EU AI Act / governance / independent audit

The EU AI Act applies to the AI you already run.

Not to a future project. To the models in production, the vendor tools your teams bought, and the automations nobody registered. We audit those systems against the Act, on compliance and on risk, and issue a formal opinion you can put in front of a board, a client or a supervisory authority.

Exposure

Two questions decide your obligations. Most organisations answer the first one wrong.

The Act binds you according to the role you play and the risk tier your system falls in. Buying an AI tool does not make you a simple deployer: put your name on it, or fine-tune it on your own data, and you may have become a provider, with the full documentation and conformity burden that carries.

Unacceptable riskProhibited

Banned outright, with no compliance route and no grandfathering. This is the heaviest penalty tier in the Act, at up to 7% of worldwide annual turnover.

Includes social scoring, untargeted facial scraping, and emotion inference in the workplace, which catches more HR and productivity tooling than most buyers realise.

High riskFull regime

Risk management system, data governance, technical documentation, event logging, human oversight, accuracy and robustness targets, and conformity assessment before the system goes to market.

Recruitment and worker management, creditworthiness, education, essential public and private services, insurance pricing, law enforcement, and AI embedded in regulated products.

Limited riskTransparency

Disclosure duties that attach to the deployer, not only to whoever built the system. People must know when they are dealing with a machine, and synthetic content must be marked as such.

Customer-facing assistants, emotion recognition, biometric categorisation, generated text, image, audio and video.

Minimal riskBaseline

No system-specific obligation, but two things still apply: AI literacy for the staff who deploy or oversee the system, and your own ability to prove the classification was made deliberately.

The tier most organisations assume they are in. It is also the one they are least able to evidence.

General-purpose models sit on a separate track, with obligations that pass to anyone who substantially modifies them. The classification is not a formality: it fixes every duty that follows, and it is the first thing an auditor, a client or a regulator will ask you to justify.

What we do

An independent opinion, not a deck of recommendations.

Lead engagement

Independent AI system audit

We audit one AI system end to end, on compliance and on risk: classification, bias, robustness, explainability, human oversight and data governance. You receive a formal opinion in the manner of a financial audit, the evidence base behind it, and a remediation plan ordered by exposure rather than by ease.

Duration
2 to 6 weeks
Access required
None to model weights
Frameworks
AI Act, ISO 42001, NIST AI RMF
Output
Formal opinion and roadmap

How the audit works

AI system inventory

A single register of every AI system in the organisation, including shadow AI and vendor-supplied models, with owner, purpose and risk tier. Nothing downstream works without it.

AI Act remediation

Execution of the post-audit plan: classification, technical documentation, provider and deployer duties, control design, through to a position you can defend.

Governance framework

The standing apparatus: committee, policies, RACI, decision and escalation paths, and reporting that lets a board see what it is accountable for.

Custom control framework

One control set mapped across your obligations at once, so the AI Act, ISO 42001, NIST and sector rules are answered by a single body of evidence rather than four parallel programmes.

Governance platform selection

Requirements matrix, RFP, comparative proof of concept and a TCO case, so the decision rests on tested evidence rather than on a demo.

Embedded expertise

Vetted AI governance practitioners placed inside your teams, under your direction, when the constraint is capacity rather than method.

For providers established outside the EU

Reaching the EU market without being established in it.

A provider established outside the Union cannot deal with EU authorities directly. The Act requires it to appoint a representative inside the Union first, and the obligation sits on the provider, not on its distributors or its customers.

Standing mandate

EU authorised representative

We take the mandate. We hold the technical documentation and the declaration of conformity for the duration, act as the named point of contact for market surveillance and national competent authorities, cooperate with them on request, and keep the mandate registered and current so your product is not stopped at the border of the single market.

A mandate is not a mailbox. The representative carries duties of its own and is required to end the mandate where it considers the provider to be acting against its obligations. We therefore check the file before signing, and tell you what is missing then rather than when an authority asks.

Who it binds
Providers outside the EU
Legal basis
Articles 22 and 54
Covers
High-risk systems, GPAI models
Form
Written mandate, held annually

What the mandate covers

Method

Six cycles, run in order, on every system.

The sequence is fixed because each step depends on the one before it. Assessment before classification produces findings nobody can act on. Remediation before assessment fixes whatever happened to be easiest to see.

  1. 01Discovery

    What exists, who owns it, what it decides, and what it touches.

  2. 02Classification

    Role under the Act, risk tier, and which regimes apply beyond it.

  3. 03Assessment

    Evidence gathered against the controls, tested rather than asserted.

  4. 04Remediation

    Gaps closed or mitigated, in the order that reduces exposure fastest.

  5. 05Decision

    A named person accepts, mitigates or withdraws. On the record.

  6. 06Monitoring

    Drift, incidents and design change tracked against the position taken.

The full method, including how we score consolidated AI risk

An opinion is only worth what it survives.

We write opinions we can defend

An audit that cannot survive challenge from a supervisory authority, a client’s procurement team or your own internal audit is worth nothing. Every conclusion is traceable to the evidence that produced it, and we say so when the evidence does not support one.

We do not need your model

Our assessment runs black box. That matters when the system is a vendor product, when the provider will not open it, or when the team that built it has moved on. You are not blocked by what you cannot access.

Who we work with

Regulated groups carrying several compliance regimes at once, where a single AI decision has to satisfy the Act, a sector supervisor and an internal risk function simultaneously. The work is done by senior directors with backgrounds in strategy consulting, law and in-house AI compliance at listed groups.

Next step

Start with one system.

Pick the AI system that would be hardest to defend if a supervisory authority, a client or your own internal audit asked tomorrow. We will scope an audit of it and tell you exactly what closing the gap involves.

Scroll to Top