Audit.Assessment.Recommendation.Implementation oversight.
Facts first. Then the judgement on them: risk, gap, maturity. Recommendations only after that. Implementation by your engineers, signed off against the evidence.
Audit
Week 1 · remote, on site in Vietnam when it helps
Where you stand against the law that applies to you, read against your sector, your business goals and your roadmap. A management audit, not a technical one: we read how the company runs its AI, not the code. Perimeter agreed first and written down: entities, systems, the law that applies. Then the inventory of your AI systems and of what makes them run, built from procurement, IT, contracts and expense data, not from memory. Interviews with system owners, business, IT, legal and risk, on video. Evidence collected on a shared drive. No judgement and no recommendations at this stage.
- AI systems register
- Evidence file per system
- Sector, business goals and roadmap on record
- Perimeter written down
Assessment
Week 2
The judgement on what the audit found. Each system classified by risk tier. The evidence weighed against each obligation of the law that applies to you, each finding tied to an article. Maturity placed on two scales, your sector and your firm. This is where the gap is measured, and where a document that exists is told apart from a control that works.
- Assessment report
- Maturity baseline, sector and firm
- Risk map
- Gap register against the law that applies to you
Recommendation
Week 3
What to stop, change, buy or build, in what order, with which controls and which owners. Written from the assessment, defensible in front of a board and a regulator, and built on a recognised standard chosen by sector: ISO/IEC 42001, NIST AI RMF, or the MAS guidelines for financial institutions. Presented to management in one session. Owners and dates agreed in the room.
- Action plan with owners, measures and dates
- Compliance plan, one line per open obligation
- AI policy and governance operating model
- Build, buy or partner decisions and business case
Implementation oversight
Your build calendar
When the audit says build or change, governance, risk and compliance go in with it. We write the controls as requirements, put each system's risks and their treatment in the register, map every obligation to the evidence that will prove it, and review the vendor or the internal team against all three. Your engineers build; we guide that work and sign off only when the evidence exists. We do not build what we recommend. The adviser who also sells the build has no limit, and the client has no second opinion.
- Control requirements and acceptance criteria per system
- Risk register entries and treatment decisions per system
- Obligation-to-evidence mapping, audit trail and logging design
- Vendor and build-team review, go-live readiness sign-off
Terms of the engagement
Typically one week per stage for a mid-size organisation, longer for a large or low-maturity estate. Implementation follows your build calendar. Scope and duration are fixed in writing before we start.
What a remote audit cannot do: observe practice on the floor. The report says what was verified from documents and interviews, and what was not. A legal opinion on local law comes from your counsel; we map the obligations, we do not give legal advice.
If management wants recommendations before the facts are complete, we say so once. If that does not change, we stop the engagement and invoice the work done.
Start with the audit.
One conversation to establish where you stand against the law that applies to you and what it would take to close the gap. No obligation, no pitch.