AI Services

An AI audit that tells you what you are actually running

Almost every organisation we audit finds AI it did not know about: a team paying for a tool on a card, a supplier quietly adding a model to a product you already bought, a spreadsheet macro calling an API. The audit establishes the truth, then ranks what to do about it.

  • Two to four weeks
  • Evidence-based, not questionnaire-based
  • Findings mapped to a named control
AI Audit in practice
The problem

You cannot govern what nobody has counted

The gap between what an organisation believes it uses and what it actually uses is usually the whole finding.

  • Nobody can produce a list of the AI systems in use, with owners
  • AI spend is spread across departments, cards and bundled licences
  • Personal data is going into tools whose terms nobody has read
  • Suppliers have added AI features to existing contracts without a review
  • A regulator, insurer or enterprise customer has asked a question you cannot evidence
What we audit

Six lines of enquiry

The audit is evidence-first: we look at systems, contracts, logs and expenditure, and use interviews to explain what we find, not to establish it.

AI inventory, including shadow AI

Every AI system in use, discovered through expenditure records, browser and network telemetry where available, supplier contracts and team interviews. Each entry gets an owner, a purpose and a data classification.

Spend and duplication

What AI actually costs you across licences, credits and bundled features - and where three teams are paying for the same capability. This part frequently pays for the audit.

Data flows

What data leaves your boundary, to whom, under which terms, and whether it can be used for model training. Mapped so a DPO can act on it.

Control gaps

Your position against the obligations that apply to you: the EU AI Act where you serve EU users, ISO/IEC 42001, ICO guidance on AI and data protection, and your own sector regulator's expectations.

Model and use-case register

A living register of models, prompts, use cases and risk classification - the artefact most assurance conversations now begin with.

Value assessment

Which deployments are earning their keep, which are unused seats, and which workflows are still waiting for the tool they were promised.

In practice

What working with us looks like

The engagement runs with the people who do the work, not around them. Sessions are short, scheduled around delivery, and every stage ends with something you can act on.

You get a named consultant for the whole engagement - the person in the room is the person doing the work.

Reviewing records and evidence on screen
Photo: Unsplash
How it runs

Two to four weeks, minimal disruption

1

Kick-off and access

We agree scope, confidentiality and the data sources we can read. Most of the evidence already exists in finance, IT and procurement systems.

  • Read-only access requests kept to a minimum
  • NDA and data-handling agreed before anything is shared
2

Discovery

Expenditure analysis, contract review, systems and telemetry review, and interviews with the teams doing the work.

  • Shadow-AI discovery across departments
  • Supplier AI clauses read line by line
3

Assessment

Each finding is tested against a named control and given a severity, an owner and an effort estimate. Nothing is raised without evidence attached.

  • Severity rated by likelihood and impact, not by vibe
  • Quick wins separated from structural fixes
4

Report and walkthrough

A written report plus a session with your leadership team, ending in an agreed remediation plan with dates.

  • Executive summary a board can read in ten minutes
  • A remediation backlog your team can run without us
Deliverables

What you leave with

What you receive

  • Complete AI inventory with owners and data classification
  • Annualised AI spend, with duplication identified
  • Data-flow map and third-party processing position
  • Control-gap assessment against the frameworks that apply to you
  • Model, prompt and use-case register you can maintain
  • Prioritised remediation plan with effort and sequence
  • Board-level summary and a working action backlog

Why organisations run one now

Enterprise customers and public bodies increasingly ask suppliers to evidence their AI governance during procurement. An audit is the fastest route to an answer that survives scrutiny.

The EU AI Act's obligations land on organisations that place AI systems on the EU market or serve EU users, and they are staged - knowing which tier you sit in is the first practical step.

It is also the cheapest way to find money. Duplicate licences, unused seats and an over-specified model choice are common findings, and they are recoverable in the same quarter.

Where this fits

Related services and sectors

Questions

Questions about ai audit

No. This is a governance, spend and risk audit of AI use. If you need offensive security testing of an AI system we will say so and scope it separately - it is a different discipline with different evidence.
Mostly through money and contracts: card expenditure, SaaS renewals, and the AI clauses suppliers have added to existing agreements. Where you can give us browser or network telemetry we use that too, always with your agreement and within your own policies.
That is what it is built for. Every finding cites its evidence and maps to a named control, so it can be handed to an internal auditor, an ISO 42001 assessor or an insurer without translation.
Then you get a short report saying so, with the register and the evidence to prove it - which is exactly what you need when a customer asks. We would rather write that report than manufacture findings.

Book the audit

Two to four weeks from kick-off to a report your board, your regulator and your customers can all read.