A specialist service from CyPro

AI governance consulting for UK businesses, at fixed published prices

Your business already uses AI, with or without permission. We put the governance around it and test the systems themselves: ISO 42001 readiness, policies, risk assessments and AI penetration testing, all from one UK team.

  • Every price published in full
  • ISO 42001, NIST AI RMF, EU AI Act
  • Governance and testing, one team
  • Named UK consultants on every report
3D illustration of a governed, secured AI technology estate

Trusted by

az
bgi
british gas
cigna
deloitte
euroclear
jpm
kpmg
lme
m & g
ns & i
royal london
rsa
schroders
shell
ubs
virgin trains
william hill

The services

AI governance services, from policy to penetration test

Two service lines, one practice: governance that makes your AI use defensible, and testing that proves whether your AI systems can be broken.

What does AI governance consulting include?

AI governance consulting puts working controls around how your business builds and uses AI: an inventory of your AI systems, a risk assessment of each, policies your staff can follow, a framework that maps to ISO 42001, NIST AI RMF and the EU AI Act, and a roadmap the board can fund. Where the systems themselves need proving, AI penetration testing and red teaming supply the evidence. The same work is variously called AI governance services, AI assurance or responsible AI consulting: the substance is what matters.

Why this practice

AI governance without the mystery

Fixed AI governance prices published in full

Published fixed prices

Nobody else in this market publishes a single figure. Our fees are on the pricing page in full: per organisation for governance, per system for testing.

Practitioners who write policies and test AI systems

Practitioners, not policy theatre

The people who write your AI policy also test AI systems for a living. The governance advice survives contact with how models actually fail.

Deliverables mapped to ISO 42001, NIST AI RMF and the EU AI Act

Mapped to the frameworks that matter

Everything we deliver traces to ISO 42001, NIST AI RMF, the EU AI Act and the UK's AI Cyber Security Code of Practice, so it stands up to scrutiny.

Governance and AI security testing from one partner

Governance and testing, one partner

Assess the paperwork and attack the systems with the same team. Findings from testing feed your risk register; your policies constrain what we test for.

Board-ready AI governance roadmaps and risk registers

Board-ready deliverables

Roadmaps, risk registers and policy packs written for the people who sign them off, with the technical evidence underneath for the people who act on them.

Ongoing AI governance through the AI Responsible Officer retainer

A path to ongoing ownership

When the assessment lands, the AI Responsible Officer retainer keeps governance running month to month, without hiring for a role that barely exists yet.

Your experts hold

  • CIPM
  • CIPP E
  • CISA
  • CISM
  • CISSP
  • CRISC
  • ISO 27001
  • Prince2

Outcomes on record

Clients, in their own words

Common questions about AI governance consulting answered

Good questions

Frequently asked questions

Does the EU AI Act apply to UK companies?

It can, despite the UK sitting outside it. The Act applies extraterritorially: if you place an AI system on the EU market, serve EU customers with one, or the output of your system is used inside the EU, obligations can attach to your UK business. A UK-only firm with UK-only customers is generally out of scope, but the boundary turns on facts worth checking properly rather than assuming.

Our applicability assessment gives you a documented answer for every AI system you run, with the evidence to show customers and regulators.

The EU AI Act and UK companies, in full

Is ISO 42001 worth it for a business our size?

It depends on who is asking you for it. Certification earns its keep when enterprise customers, regulators or procurement frameworks demand evidence of responsible AI management; it is rarely the right first step for a small firm with no such pressure. Many businesses get most of the value from aligning with the standard without certifying: the management system, risk process and policies, minus the certification body.

A gap analysis tells you the distance to either destination before you commit to the journey.

ISO 42001, explained by practitioners

Do we need ISO 42001 certification, or just alignment?

Certification means an accredited certification body audits your AI management system and issues a certificate; alignment means you build and run the same system without the external audit. Choose certification when a contract, tender or regulator will ask for the certificate itself. Choose alignment when you want the discipline and the evidence but nobody is demanding the badge.

We deliver the readiness work for both. Certification itself is always issued by an independent certification body, never by us.

Do we need an AI policy if we only use ChatGPT and Copilot?

Yes, and arguably that is exactly when you need one most. Staff using public AI tools without rules is how client data ends up in training sets, how confidential documents leave the business and how nobody can answer what the board asks after an incident. A short, enforceable policy that says what may be used, for what, with what data, closes most of that exposure in a few pages.

Our policy template covers the ChatGPT-and-Copilot case as the baseline, not the afterthought.

Writing an AI policy that people follow

Rocket launching above the AI Governance UK call to action

Start here

Find out where your AI use actually stands

Take a free 45 minute scoping call about how AI is used across your business, and leave knowing what a governance assessment or a security test involves, what it costs and what comes back. No pressure at any point.