🔍 Service 05  ·  AI Audit Suite

You Can't Govern
What You Haven't
Measured.

Independent. Fixed-Fee. Actionable From Day One.

Productized AI maturity assessments, ISO 42001 pre-audit readiness checks, AI risk scans, and vendor evaluations — independently delivered before you commit to a full governance programme.

Most AI governance programmes fail not because the organisation lacked commitment — but because they started building without knowing where they actually stood. An audit tells you the truth. Then you can build on it.

🏛️ ISO 42001 Lead Auditor 📜 ISO 27001 · 31000 · 37301 ⚫ Six Sigma Black Belt 🔍 Independent — No Vendor Affiliations 🌐 GCC & India Specialist
5
Distinct Audit Products
Including a Free Tier
39
ISO 42001 Annex A
Controls Assessed
7
Maturity Dimensions
Assessed Per Engagement
1wk
Fastest Audit Turnaround
AI Risk Quick-Scan

The Cost of Building Without Knowing

Organisations that skip the baseline assessment typically spend three to six months building governance structures that don't address their actual gaps — then discover this at their first audit or regulator review.

?

You're building governance on top of unknown risk.

AI tools are already deployed. Data is already flowing. But nobody has mapped what AI is being used for, what data it touches, or what the failure scenarios are. That's not a governance programme — it's a paper exercise.

?

Your ISO 42001 preparation started in the wrong place.

Many organisations begin ISO 42001 certification preparation by writing policies — without first assessing their gap against the standard. The result: policies written for an imagined organisation, not the actual one.

?

Your AI vendor's claims haven't been independently tested.

"ISO-aligned." "Enterprise-ready." "Fully compliant." Every AI vendor says this. Without an independent technical and governance evaluation, you have no way to verify what's real and what's marketing.

?

You have a risk register but no idea if it's complete.

A risk register created by people inside the organisation tends to miss the risks they're most exposed to — because those are the risks they're most normalised to. An independent scan surfaces what's been missed.

Five Levels. One Honest Score.

Every AI Audit Suite engagement maps your organisation against a five-level maturity model — structured around ISO 42001 and benchmarked against real organisations across comparable industries. Your score tells you where you are today, what the next level looks like, and which gaps to close first to progress efficiently. No inflated scores. No vanity metrics. An honest read your leadership can act on.

1
InitialAd hoc & reactive
No formal AI governance. AI tools used without policy, oversight, or documentation. Risks unidentified. Most organisations discover they are here during their first assessment.
Level 1 / 5
2
DevelopingAwareness exists, little structure
Leadership aware of AI governance obligations. Some informal policies exist. AI risks partially identified but not systematically managed. No formal ISO 42001 alignment.
Level 2 / 5
3
DefinedDocumented but inconsistently applied
Formal AI policy in place. Risk register exists. Roles assigned. Controls documented but not consistently applied across the organisation. Audit-readiness is partial.
Level 3 / 5
4
ManagedMeasured, monitored & improving
AI governance embedded in operations. KPIs tracked. Regular reviews conducted. ISO 42001 substantially aligned. Audit evidence organised. Management reviews producing real decisions.
Level 4 / 5
5
OptimisingCertified, adaptive & leading
ISO 42001 certified or certification-ready. Continuous improvement culture active. AI governance is a competitive differentiator — used in RFPs, investor materials, and regulatory submissions.
Level 5 / 5

Five Productized Audit Offerings

Each audit is a fixed-scope, fixed-fee product — scoped precisely so you know exactly what you're buying, what you'll receive, and when. Start with the free assessment or go straight to the product that matches your most urgent need.

Free
// AUDIT 01
🎯

AI Readiness Assessment

Online · 10 Minutes · Instant Results

The zero-commitment entry point. A structured 10-minute online diagnostic that maps your AI readiness across five dimensions and gives you an immediate maturity indication with prioritised next steps.

