EU AI Act / governance / independent audit
The EU AI Act applies to the AI you already run.
Not to a future project. To the models in production, the vendor tools your teams bought, and the automations nobody registered. We audit those systems against the Act, on compliance and on risk, and issue a formal opinion you can put in front of a board, a client or a supervisory authority.
Exposure
Two questions decide your obligations. Most organisations answer the first one wrong.
The Act binds you according to the role you play and the risk tier your system falls in. Buying an AI tool does not make you a simple deployer: put your name on it, or fine-tune it on your own data, and you may have become a provider, with the full documentation and conformity burden that carries.
Banned outright, with no compliance route and no grandfathering. This is the heaviest penalty tier in the Act, at up to 7% of worldwide annual turnover.
Includes social scoring, untargeted facial scraping, and emotion inference in the workplace, which catches more HR and productivity tooling than most buyers realise.
Risk management system, data governance, technical documentation, event logging, human oversight, accuracy and robustness targets, and conformity assessment before the system goes to market.
Recruitment and worker management, creditworthiness, education, essential public and private services, insurance pricing, law enforcement, and AI embedded in regulated products.
Disclosure duties that attach to the deployer, not only to whoever built the system. People must know when they are dealing with a machine, and synthetic content must be marked as such.
Customer-facing assistants, emotion recognition, biometric categorisation, generated text, image, audio and video.
No system-specific obligation, but two things still apply: AI literacy for the staff who deploy or oversee the system, and your own ability to prove the classification was made deliberately.
The tier most organisations assume they are in. It is also the one they are least able to evidence.
General-purpose models sit on a separate track, with obligations that pass to anyone who substantially modifies them. The classification is not a formality: it fixes every duty that follows, and it is the first thing an auditor, a client or a regulator will ask you to justify.
What we do
An independent opinion, not a deck of recommendations.
Lead engagement
Independent AI system audit
We audit one AI system end to end, on compliance and on risk: classification, bias, robustness, explainability, human oversight and data governance. You receive a formal opinion in the manner of a financial audit, the evidence base behind it, and a remediation plan ordered by exposure rather than by ease.
- Duration
- 2 to 6 weeks
- Access required
- None to model weights
- Frameworks
- AI Act, ISO 42001, NIST AI RMF
- Output
- Formal opinion and roadmap
AI system inventory
A single register of every AI system in the organisation, including shadow AI and vendor-supplied models, with owner, purpose and risk tier. Nothing downstream works without it.
AI Act remediation
Execution of the post-audit plan: classification, technical documentation, provider and deployer duties, control design, through to a position you can defend.
Governance framework
The standing apparatus: committee, policies, RACI, decision and escalation paths, and reporting that lets a board see what it is accountable for.
Custom control framework
One control set mapped across your obligations at once, so the AI Act, ISO 42001, NIST and sector rules are answered by a single body of evidence rather than four parallel programmes.
Governance platform selection
Requirements matrix, RFP, comparative proof of concept and a TCO case, so the decision rests on tested evidence rather than on a demo.
Embedded expertise
Vetted AI governance practitioners placed inside your teams, under your direction, when the constraint is capacity rather than method.
For providers established outside the EU
Reaching the EU market without being established in it.
A provider established outside the Union cannot deal with EU authorities directly. The Act requires it to appoint a representative inside the Union first, and the obligation sits on the provider, not on its distributors or its customers.
Standing mandate
EU authorised representative
We take the mandate. We hold the technical documentation and the declaration of conformity for the duration, act as the named point of contact for market surveillance and national competent authorities, cooperate with them on request, and keep the mandate registered and current so your product is not stopped at the border of the single market.
A mandate is not a mailbox. The representative carries duties of its own and is required to end the mandate where it considers the provider to be acting against its obligations. We therefore check the file before signing, and tell you what is missing then rather than when an authority asks.
- Who it binds
- Providers outside the EU
- Legal basis
- Articles 22 and 54
- Covers
- High-risk systems, GPAI models
- Form
- Written mandate, held annually
Method
Six cycles, run in order, on every system.
The sequence is fixed because each step depends on the one before it. Assessment before classification produces findings nobody can act on. Remediation before assessment fixes whatever happened to be easiest to see.
- 01Discovery
What exists, who owns it, what it decides, and what it touches.
- 02Classification
Role under the Act, risk tier, and which regimes apply beyond it.
- 03Assessment
Evidence gathered against the controls, tested rather than asserted.
- 04Remediation
Gaps closed or mitigated, in the order that reduces exposure fastest.
- 05Decision
A named person accepts, mitigates or withdraws. On the record.
- 06Monitoring
Drift, incidents and design change tracked against the position taken.
The full method, including how we score consolidated AI risk
An opinion is only worth what it survives.
We write opinions we can defend
An audit that cannot survive challenge from a supervisory authority, a client’s procurement team or your own internal audit is worth nothing. Every conclusion is traceable to the evidence that produced it, and we say so when the evidence does not support one.
We do not need your model
Our assessment runs black box. That matters when the system is a vendor product, when the provider will not open it, or when the team that built it has moved on. You are not blocked by what you cannot access.
Who we work with
Regulated groups carrying several compliance regimes at once, where a single AI decision has to satisfy the Act, a sector supervisor and an internal risk function simultaneously. The work is done by senior directors with backgrounds in strategy consulting, law and in-house AI compliance at listed groups.
Next step
Start with one system.
Pick the AI system that would be hardest to defend if a supervisory authority, a client or your own internal audit asked tomorrow. We will scope an audit of it and tell you exactly what closing the gap involves.
