Governing and securing AI, including where it reaches into operations.
AI is arriving in industrial environments through anomaly detection, predictive maintenance and autonomous control — where a wrong inference has physical consequences. We work on AI governance to ISO/IEC 42001, AI risk management, and the specific problem of trusting AI inside an operational technology estate.
- ISO/IEC 42001
- AI management system
- ISO/IEC 23894
- AI risk management
- EU AI Act
- Conformity obligations
Standards in scope
ISO/IEC 42001
Artificial intelligence management system (AIMS)
ISO/IEC 23894
AI risk management guidance
EU AI Act
Regulatory classification and conformity
NIST AI RMF
AI Risk Management Framework
The frameworks AI governance is now measured against.
AI assurance has moved quickly from principle to obligation. ISO/IEC 42001 is the certifiable management system; ISO/IEC 23894 and the NIST AI RMF give you the risk method; the EU AI Act sets the legal floor for anything placed on the European market.
Artificial intelligence management system (AIMS)
The certifiable management system for organisations developing or using AI: governance, roles, impact assessment, lifecycle controls and continual improvement.
How we support you
- AIMS scoping and gap assessment
- AI policy, roles and governance structure
- AI system inventory and classification
- AI impact assessment process
- Control implementation across the AI lifecycle
- Internal audit and certification readiness
AI risk management guidance
How to identify, analyse and treat AI-specific risk — data quality, bias, drift, explainability, robustness and the consequences of incorrect output.
How we support you
- AI risk methodology tailored to your use cases
- Model risk register and treatment plan
- Data quality and provenance assessment
- Drift, robustness and failure-mode analysis
- Human oversight and escalation design
- Integration with enterprise risk reporting
Regulatory classification and conformity
Determining whether a system is in scope, which risk tier it falls into, and what technical documentation, transparency and oversight obligations follow.
How we support you
- Applicability and risk-tier classification
- Obligation mapping for your role in the chain
- Technical documentation structure
- Transparency and human oversight measures
- Post-market monitoring approach
- Conformity assessment readiness
AI Risk Management Framework
A practical structure — govern, map, measure, manage — often the easiest way to start when a full management system is premature.
How we support you
- Framework-aligned maturity assessment
- Use-case mapping and context definition
- Measurement approach and metrics
- Management controls and monitoring
- Roadmap toward ISO/IEC 42001 certification
- Executive briefing and governance setup
Where we focus
What an AI security engagement covers.
The same seven services run across every practice, so you can compare scope without re-learning the menu.
Risk assessment
AI risk assessment across data, model and deployment context — including what happens downstream when the model is wrong.
Advisory & consulting
AI governance design: who approves a model into production, on what evidence, and who is accountable once it is running.
VA-PT & security testing
Adversarial and robustness testing, prompt injection and data poisoning exposure review, and model supply chain assessment.
Compliance & audit readiness
ISO/IEC 42001 readiness and internal audit, plus EU AI Act classification and technical documentation.
Implementation support
Embedding controls into the AI lifecycle — data handling, evaluation gates, monitoring, logging and rollback.
Security operations
Ongoing model monitoring for drift and misuse, with incident handling that treats AI failures as operational events.
Training & capability
AI governance and AI risk training for leadership, engineering and audit functions.
Where AI shows up in our clients' estates
- Anomaly detection on industrial telemetry
- Predictive maintenance and asset health models
- Computer vision for quality and safety
- Advisory and closed-loop control assistance
- Large language model assistants and copilots
- Third-party and embedded vendor AI features
- AI features inside connected products
- Data pipelines feeding model training
What you receive
- AI system inventory with risk classification
- AI impact assessments for in-scope use cases
- AIMS documentation set aligned to ISO/IEC 42001
- Model risk register and treatment plan
- EU AI Act obligation and technical documentation map
- Governance roadmap with decision gates and owners
Putting AI into an operational environment?
Tell us the use case and whether certification or the EU AI Act is in play, and we will set out what governance is actually required.