AI Risk, Compliance & Assurance
Identify, evaluate, treat and evidence AI risk in a form auditors accept.
What the engagement covers.
AI risk is not a new register; it is new content in the existing one. This service classifies use cases, assesses impact and produces the evidence trail regulators and internal audit will ask for.
Included capabilities
- AI regulatory compliance assessment and readiness audit
- AI risk and impact assessments including affected-person analysis
- Use-case inventory with risk classification by impact and autonomy
- Control mapping, evidence, issue and action management
- Independent governance and control assessment
Outputs and deliverables
- AI risk and impact assessment reports
- Use-case inventory with risk classification
- AI control catalogue and traceability matrix
- Independent assessment report for audit committee
How it is delivered, step by step.
Each step has an owner, an entry condition and an artefact that has to exist before the next step begins.
Where this is typically applied.
Internal audit requesting assurance over AI deployments
Vendor AI systems requiring impact assessment before procurement
The operating pattern for AI System Advisory & Development.
The same delivery discipline applies across every capability in this line, so combined engagements stay coherent.
Integration
- Model registry, feature store and MLOps pipelines for lifecycle gates.
- GRC platform for AI control mapping, evidence and issue management.
- Data catalogue and lineage tooling for dataset provenance.
- Security stack for logging, monitoring and incident handling of AI systems.
Engagement approach
Baseline engagements are a readiness and risk assessment. Build engagements operationalize the framework. Assurance engagements test models, LLM applications, agents and the governance controls around them, then validate remediation.
Other capabilities in AI System Advisory & Development.
AI Strategy & Readiness
Decide where AI is worth doing before deciding how.
AA-03Secure AI Lifecycle Development
Build the controls into the pipeline rather than reviewing at the end.
AA-04Explainability & Human Oversight
Make automated decisions explainable to the person they affect.
AA-05AI Capability Development
Give decision-makers and builders the skills the strategy assumes they have.
AA-06AI Solution Implementation
Take responsible AI requirements all the way into working systems.