You can't govern what nobody has counted.
Most companies discover their AI footprint the hard way: a security questionnaire, a customer audit, or an incident. We inventory every AI system in the business, tier it by actual risk, put named controls and running evals behind the ones that need them, and produce the evidence pack that answers the question before it's asked — engineered, not written as a policy document nobody reads.
every AI system inventoried, tiered, controlled and evidenced
- Or 7% of global turnover, EU AI Act ceiling
- €35mOr 7% of global turnover, EU AI Act ceiling
- High-risk obligations landing through this year
- 2026High-risk obligations landing through this year
- Artefacts an auditor accepts, not a policy PDF
- EvidenceArtefacts an auditor accepts, not a policy PDF
- Evals in CI, not a one-off assessment
- RunningEvals in CI, not a one-off assessment
Governance that survives contact with an auditor
The failure mode isn't having no policy. It's having a policy that describes a system nobody built. Everything here produces an artefact tied to something running in production.
AI system inventory
The register nobody has: every model, agent, vendor feature and shadow-IT subscription touching company or customer data, with its purpose, data flows, owner and downstream dependencies. Clients routinely find systems in this step that leadership didn't know existed.
- Discovery across vendors, repos, SaaS features and expensed tools
- Data-flow mapping including third-party sub-processors
- Named accountable owner per system, not a department
Risk tiering & classification
Each system classified against the frameworks that actually apply to you — EU AI Act risk categories, ISO/IEC 42001, the NIST AI RMF, plus sector rules like HIPAA, FCA guidance or SOC 2 commitments. Proportionate, so low-risk tooling doesn't drown in process.
- EU AI Act categorisation with the reasoning recorded
- ISO 42001 and NIST AI RMF control mapping
- Sector overlays for health, finance and employment use
Evals & red-teaming
Assurance you can re-run. We build golden datasets and adversarial suites for each material system, wire them into CI, and set the thresholds that block a release — so 'we tested it' has a date, a commit and a score attached.
- Golden datasets built from your real traffic
- Adversarial, jailbreak and prompt-injection suites
- Release gates with recorded pass thresholds
Bias & fairness testing
For systems touching hiring, credit, pricing, admissions or benefits, we test outcomes across protected groups, document the methodology, and record both the results and what was changed in response.
- Outcome disparity testing with stated methodology
- Documented mitigations and residual-risk decisions
- Re-testing on a schedule, not once at launch
Human oversight design
Meaningful oversight is a workflow, not a checkbox. We design where a human sits, what they actually see, what authority they have to override, and how that intervention gets logged — then verify the reviewer has enough context to disagree.
- Escalation thresholds tied to confidence and impact
- Reviewer interfaces that show the evidence, not just the output
- Override logging with reasons captured
Data protection & privacy
The GDPR work that AI makes newly sharp: lawful basis for training and inference, DPIAs for the systems that need them, retention and deletion that reach into vector stores and logs, and vendor terms that don't quietly claim your data.
- DPIAs and legitimate-interest assessments
- Retention and deletion covering embeddings and traces
- Vendor DPA and training-rights review
Incident response & monitoring
A playbook for the day a model does something it shouldn't: detection, containment, rollback, notification thresholds and post-incident review — rehearsed once before you need it.
- Drift, abuse and output monitoring with alerting
- Kill-switch and rollback paths that have been tested
- Notification decision tree with legal thresholds
Evidence packs & customer assurance
The output your sales team keeps asking for: model cards, risk assessments, eval results, oversight records and sub-processor lists, assembled per system and kept current — so an enterprise security review stops being a three-week fire drill.
- Per-system model cards and technical documentation
- Pre-filled responses for common AI security questionnaires
- Trust-centre content your buyers can self-serve
The artefacts you end up holding
Live AI system register
Every system, owner, risk tier and data flow, maintained as systems are added rather than snapshotted once.
Risk assessments per system
Classification, reasoning, mitigations and residual risk, in the form the relevant framework expects.
Running eval suites
In your CI, with thresholds that block releases and a history you can point an auditor at.
Policy set that matches reality
Acceptable use, procurement, disclosure and oversight policies written against the systems you actually run.
Incident playbook
Detection, containment, rollback and notification, walked through with the people who'd be on the call.
Customer-facing assurance pack
Model cards, questionnaire responses and trust-centre content that shorten enterprise security reviews.
Frameworks and tooling we work to
Regulation
- EU AI Act
- GDPR
- Colorado AI Act
- NYC Local Law 144
Standards
- ISO/IEC 42001
- NIST AI RMF
- SOC 2
- ISO 27001
Evals
- Braintrust
- Langfuse
- Promptfoo
- Custom harnesses
Monitoring
- OpenTelemetry
- LangSmith
- Datadog
- Sentry
Security
- OWASP LLM Top 10
- MITRE ATLAS
- Garak
Sector overlays
- HIPAA
- PCI DSS
- FCA guidance
- FINRA
The first 90 days
Weeks 1–3
Find everything
Discovery across teams, vendors, repos and expenses. The register is built before any judgement is passed on what's in it.
Weeks 4–5
Tier and triage
Classification against the frameworks that bind you, and an honest split between what needs controls now, later, or never.
Weeks 6–9
Build the controls
Evals into CI, oversight workflows into the product, monitoring and alerting live, DPIAs written for the systems that need them.
Weeks 10–12
Evidence & rehearsal
Model cards and assurance packs assembled, and one incident walked through end to end with the people who'd actually respond.
Ongoing
Keep it true
New systems onboarded to the register at build time, evals maintained as behaviour drifts, and regulatory changes tracked so the pack never goes stale.
Governance engagements
Start with the register — it is cheap, fast, and it reliably changes what people think the priorities are. Everything after is scoped from what it finds.
AI Risk Register
$8,500
fixed fee · 3 weeks
Every AI system in the business, found, tiered and ranked by exposure, with a costed remediation plan.
- Full discovery across teams, vendors and repos
- Risk tiering against the frameworks that apply to you
- Gap analysis with regulatory deadlines mapped
- Prioritised remediation plan with effort estimates
- Board-ready summary of exposure
Boards and GCs who need a defensible answer to 'what AI are we running?'
Get startedAssurance Programme
from$16,000
project · 10–14 weeks
Controls, evals, oversight and evidence built for every system the register flagged as material.
- Everything in the Risk Register
- Eval suites and red-teaming wired into CI
- Human oversight workflows implemented
- DPIAs and technical documentation
- Incident playbook and rehearsal
- Customer assurance pack
Companies with high-risk systems, or enterprise buyers asking hard questions.
Get startedGovernance Retainer
from$5,500
per month · 6-month minimum
We keep the register true, the evals honest and the evidence current as you ship and the rules move.
- New systems onboarded and classified at build time
- Eval maintenance and quarterly red-team runs
- Regulatory change monitoring and impact notes
- Security-questionnaire support for sales
- Quarterly review with your GC or risk committee
Teams shipping AI continuously into a regulated or enterprise market.
Get startedPrices are starting points, not quotes. Scope drives the number, and you get a fixed one before you commit.
AI Governance questions, answered
Does the EU AI Act apply to us if we're not in the EU?
Aren't you a technical agency? Why are you doing compliance?
Will this slow our shipping down?
We already have SOC 2. Isn't that enough?
What if the register turns up something bad?
Can you certify us to ISO 42001?
Find out what you're actually running. Before someone asks.
Thirty minutes on where AI has already spread in your business, which parts would matter to a regulator or an enterprise buyer, and what a defensible position looks like from here.
30-minute strategy call
With an engineer, not a closer
Typical reply time: under 4 business hours.
hello@searchsynth.ai