AI inventory, including shadow AI
Every AI system in use, discovered through expenditure records, browser and network telemetry where available, supplier contracts and team interviews. Each entry gets an owner, a purpose and a data classification.
Almost every organisation we audit finds AI it did not know about: a team paying for a tool on a card, a supplier quietly adding a model to a product you already bought, a spreadsheet macro calling an API. The audit establishes the truth, then ranks what to do about it.
The gap between what an organisation believes it uses and what it actually uses is usually the whole finding.
The audit is evidence-first: we look at systems, contracts, logs and expenditure, and use interviews to explain what we find, not to establish it.
Every AI system in use, discovered through expenditure records, browser and network telemetry where available, supplier contracts and team interviews. Each entry gets an owner, a purpose and a data classification.
What AI actually costs you across licences, credits and bundled features - and where three teams are paying for the same capability. This part frequently pays for the audit.
What data leaves your boundary, to whom, under which terms, and whether it can be used for model training. Mapped so a DPO can act on it.
Your position against the obligations that apply to you: the EU AI Act where you serve EU users, ISO/IEC 42001, ICO guidance on AI and data protection, and your own sector regulator's expectations.
A living register of models, prompts, use cases and risk classification - the artefact most assurance conversations now begin with.
Which deployments are earning their keep, which are unused seats, and which workflows are still waiting for the tool they were promised.
The engagement runs with the people who do the work, not around them. Sessions are short, scheduled around delivery, and every stage ends with something you can act on.
You get a named consultant for the whole engagement - the person in the room is the person doing the work.
We agree scope, confidentiality and the data sources we can read. Most of the evidence already exists in finance, IT and procurement systems.
Expenditure analysis, contract review, systems and telemetry review, and interviews with the teams doing the work.
Each finding is tested against a named control and given a severity, an owner and an effort estimate. Nothing is raised without evidence attached.
A written report plus a session with your leadership team, ending in an agreed remediation plan with dates.
Enterprise customers and public bodies increasingly ask suppliers to evidence their AI governance during procurement. An audit is the fastest route to an answer that survives scrutiny.
The EU AI Act's obligations land on organisations that place AI systems on the EU market or serve EU users, and they are staged - knowing which tier you sit in is the first practical step.
It is also the cheapest way to find money. Duplicate licences, unused seats and an over-specified model choice are common findings, and they are recoverable in the same quarter.
Two to four weeks from kick-off to a report your board, your regulator and your customers can all read.