top of page

AI Risk Desk

AI adoption outpaces governance in most organisations. Tools are deployed without oversight, risks accumulate quietly, and gaps surface only when something goes wrong. The AI Risk Desk covers the full arc: understanding where you stand, building what is missing, and monitoring what you run.

Understand where you stand

Framework Compliance Assessment

Best for: Organisations responding to external due-diligence or proactively managing AI compliance internally

Customers, partners, and regulators increasingly ask about AI framework alignment by name — and boards often want the same answer before anyone asks. We assess your organisation against the framework that matters to you: NIST AI RMF, Australia's VAISS, AIUC-1 for organisations building internal agents, or NIST CSF 2.0 where AI sits inside an existing security programme, depending on what you need to demonstrate, and deliver a compliance score, detailed findings, and prioritised recommendations.

Express AI Risk Assessment

Best for: Organisations wanting a fast first view of AI risk exposure

Not every organisation is ready for a full assessment engagement.  Sometimes you just need to know, quickly, where the biggest risks sit before deciding what to do next.  The Express AI Risk Assessment is a scoped, self-service review that surfaces your highest-priority AI risks without the time or cost of a full engagement.


It's designed as a practical entry point: a clear, prioritised starting list you can act on immediately, or use as the basis for deciding whether a deeper engagement, like a Framework Compliance Assessment or full Governance Review, is the right next step.

AI Risk and Governance Review

Best for: Organisations wanting expert judgement, not just a scored report

Scored assessments are useful, but they can't tell you whether your AI is actually well-governed in practice - only whether your documentation says it is.  The AI Risk and Governance Review is a practitioner-led engagement that looks past the paperwork: how AI systems are actually built, deployed, and overseen day to day.


This review covers three dimensions: AI practice maturity across your teams, product-level risk in specific AI systems you're running, and the strength of your organisational governance structures - roles, accountability, and escalation paths. The output is direct, practical judgment from someone who has done this work before, not a generic checklist.

Build what is missing

Agentic AI Governance

Best for: Organisations already running AI agents in production

Most AI governance work assesses what you have. This engagement builds what you need. Organisations shipping agents into production usually do not want another compliance assessment, they want working guardrails their engineers can build against the next sprint.

We govern individual agents, not the organisation. Each agent is registered, tiered by autonomy and action-space, and bounded by controls proportionate to what it can affect. The framework document is a by-product of that work, not the deliverable.

Two ways in, both three to four weeks at a fixed fee: an agent census if you cannot list what you are running, or control design if you already know which agents matter.

ISO 42001 Certification Support

Best for: Organisations for whom certification is a customer or contractual requirement

For some organisations, AI governance maturity isn't optional. A customer contract, tender requirement, or regulatory expectation may specifically call for ISO/IEC 42001 certification.  Getting there requires more than good intentions: auditors expect specific documentation, controls, and evidence trails that most organisations haven't yet built.


We help close that gap - identifying what's missing against the ISO/IEC 42001 standard, building the required documentation and controls, and preparing your organisation for the certification audit itself. The goal is a smooth audit, not a scramble.

Fractional AI Governance Lead

Best for: Organisations that know what needs building and have nobody to own it

Assessments end with a list of things to fix. Many organisations then discover the real constraint: AI governance is nobody's full-time job, and hiring for it is hard to justify against everything else competing for headcount.

We take the role on a retained, part-time basis. That means building what is missing: AI policy, use-case register, risk assessment process, roles and escalation paths, and then running it: running the review meetings, assessing new use cases as they arrive, and preparing the reporting that your board or auditors expect. The work is framework-agnostic, drawing on NIST AI RMF, ISO/IEC 42001, or VAISS as the situation requires, rather than committing you to any one of them.

Engagements typically run two to three quarters, by which point governance is operating, and the internal owner is clear. The intention is to hand it over, not to stay.

Monitor what you run

Skopix

Best for: Organisations needing ongoing compliance monitoring for live AI chatbots

Most AI chatbots are assessed once, then left unmonitored. Behaviour drifts, edge cases emerge, and compliance gaps go unnoticed until a customer complaint or regulator inquiry surfaces them. Skopix closes that gap with continuous, independent monitoring. It performs synthetic probing that tests your chatbot the way a real user would, with no SDK integration required. Findings map to NIST AI RMF, ISO/IEC 42001, and VAISS, in a form you can hand to a board, auditor, or customer's due-diligence team.

These engagements are scoped to your situation, not sold as fixed packages. A short conversation is usually the fastest way to find the right starting point.

bottom of page