It fits when
- You have AI in production or about to be, and you haven't formally reviewed governance.
- A procurement, board, or audit event has triggered "can we defend this?"
- You operate in a regulated sector and need the evidence on file.
A short-form review of your AI plans (or existing AI footprint) against GDPR, ethics, data quality, security, and data sovereignty, with a hand-to-compliance report at the end.
Intake + documentation review
What AI is already in play, what policies exist, what audit triggers are in flight.
Stakeholder interviews
DPO, security lead, AI owner, procurement. Short, structured, on-record.
Framework-by-framework assessment
GDPR, ethics, data quality, security, sovereignty. Evidence, gaps, severity.
Written report + readout
Joint session with compliance and operations. Report handed over for the file.
1–2 weeks
Fixed fee
Fixed fee at kickoff. Scope covers one AI footprint (one product line, one department, or one adoption plan).
An anonymised sample of a past deliverable for this engagement is being prepared. Until it's published here, the clearest picture comes from the methodology page. This service is one productised slice of the same method.
You can usually get the compliance team to approve something. The question is whether you can defend it later, when something goes wrong, when an auditor asks, when the regulator changes position.
If you haven't scoped the AI problem yet.
See the Discovery SprintFor the finance side of the same decision.
See the Cost & ROI ModelOnce governance is cleared, prove the build.
See the Rapid Secure AI POC