Free Instant Results No Registration Required 5 Dimensions
  • 10-question structured diagnostic
  • Instant maturity score across 5 dimensions
  • Automated priority recommendations
  • PDF summary report emailed on completion
  • Optional upgrade to paid Deep-Dive Report
Take The Free Assessment →
// AUDIT 03

AI Risk Quick-Scan

1 Week · Targeted · Risk-Focused

A focused, rapid risk assessment for organisations that need to understand their immediate AI risk exposure — without committing to a full maturity programme. Best when triggered by a specific incident, tender requirement, or regulatory query.

Fixed-Fee 1-Week Turnaround Risk Register Output Immediate Actions
  • Scoped intake questionnaire (async, 20 minutes)
  • AI use case inventory and data flow review
  • Risk identification across 5 AI risk categories
  • Severity-rated risk register (likelihood × impact)
  • Top 5 immediate actions with owners and timelines
  • Written report delivered within 5 business days
Book The Risk Scan →
// AUDIT 04
🏛️

ISO 42001 Pre-Audit Readiness Check

2–4 Weeks · Certification-Track · Clause-Level

A structured pre-certification audit for organisations pursuing ISO 42001 certification — identifying precisely which clauses and Annex A controls are complete, partially addressed, or missing, with a remediation plan before the formal audit.

Fixed-Fee All 39 Controls Certification-Track Evidence Pack Review
  • Clause-by-clause review against ISO 42001 requirements
  • All 39 Annex A controls assessed and rated
  • Evidence pack review and gap identification
  • Nonconformity log with severity classification
  • Pre-audit remediation plan with priorities and timelines
  • Certification body selection advisory
  • Mock audit walkthrough session (optional add-on)
Book ISO 42001 Check →
// AUDIT 05
🔭

AI Vendor & Tool Evaluation

1–2 Weeks · Independent · No Vendor Affiliations

An independent evaluation of a specific AI vendor, platform, or tool — covering capability claims, governance compliance, data handling, integration risks, and contract red flags. Used before purchasing, renewing, or expanding a vendor relationship.

Fixed-Fee 100% Independent No Vendor Commission Contract Review Included
  • Capability claims verification against stated specifications
  • Data handling and privacy compliance review
  • ISO 42001 and ISO 27001 alignment assessment
  • Integration risk and dependency analysis
  • Vendor contract red-flag review (key clauses)
  • Comparison against 1–2 alternatives (if requested)
  • Written recommendation with buy / negotiate / avoid rating
Book Vendor Evaluation →

What A Deep-Dive Report Actually Contains

A maturity report is only valuable if it's specific, actionable, and honest. Here's the exact structure of every AI Maturity Deep-Dive Report — so you know what you're receiving before you commission it.

📄 Report Structure — 8 Sections

1

Executive Summary

1-page board-ready summary — overall maturity level, top three strengths, top three risks, and primary recommendation.

2

Methodology & Scope

How the assessment was conducted, what was reviewed, who was interviewed, and what limitations apply.

3

Maturity Scorecard

Scored across all 7 dimensions — benchmarked against industry peers and the ISO 42001 standard.

4

Dimension-Level Analysis

Detailed findings for each of the 7 assessment dimensions — what's working, what's missing, and what that means.

5

ISO 42001 Gap Map

Clause-by-clause gap analysis — Conformant / Partial / Not Addressed — across ISO 42001 Clauses 4–10 and all 39 Annex A controls.

6

Prioritised Gap Register

Every identified gap rated by severity, effort to close, and business impact — sorted by priority so you know where to start.

7

12-Month Improvement Roadmap

Phased action plan — Quick Wins (0–3 months), Foundation (3–6 months), Maturity Build (6–12 months).

8

Recommended Next Steps

Specific, sequenced recommendations — including whether a full governance programme, targeted sprint, or certification track is the right next engagement.

