Due Diligence

Risk and governance audits, done properly.

If you're inheriting a system, preparing for rollout, or under compliance pressure, you need a real audit, not opinions.

  1. 01 · Code

    Code and architecture audit. How it is built, and where the structural risk sits.

  2. 02 · Risk

    Risk and compliance review. Data flows and legal basis against the regime that applies.

  3. 03 · Test

    Model testing and bias. Measured behaviour on the cases that carry the exposure.

  4. 04 · Govern

    Governance setup. Monitoring, guardrails, documentation, ownership.

a system you did not buildopened layer by layereach one testedworst first, with the work beside ita system you did not buildCodeDataModelAccessopened layer by layereach one testedworst first, with the work beside ita system you did not buildCodepassDatafailModelreviewAccesspassopened layer by layereach one testedworst first, with the work beside ita system you did not buildCodepassDatafailModelreviewAccesspassopened layer by layereach one testedworst first, with the work beside it
How it works

From a closed system to a work plan.

Someone has to sign it off. This is what they get to sign off against.

  1. 01

    Closed

    An AI system arrives at a gate, and all anyone has is a summary from the people who built it.

  2. 02

    Opened

    We read it layer by layer: the code, the data it touches, the model, and who can reach what.

  3. 03

    Tested

    Each layer is measured rather than described. Some pass, some need review, some fail.

  4. 04

    Ranked

    Findings are ordered by severity, with the size of each fix beside it, so the report is a work plan.

We help when you're dealing with

The situations that usually bring people to an audit.

/01

Unclear data access

  • Nobody can state what the system reads, or on whose behalf.
/02

GDPR and AI Act risk

  • A deadline approaching, with the exposure unmeasured.
/03

Drift and instability

  • It worked at launch and nobody can say what it does now.
/04

No owner

  • In production, with no one formally responsible for it.
What we assess against

The frameworks and the checks we hold a system against.

  • EU AI Act

    Which risk category the system falls into, and what that requires.

  • GDPR

    Legal basis, data flows and retention, documented.

  • Code audit

    How it is built, and where the structural risk sits.

  • Risk review

    Each risk rated by impact and likelihood, with an owner.

  • Model testing

    Behaviour measured on the cases that carry the exposure.

  • Bias assessment

    Results compared across groups against a set threshold.

  • Governance setup

    Monitoring, guardrails, documentation and ownership in place.

Next service · Training

Learn from the team that actually ships AI.

Practical training built around production delivery, so teams can apply it immediately.

Open the service
Contact

Need to sign off on a system you did not build?

Tell us what the gate is and when it is. The scope follows from that.

Get in touch