Skip to content
AI Governance & Assurance

You can't govern what nobody has counted.

Most companies discover their AI footprint the hard way: a security questionnaire, a customer audit, or an incident. We inventory every AI system in the business, tier it by actual risk, put named controls and running evals behind the ones that need them, and produce the evidence pack that answers the question before it's asked — engineered, not written as a policy document nobody reads.

AI SYSTEM INVENTORYEVIDENCE PACKsupport agentcv screeningpricing modelchat assistantcontrolsrisk assessmenteval resultsmodel cardshuman oversight

every AI system inventoried, tiered, controlled and evidenced

Or 7% of global turnover, EU AI Act ceiling
€35mOr 7% of global turnover, EU AI Act ceiling
High-risk obligations landing through this year
2026High-risk obligations landing through this year
Artefacts an auditor accepts, not a policy PDF
EvidenceArtefacts an auditor accepts, not a policy PDF
Evals in CI, not a one-off assessment
RunningEvals in CI, not a one-off assessment

Governance that survives contact with an auditor

The failure mode isn't having no policy. It's having a policy that describes a system nobody built. Everything here produces an artefact tied to something running in production.

AI system inventory

The register nobody has: every model, agent, vendor feature and shadow-IT subscription touching company or customer data, with its purpose, data flows, owner and downstream dependencies. Clients routinely find systems in this step that leadership didn't know existed.

  • Discovery across vendors, repos, SaaS features and expensed tools
  • Data-flow mapping including third-party sub-processors
  • Named accountable owner per system, not a department

Risk tiering & classification

Each system classified against the frameworks that actually apply to you — EU AI Act risk categories, ISO/IEC 42001, the NIST AI RMF, plus sector rules like HIPAA, FCA guidance or SOC 2 commitments. Proportionate, so low-risk tooling doesn't drown in process.

  • EU AI Act categorisation with the reasoning recorded
  • ISO 42001 and NIST AI RMF control mapping
  • Sector overlays for health, finance and employment use

Evals & red-teaming

Assurance you can re-run. We build golden datasets and adversarial suites for each material system, wire them into CI, and set the thresholds that block a release — so 'we tested it' has a date, a commit and a score attached.

  • Golden datasets built from your real traffic
  • Adversarial, jailbreak and prompt-injection suites
  • Release gates with recorded pass thresholds

Bias & fairness testing

For systems touching hiring, credit, pricing, admissions or benefits, we test outcomes across protected groups, document the methodology, and record both the results and what was changed in response.

  • Outcome disparity testing with stated methodology
  • Documented mitigations and residual-risk decisions
  • Re-testing on a schedule, not once at launch

Human oversight design

Meaningful oversight is a workflow, not a checkbox. We design where a human sits, what they actually see, what authority they have to override, and how that intervention gets logged — then verify the reviewer has enough context to disagree.

  • Escalation thresholds tied to confidence and impact
  • Reviewer interfaces that show the evidence, not just the output
  • Override logging with reasons captured

Data protection & privacy

The GDPR work that AI makes newly sharp: lawful basis for training and inference, DPIAs for the systems that need them, retention and deletion that reach into vector stores and logs, and vendor terms that don't quietly claim your data.

  • DPIAs and legitimate-interest assessments
  • Retention and deletion covering embeddings and traces
  • Vendor DPA and training-rights review

Incident response & monitoring

A playbook for the day a model does something it shouldn't: detection, containment, rollback, notification thresholds and post-incident review — rehearsed once before you need it.

  • Drift, abuse and output monitoring with alerting
  • Kill-switch and rollback paths that have been tested
  • Notification decision tree with legal thresholds

Evidence packs & customer assurance

The output your sales team keeps asking for: model cards, risk assessments, eval results, oversight records and sub-processor lists, assembled per system and kept current — so an enterprise security review stops being a three-week fire drill.

  • Per-system model cards and technical documentation
  • Pre-filled responses for common AI security questionnaires
  • Trust-centre content your buyers can self-serve

The artefacts you end up holding

  • Live AI system register

    Every system, owner, risk tier and data flow, maintained as systems are added rather than snapshotted once.

  • Risk assessments per system

    Classification, reasoning, mitigations and residual risk, in the form the relevant framework expects.

  • Running eval suites

    In your CI, with thresholds that block releases and a history you can point an auditor at.

  • Policy set that matches reality

    Acceptable use, procurement, disclosure and oversight policies written against the systems you actually run.

  • Incident playbook

    Detection, containment, rollback and notification, walked through with the people who'd be on the call.

  • Customer-facing assurance pack

    Model cards, questionnaire responses and trust-centre content that shorten enterprise security reviews.

