Framework Compliance Assessment
Structured compliance assessments against the leading AI governance frameworks. Most organisations don't know their AI governance gaps until an auditor, regulator, or customer questionnaire finds them first. Our assessments give you a structured, actionable, evidence-based view of where you stand against one framework, or across several where more than one applies.
Frameworks covered

NIST AI RMF Assessment
-
What it is: Assessment against all 72 subcategories across the four NIST AI RMF functions: Govern, Map, Measure, and Manage.
-
Who it's for: Organisations needing a comprehensive, internationally recognised governance baseline, including for cross-border contracts and customer due diligence.
-
Output: Function-level and subcategory-level scoring, gap register, suggested actions.
.png)
AIUC-1 Assessment
-
What it is: Assessment against the AIUC-1 control set for AI agents, applied as a self-assessment lens rather than a certification pursuit.
-
Who it's for: Organisations building or deploying internal AI agents that take actions, not just answer questions.
-
Output: Control-level findings, gap list, and prioritised recommendations focused on agent authority, scope, and oversight.
.png)
VAISS Assessment
-
What it is: Assessment against Australia's Voluntary AI Safety Standard (10 guardrails).
-
Who it's for: Organisations deploying AI in or for the Australian market, or benchmarking against AU practice.
-
Output: Compliance score per guardrail, supporting evidence, gap list, prioritised recommendations.

NIST CSF 2.0 Assessment
-
What it is: Assessment against the six NIST CSF 2.0 functions: Govern, Identify, Protect, Detect, Respond, Recover.
-
Who it's for: Organisations whose AI governance has to sit inside an existing security programme, and who report to boards or regulators in cyber terms.
-
Output: Function and category-level scoring, gap register, and recommendations mapped to your existing control environment.
EU AI Act. We do not provide legal advice on AI Act classification. Where you have EU-facing AI systems, we assess your practical readiness against Article 50 transparency obligations, which applied from 2 August 2026, and map your existing governance to what the high-risk regime will require ahead of December 2027. Legal classification stays with your counsel; we cover the evidence and controls.
How it works
What you get
A structured report containing: overall and per-category compliance score, detailed observations against each requirement, identified gaps, and prioritised next steps. Written for management decision-making, not just auditors.
