Service Ladder

What We Deliver

Three tiers. Clear deliverables. No ambiguity. Every engagement is mapped against the frameworks relevant to your sector and tier.

Assessed against OWASP LLM Top 10 (2026)

OWASP published the 2026 edition on 3 August 2026 and renumbered eight of the ten entries. All six of our report templates were migrated and verified against it before this page went live. You receive a report that is current on the day it lands, with findings numbered the way your auditor, insurer or enterprise customer will expect from now on.

Tier 1

Basic AI Risk Assessment

£900

5 to 7 working days

A structured review of your AI tool usage mapped across five frameworks, six for recruitment, HR and accountancy clients. Key compliance gaps identified. Clear, prioritised action plan.

  • Complete AI tool inventory
  • EU AI Act risk classification (deployer tier)
  • OWASP LLM Top 10 (2026): all 10 categories
  • NIST AI RMF maturity snapshot
  • GRC posture overview: scored
  • UK GDPR & Data (Use and Access) Act 2025 compliance snapshot
  • Full risk register with free quick-win actions where available
  • Remediation roadmap: This Week / 30 Days / 90 Days
  • Founder-led delivery from discovery call to report
  • One-page executive summary with overall risk rating
  • Transparent 5x5 risk scoring methodology
  • Sector assessment: Equality Act 2010 & EHRC (recruitment and HR clients) or professional standards (accountancy clients)
Get Started: From £900

Tier 2

Full AI Risk Review

£2,500

7 to 10 working days

Board-ready deep-dive. Everything in Basic expanded to full depth, plus DPA review, Staff AI Policy, and 90-day reassessment call.

Everything in Basic, plus:

  • EU AI Act deployer gap analysis: per tool, per article
  • NIST AI RMF full 4-function assessment
  • GRC framework scored 1 to 10 across all three pillars
  • UK GDPR + Data (Use and Access) Act 2025 full gap analysis
  • Framework cross-reference matrix: every framework in scope
  • Documented Evidence Register for every material finding
  • Regulatory exposure explained against UK GDPR fine ceilings
  • DPA review: up to 10 AI tool providers
  • 14-clause Staff AI Usage Policy + ADM procedure (Articles 22A to 22D)
  • 90-day roadmap with action owners
  • Extended findings walkthrough on delivery, plus 90-day reassessment session
  • Full sector assessment: Equality Act 2010 & EHRC (recruitment and HR clients) or professional standards (accountancy clients)
Get Started: From £2,500

Ongoing Support

Retainer

£395

Per month · billed monthly · 12-month term

AI adoption doesn't stop after a single assessment. A retainer keeps your compliance posture current as legislation evolves, new tools are adopted, and your AI footprint grows.

  • Quarterly AI risk reassessment against standing risk register
  • Up to 3 tool vettings per quarter (verdict within 2 to 5 working days)
  • Policy updates at each quarterly reassessment, plus written alerts for urgent changes
  • Written regulatory alerts
  • 2 advisory hours per quarter

What we don't do: penetration testing, red teaming, vulnerability scanning or incident response, and no emergency or same-day response service. Our work is not legal advice and does not guarantee compliance.

The Process

What to Expect

Every engagement begins with a 30 to 45 minute discovery call. No technical knowledge required on your side. We map your AI tool usage, data flows, governance position, and sector-specific obligations.

From there, we work independently. You receive your report within the stated turnaround, walk through it together, and leave with complete clarity on next steps.