Frameworks and tooling we work to

Regulation

  • EU AI Act
  • GDPR
  • Colorado AI Act
  • NYC Local Law 144

Standards

  • ISO/IEC 42001
  • NIST AI RMF
  • SOC 2
  • ISO 27001

Evals

  • Braintrust
  • Langfuse
  • Promptfoo
  • Custom harnesses

Monitoring

  • OpenTelemetry
  • LangSmith
  • Datadog
  • Sentry

Security

  • OWASP LLM Top 10
  • MITRE ATLAS
  • Garak

Sector overlays

  • HIPAA
  • PCI DSS
  • FCA guidance
  • FINRA
Process

The first 90 days

  1. Weeks 1–3

    Find everything

    Discovery across teams, vendors, repos and expenses. The register is built before any judgement is passed on what's in it.

  2. Weeks 4–5

    Tier and triage

    Classification against the frameworks that bind you, and an honest split between what needs controls now, later, or never.

  3. Weeks 6–9

    Build the controls

    Evals into CI, oversight workflows into the product, monitoring and alerting live, DPIAs written for the systems that need them.

  4. Weeks 10–12

    Evidence & rehearsal

    Model cards and assurance packs assembled, and one incident walked through end to end with the people who'd actually respond.

  5. Ongoing

    Keep it true

    New systems onboarded to the register at build time, evals maintained as behaviour drifts, and regulatory changes tracked so the pack never goes stale.

Governance engagements

Start with the register — it is cheap, fast, and it reliably changes what people think the priorities are. Everything after is scoped from what it finds.

AI Risk Register

$8,500

fixed fee · 3 weeks

Every AI system in the business, found, tiered and ranked by exposure, with a costed remediation plan.

  • Full discovery across teams, vendors and repos
  • Risk tiering against the frameworks that apply to you
  • Gap analysis with regulatory deadlines mapped
  • Prioritised remediation plan with effort estimates
  • Board-ready summary of exposure

Boards and GCs who need a defensible answer to 'what AI are we running?'

Get started
Most chosen

Assurance Programme

from$16,000

project · 10–14 weeks

Controls, evals, oversight and evidence built for every system the register flagged as material.

  • Everything in the Risk Register
  • Eval suites and red-teaming wired into CI
  • Human oversight workflows implemented
  • DPIAs and technical documentation
  • Incident playbook and rehearsal
  • Customer assurance pack

Companies with high-risk systems, or enterprise buyers asking hard questions.

Get started

Governance Retainer

from$5,500

per month · 6-month minimum

We keep the register true, the evals honest and the evidence current as you ship and the rules move.

  • New systems onboarded and classified at build time
  • Eval maintenance and quarterly red-team runs
  • Regulatory change monitoring and impact notes
  • Security-questionnaire support for sales
  • Quarterly review with your GC or risk committee

Teams shipping AI continuously into a regulated or enterprise market.

Get started

Prices are starting points, not quotes. Scope drives the number, and you get a fixed one before you commit.

AI Governance

AI Governance questions, answered

Does the EU AI Act apply to us if we're not in the EU?
Often yes. It reaches providers and deployers whose systems are used in the EU or whose outputs are used there, regardless of where you're incorporated — the same extraterritorial logic as GDPR. The practical trigger is usually simpler than the legal test: an EU customer asks you to evidence compliance in a procurement round. The register tells you where you stand in about three weeks.
Aren't you a technical agency? Why are you doing compliance?
Because the artefacts these frameworks demand are technical ones. Accuracy and robustness testing, logging, human oversight, post-market monitoring — those are engineering deliverables, and law firms rightly won't build them. We work alongside your counsel: they own the legal interpretation, we build and evidence the controls. If you need an opinion on liability, we'll tell you to ask a lawyer.
Will this slow our shipping down?
Proportionately, and less than the alternative. Most systems in a typical register are low-risk and should carry almost no process — the point of tiering is to concentrate effort where it matters. What does take real work is the handful of consequential systems, and those are the ones where an incident would cost you far more than the controls. Teams that wire evals into CI early usually ship faster afterwards, because they stop hand-testing every release.
We already have SOC 2. Isn't that enough?
SOC 2 covers how you handle data and run your security programme. It says nothing about whether a model's outputs are accurate, biased, or appropriately overseen — which is precisely what AI-specific frameworks and enterprise AI questionnaires ask about. They complement each other; ISO 42001 is the closest analogue on the AI side, and it maps cleanly onto a SOC 2 programme you already run.
What if the register turns up something bad?
It usually turns up something surprising, and that's the value. Common finds are a team pasting customer data into a consumer chatbot, a vendor whose terms allow training on your inputs, or an automated decision affecting people with no oversight path. Every one of those is far cheaper to fix in a planned sprint than during an incident, and none of them is unusual.
Can you certify us to ISO 42001?
No — certification comes from an accredited body, and no consultancy can issue it. What we do is build and evidence the management system so the audit is a formality rather than a project: controls implemented, documentation written, evidence collected in the form auditors expect. We'll also tell you honestly whether certification is worth pursuing for your market, because for plenty of companies it isn't.

Find out what you're actually running. Before someone asks.

Thirty minutes on where AI has already spread in your business, which parts would matter to a regulator or an enterprise buyer, and what a defensible position looks like from here.

30-minute strategy call

With an engineer, not a closer

Book a strategy call

Typical reply time: under 4 business hours.

hello@searchsynth.ai