📋 Sample Scorecard Output

AI Strategy & LeadershipLevel 2 — Developing
AI Risk ManagementLevel 1 — Initial
Data Governance for AILevel 2 — Developing
AI Policy & DocumentationLevel 3 — Defined
AI Operations & MonitoringLevel 1 — Initial
AI Talent & CapabilityLevel 3 — Defined
Responsible AI & EthicsLevel 2 — Developing
Overall Maturity Score 2.1 — Developing

*Illustrative sample. Actual scores reflect your organisation's specific situation. Scores are not used for marketing — your report is confidential.

🔍 What Makes This Report Different

Most AI maturity reports are produced by generalist consultants using a generic scoring template. Ours is produced by an ISO 42001 Lead Auditor who is actively managing live AI governance programmes — which means the gaps we identify are the gaps that actually get challenged in real audits, the controls we assess are the ones certification bodies actually check, and the roadmap we produce is grounded in what genuinely moves organisations from one level to the next. We've seen what passes and what fails under real scrutiny. That's what you get in the report.

What Gets Evaluated — In Depth

Every Deep-Dive Report and ISO 42001 Readiness Check covers all seven dimensions. Each dimension maps to specific ISO 42001 clauses and Annex A controls — so findings are always traceable to the standard.

Dimension 01
🧭

AI Strategy & Leadership

How well AI ambition is defined, owned, and resourced at leadership level.

  • Documented AI strategy and roadmap
  • Board and executive AI ownership
  • AI investment and resource allocation
  • ISO 42001 Clauses 4, 5, 6 alignment
Dimension 02
⚠️

AI Risk Management

The rigour and completeness of how AI-specific risks are identified, assessed, and treated.

  • AI risk register existence and currency
  • Risk assessment methodology
  • Treatment plans and control mapping
  • ISO 42001 Clause 6.1, Annex A controls
Dimension 03
🗄️

Data Governance for AI

How data used to train, run, and evaluate AI systems is classified, protected, and managed.

  • Data classification and sensitivity mapping
  • Training data quality controls
  • Data retention and deletion for AI
  • ISO 42001 Annex A.8 alignment
Dimension 04
📋

AI Policy & Documentation

The completeness, currency, and practical usability of your AI governance documentation suite.

  • AI policy existence and board approval
  • Operational procedures and SOPs
  • Document control and version management
  • ISO 42001 Clause 7.5, Annex A.2 alignment
Dimension 05
⚙️

AI Operations & Monitoring

How deployed AI systems are monitored, reviewed, and maintained against performance and compliance standards.

  • AI system performance monitoring
  • Model drift detection and response
  • Incident reporting and management
  • ISO 42001 Clauses 8, 9 alignment
Dimension 06
🧠

AI Talent & Capability

Whether your organisation has the skills, training, and role clarity to govern and use AI responsibly.

  • AI competency framework and role mapping
  • Training programme existence and coverage
  • AI governance awareness across the organisation
  • ISO 42001 Clause 7.2, Annex A.4 alignment
Dimension 07
⚖️

Responsible AI & Ethics

How fairness, transparency, accountability, and human oversight are embedded in your AI programme.

  • Bias testing and fairness controls
  • Transparency and explainability practices
  • Human-in-the-loop design for high-risk decisions
  • ISO 42001 Annex A.6, EU AI Act alignment

How The Deep-Dive Audit Runs

A structured, four-phase process designed to produce an honest, defensible, and actionable maturity assessment — without consuming excessive leadership time.

1
Day 1–2 — Scoping

30-Minute Intake & Context Setting

A structured intake call covering your organisation's AI landscape — tools deployed, use cases live, regulatory environment, existing governance artefacts, and any known risk areas. This ensures the assessment covers what matters for your specific situation — not a generic checklist. Output: confirmed scope, evidence request list, and assessment plan.

2
Week 1 — Evidence Review

Document & Artefact Review

Review of your existing governance artefacts — policies, risk registers, SOPs, training records, system inventories, vendor contracts, and any ISO documentation already in place. Submitted securely via a shared workspace. No stakeholder time required beyond the intake call and one follow-up Q&A slot. Output: evidence inventory and preliminary gap identification.

