Confidence to act. Clarity to decide.
Independent advisory for mid-sized organisations building AI governance and cyber resilience that stands up to scrutiny.
Who We Are
New Pacific Way is a specialist advisory firm helping mid-sized organisations govern AI and strengthen cyber resilience. We work with business owners and managers who need actionable intelligence, not lengthy reports. Assessments that end in a prioritised decision, and engagements that close the gaps they find. Our experience spans 20+ years across risk management, corporate governance, cybersecurity, and AI, built in APAC and Europe.
We do not sell fear. We provide the clarity and confidence to move forward.
AI Risk Desk
AI adoption outpaces governance in most organisations. Tools are deployed without oversight, risks accumulate quietly, and gaps surface only when something goes wrong. The AI Risk Desk provides structured assessment of AI use, risks, and priorities across your organisation.
Framework Compliance Assessment
Best for: Organisations responding to or managing AI compliance
Structured assessment against NIST AI RMF or VAISS, delivering a compliance score, detailed findings, gaps, and prioritised recommendations.
AI Risk and Governance Review
Best for: Organisations wanting expert judgement, not just a scored report
A practitioner-led review of AI practice maturity and governance - assessing how AI is actually built, not just how it's documented.
Express AI Risk Assessment
Best for: Organisations wanting a fast first view of AI risk exposure
A fast, scoped self-assessment that surfaces the highest-priority risks quickly - a practical entry point before a full engagement.
Fractional AI Governance Lead
Best for: Organisations that know what needs building and have nobody to own it
A retained, part-time governance lead — building the policy, register, and review process, then running it until your team can.
Cyber Resilience
Knowing your controls are covered is not the same as knowing your organisation would cope. We test how your people, systems, and suppliers hold up under pressure, and then help you strengthen what is exposed.
Incident Response Readiness
Best for: Organisations that need to know their response plans work
Facilitated tabletop exercises that test whether your response plan works, including AI failure scenarios most plans don't cover.
Security Testing Design and Oversight
Best for: Organisations wanting security testing to answer the right questions
We scope and brief your penetration and red team testing, select the provider, and review what comes back independently.
Third-Party Security Due Diligence
Best for: Organisations answering security questionnaires, or sending them
Security questionnaires in both directions: your responses, and your assessment of vendors and partners.
AI Assurance Products
Skopix
Continuous, independent monitoring for AI chatbots. Detects hallucinations, drift, and compliance violations through synthetic probing, with no SDK integration required. Findings map to NIST AI RMF, ISO/IEC 42001, and VAISS, and arrive in a form you can hand to a board, auditor, or customer.
USD 275/month per bot. No SDK integration.

.png)
.png)
.png)