue certifications.
This is independent assurance and evidence, not accreditation. Where formal certification - ISO 27001, SOC 2, NHS DSPT - is the right next step, we’ll often be the preparation; the certification body is the certifier.
We don’t fix findings silently.
Findings are reported with the evidence behind them, in writing. Remediation is a separate, scoped workstream.
We don’t soften the report for the audience.
The point of independent assurance is that it’s independent.
Engagement shape
- Typical entry point
- Assurance Sprint · 2-4 weeks
- Output
- Isolation report, governance review, audit-trail design, the Assurance Pack
- Team
- Senior assurance lead · senior engineer · domain reviewer
- Follow-on
- Remediation, periodic re-assurance, or expansion to additional systems
Have an AI system you have to defend?
Evidence lands differently for a board, a regulator, a buyer. Tell us which one you’re facing.