Tier 1

Basic AI Risk Assessment

From £900 · 5 to 7 Working Days

A structured review of your AI tool usage mapped across five frameworks, six for recruitment, HR and accountancy clients. Identifies key compliance gaps and delivers a clear, prioritised action plan for your business.

What's Included

01

AI Tool Inventory

We document every AI tool in use across your business: by department, by function, and by the data each tool touches. Businesses typically discover tools they weren't aware staff were using.

02

EU AI Act Risk Classification

Each tool in your inventory is classified against the EU AI Act's four-tier risk hierarchy: Unacceptable Risk, High Risk, Limited Risk, Minimal Risk. As a deployer, you carry distinct obligations at each tier. Prohibited applications are flagged immediately. AI literacy (Article 4) applies now; high-risk deployer obligations are phased in from December 2027.

03

OWASP LLM Top 10 (2026) Assessment

All 10 vulnerability categories assessed against your current tool usage and deployment, using the 2026 edition published on 3 August 2026. Includes prompt injection (LLM01), sensitive information disclosure (LLM02), excessive agency (LLM03), data and model poisoning (LLM05), hidden context exposure (LLM08), and improper output handling (LLM10). The 2026 edition renumbered eight of the ten entries, so findings carry the numbering your auditor or insurer will expect.

04

NIST AI RMF Maturity Snapshot

A rapid maturity assessment across NIST AI RMF's four functions (GOVERN, MAP, MEASURE, MANAGE). Establishes your current baseline and identifies the highest-priority gaps.

05

GRC Posture Overview

Governance, Risk, and Compliance assessed and scored across your current AI usage. Identifies structural gaps in oversight, accountability, and control that create organisational exposure.

06

UK GDPR & Data (Use and Access) Act 2025 Compliance Snapshot

A targeted review of your AI-related compliance position under UK GDPR and the Data (Use and Access) Act 2025 (DUAA). DUAA replaced Article 22 UK GDPR with new Articles 22A to 22D, in force since 5 February 2026, requiring safeguards (notice, representations, human intervention, contest) for solely automated significant decisions, meaning decisions taken with no meaningful human involvement. Includes lawful basis assessment, DPIA requirement identification, and ADM compliance.

07

Full Risk Register

Every identified risk documented with: risk description, relevant framework, severity rating, likelihood, business impact, and the specific immediate action required to remediate. Findings include practical actions, many of them free.

08

Prioritised Remediation Roadmap

All findings organised into three action horizons: This Week (free quick wins where available), 30 Days (quick-win implementations), and 90 Days (strategic compliance investments).

09

Founder-Led Delivery

The person who runs your discovery call is the person who writes your report. No account managers, no handoffs, no junior analysts. You deal directly with the founder of QuaZarR Security from first call to final delivery.

10

One-Page Executive Summary

A board-ready single page presenting your overall risk rating, top three priority findings, and the single most important action to take immediately. Designed to be shared with directors, investors, or compliance leads without requiring them to read the full report.

11

Transparent 5x5 Risk Scoring Methodology

Every risk in your register is scored out of 25 using a defined 5x5 matrix: five likelihood levels multiplied by five impact levels, each with explicit anchors. Scores are never subjective. You receive the scoring matrix alongside every finding so you can challenge, verify, and track changes over time.

12

Sector Assessment

For recruitment clients: we assess your AI-assisted sourcing, screening and shortlisting tools against the Equality Act 2010 and EHRC guidance, checking for discriminatory or biased automated decisions, indirect discrimination risk, and the safeguards required before an AI tool influences who you interview or reject. For HR clients: the employer duties in section 39 apply to recruitment, promotion, performance and dismissal decisions, assessed alongside the EHRC Employment Statutory Code of Practice. For accountancy clients: a professional standards review covering the Code of Ethics and PCRT. We assess against published guidance. We are not endorsed, certified or approved by the EHRC or any professional body.

Turnaround

5 to 7 working days once we have everything we need from you.

QuaZarR Security provides risk assessment and guidance, not legal advice.