Service scope
Assessment areas
Each area is assessed against records, live systems and interviews with the people who build, buy and operate AI - not against the policy document alone.
AI Governance Maturity
Evaluate whether AI decisions are made by an accountable body with real authority, on documented criteria, with recorded outcomes - or whether governance exists only as a policy nobody consults.
AIMS Boundary Review
Test whether the declared AI management system boundary covers the AI the organization develops, provides and consumes, including AI embedded inside procured platforms.
AI Use-Case Inventory Quality
Sample business functions to find AI in use that is missing from the inventory, and assess whether recorded entries carry enough detail - purpose, data, owner, criticality - to be usable for risk decisions.
AI Risk Evidence
Determine whether AI risk assessments exist for material systems, whether they address AI-specific failure modes rather than generic IT risk, and whether resulting decisions were recorded.
AI Impact Assessment Quality
Review completed impact assessments for depth, timing and consequence: were they performed before deployment, did they consider affected individuals and groups, and did they change any decision?
Accountability Effectiveness
Test whether named owners understand and exercise their responsibilities, particularly at the handover between build teams and operational teams where AI accountability commonly lapses.
Third-Party AI Oversight
Assess due diligence, contractual terms, pre-deployment evaluation and ongoing monitoring for procured AI, including how the organization learns about vendor model changes.
Transparency Readiness
Evaluate whether AI use is disclosed where it should be, and whether channels for concerns, contest or human review exist, are reachable and are actually resourced.
Monitoring Evidence
Request post-deployment monitoring records for live AI systems and assess whether performance, drift and incidents are measured against defined thresholds - or not measured at all.
Certification Gap Prioritization
Rank every gap by the barrier it presents to certification and by AI risk exposure, separating what must be fixed first from what can follow.