top of page

Confidence to act. Clarity to decide.

Independent advisory for mid-sized organisations building AI governance and cyber resilience that stands up to scrutiny.

Who We Are

New Pacific Way is a specialist advisory firm helping mid-sized organisations govern AI and strengthen cyber resilience. We work with business owners and managers who need actionable intelligence, not lengthy reports. Assessments that end in a prioritised decision, and engagements that close the gaps they find. Our experience spans 20+ years across risk management, corporate governance, cybersecurity, and AI, built in APAC and Europe.

 

We do not sell fear. We provide the clarity and confidence to move forward.

AI Risk Desk

AI adoption outpaces governance in most organisations. Tools are deployed without oversight, risks accumulate quietly, and gaps surface only when something goes wrong. The AI Risk Desk provides structured assessment of AI use, risks, and priorities across your organisation.

Framework Compliance Assessment

Best for: Organisations responding to or managing AI compliance 

 

Structured assessment against NIST AI RMF or VAISS, delivering a compliance score, detailed findings, gaps, and prioritised recommendations.

AI Risk and Governance Review

Best for: Organisations wanting expert judgement, not just a scored report

 

A practitioner-led review of AI practice maturity and governance - assessing how AI is actually built, not just how it's documented.

Express AI Risk Assessment

Best for: Organisations wanting a fast first view of AI risk exposure

 

A fast, scoped self-assessment that surfaces the highest-priority risks quickly - a practical entry point before a full engagement.

Fractional AI Governance Lead

Best for: Organisations that know what needs building and have nobody to own it

A retained, part-time governance lead — building the policy, register, and review process, then running it until your team can.

Cyber Resilience

Knowing your controls are covered is not the same as knowing your organisation would cope. We test how your people, systems, and suppliers hold up under pressure, and then help you strengthen what is exposed.

Incident Response Readiness

Best for: Organisations that need to know their response plans work

 

Facilitated tabletop exercises that test whether your response plan works, including AI failure scenarios most plans don't cover.

Security Testing Design and Oversight

Best for: Organisations wanting security testing to answer the right questions

 

We scope and brief your penetration and red team testing, select the provider, and review what comes back independently.

Third-Party Security Due Diligence

Best for: Organisations answering security questionnaires, or sending them

Security questionnaires in both directions: your responses, and your assessment of vendors and partners.

AI Assurance Products

Skopix

Continuous, independent monitoring for AI chatbots. Detects hallucinations, drift, and compliance violations through synthetic probing, with no SDK integration required. Findings map to NIST AI RMF, ISO/IEC 42001, and VAISS, and arrive in a form you can hand to a board, auditor, or customer.

 

USD 275/month per bot. No SDK integration.

We practice what we advise

These are public, voluntary frameworks we align our practice with. We hold ourselves to the same standards we assess for clients. Our own internal self-assessments cover NIST AI RMF and VAISS, reassessed quarterly.

NIST AI RMF
Voluntary AI Safety Standard
OECD AI Principles

Confidence to act. Clarity to decide.

Get a clear, prioritised view of your AI and security risks without lengthy reports.

bottom of page