3
Week 1–2 — Analysis

Gap Analysis & Maturity Scoring

Assessment across all seven dimensions against the ISO 42001 framework and the five-level maturity model. Each dimension scored independently, then cross-referenced for coherence. Gaps classified by severity (critical / major / minor / observation) and mapped to specific corrective actions. Output: completed maturity scorecard and gap register.

4
Week 2–3 — Reporting

Report Production & Findings Presentation

Full written report produced to the eight-section structure. Executive summary formatted for board presentation. 12-month roadmap phased and sequenced. Report delivered digitally before the findings call. 45-minute findings presentation to your leadership team — walking through the scorecard, the critical gaps, and the recommended roadmap. Questions answered live. Output: final report, roadmap, and leadership session recording (if requested).

What Changes After The Audit

An audit is only worth commissioning if the output creates clarity and enables action. Here's what every Deep-Dive engagement produces.

An Honest Baseline You Can Trust

Not a self-assessment that scores you where you'd like to be — an independently produced baseline that accurately reflects where you are. That's what makes subsequent improvement measurable.

A Prioritised Gap Register, Not A List

Every gap rated by severity, effort to close, and impact on certification or regulatory posture. You know exactly which three to five gaps to address first — and why the sequence matters.

A Board-Presentable Executive Summary

A one-page summary your CEO or CFO can present to the board — showing the AI governance posture, the risk exposure, and the investment required to reach the next maturity level.

A Certification Decision Made Confidently

Know precisely how far you are from ISO 42001 certification-readiness, what it will cost to get there, and whether a certification track makes commercial sense for your situation right now.

Regulatory Exposure Quantified

Your exposure to EU AI Act, Saudi AI principles, India DPDP, and ISO 42001 requirements mapped against your current state — so you know where the regulatory risk actually sits.

A Foundation For The Next Engagement

Whether the next step is a full governance programme, an ISO 42001 sprint, or a targeted policy build — the audit report becomes the brief. No re-scoping. No re-discovery. You start building from a known position.

Start Here. Build From A Known Position.

The AI Audit Suite is deliberately designed as the entry point for organisations that haven't yet committed to a full governance programme. It answers the question "where are we?" before you spend budget on the question "what should we build?" Most clients who begin with an audit move into a focused governance engagement within 60 days — with a clear brief, a prioritised scope, and no wasted effort.
🎯
Free Assessment
10 min online · Instant results
📊
Deep-Dive Audit
Full maturity report · Roadmap
🛡️
Governance Build
Policy · Risk register · Operating model
🏛️
ISO 42001 Track
Gap close · Evidence pack · Cert
🤝
Ongoing Advisory
Fractional retainer · Continuous

Is The AI Audit Suite Right For You?

Audits produce the most value when the organisation is genuinely ready to act on what they find. Here's an honest read on fit.

✓ Great Fit If You Are…

  • Deploying AI but uncertain about your governance posture or risk exposure
  • Considering ISO 42001 certification and want to know how far away you are
  • Responding to a board, regulator, or customer question about your AI governance
  • About to select or renew a significant AI vendor contract
  • Preparing an RFP response that includes AI governance attestations
  • A new CAIO, Compliance Officer, or Operations lead who needs a baseline before acting
  • Operating in or selling into the EU, GCC, or India — markets where AI scrutiny is increasing
  • Ready to act on findings — not just collect a report and file it

✕ Probably Not A Fit If You Are…

  • Not yet deploying any AI tools or systems — nothing to audit yet
  • Looking for a generic audit template to complete internally without an independent auditor
  • Expecting the audit to produce a positive score regardless of actual maturity
  • Not prepared to share existing policies, system inventories, or governance artefacts
  • Treating the audit as a one-time exercise with no intention of acting on findings
  • A large enterprise with an in-house ISO 42001 team that conducts its own internal audits
  • Looking for the cheapest available template assessment — we compete on rigour, not price

Things Buyers Ask Before Commissioning

How is this different from the free online assessment?
The free online AI Assessment is a 10-question self-diagnostic that gives you an indicative maturity score and automated recommendations — useful for a quick orientation and a starting point for conversation. The Deep-Dive Report is an independently conducted, expert-reviewed audit: 30-minute intake call, evidence review, seven-dimension scoring, ISO 42001 clause-level gap map, benchmarked scorecard, and a board-presentable report with a 12-month roadmap. The gap in rigour, specificity, and defensibility is substantial. The free assessment tells you roughly where you are. The Deep-Dive tells you precisely, with evidence.
How much leadership time does the Deep-Dive require?
Deliberately minimal. The intake call is 30 minutes. Evidence submission is asynchronous — you share documents via a secure workspace on your own schedule. One optional 30-minute follow-up Q&A slot may be needed if clarifications arise during analysis. The findings presentation is 45 minutes. Total leadership time: approximately 90 minutes across two to three weeks. We've designed it this way because leadership time is the scarcest resource in any organisation — the audit should consume as little of it as possible while producing maximum clarity.
Is the report confidential? Can it be used against us in a regulatory process?
The report is fully confidential. Mutual NDAs are signed before the intake call. The report is produced for internal decision-making — it is your document, not ours. We don't retain copies beyond the agreed record-keeping period. In most jurisdictions, an internally commissioned maturity assessment does not constitute an admission of non-compliance — but we recommend you discuss this with your legal counsel if you have specific regulatory concerns before commissioning. We can also scope the assessment to focus on specific areas and exclude others if particular sensitivity exists.
What's the difference between the ISO 42001 Readiness Check and the Deep-Dive Report?
The Deep-Dive Report is a broad maturity assessment across seven dimensions — designed to give a comprehensive picture of your AI governance posture and identify the most impactful improvements. The ISO 42001 Readiness Check is specifically focused on certification preparation — it goes clause by clause through ISO 42001 Clauses 4–10 and all 39 Annex A controls, producing a nonconformity log and a remediation plan mapped to certification requirements. If you're not on a certification track, the Deep-Dive is the right product. If you're actively pursuing ISO 42001 certification, the Readiness Check is more precise and actionable for that specific goal.
Can we commission an audit for a specific business unit rather than the whole organisation?
Yes — and it's often the right approach when AI deployment is concentrated in one function (e.g., a data science team, a BPO operation, or a specific product line). We scope the assessment to the unit's boundaries during the intake call, which typically makes the audit faster and more targeted. The report will note that scope is limited to the assessed unit and flag any organisational-level dependencies that would affect the findings — so leadership has the full picture of what was and wasn't assessed.
Do you provide a re-assessment after we implement the recommendations?
Yes — and we recommend it. A re-assessment typically takes 30–40% less time than the initial audit because the baseline is established and we're measuring delta rather than starting from scratch. Most clients do a re-assessment 6–12 months after initial findings, once the priority gaps have been addressed. This produces a before/after scorecard that's useful for board reporting, regulatory submissions, and RFP responses — demonstrating not just current posture but the trajectory of improvement. Re-assessment pricing is discounted for existing audit clients.
Can this audit support our tender / RFP response that asks about AI governance?
Yes — and this is one of the most common use cases, particularly in the GCC where large government and semi-government entities are increasingly including AI governance attestation requirements in RFPs. The Deep-Dive Report includes an executive summary section written specifically for this purpose — describing your AI governance posture, the standard it aligns to, the assessment methodology, and the auditor's credentials. It does not misrepresent your maturity level; it accurately characterises it with the ISO 42001 Lead Auditor's professional sign-off. That's what procurement teams and legal reviewers are actually looking for.

Start Free. Go Deep When You're Ready.

Take the free 10-minute online assessment for an immediate maturity indication — or book a discovery call to discuss which paid audit product matches your most urgent need. Both options are obligation-free.