Service ยท Audits

    AI Audits & Readiness Reviews

    An AI audit is an independent review of the AI systems your organisation builds, buys or embeds - classifying each by EU AI Act risk tier, checking documentation, oversight and vendor evidence, and producing a prioritised action plan. Our three audits answer the questions leadership actually asks: Are we compliant? Where can we automate? What could go wrong?

    What's included

    • AI Readiness Audit - inventory of AI systems, risk classification, gap analysis vs the EU AI Act.
    • AI Automation Potential Audit - process mapping, ROI-ranked automation opportunities.
    • AI Risk Analysis - bias, security, IP, data protection and reputational risk assessment.
    • Annex IV documentation review for suspected high-risk systems.
    • Executive-ready report with prioritised action plan and effort estimates.
    • Workshop to walk leadership through the findings.

    Who it's for

    • CIOs & CTOs

      Get an independent view of what AI is already deployed and where the exposure sits.

    • DPOs & Compliance

      Evidence-based gap analysis for supervisors and internal audit.

    • COOs & Ops leaders

      Rank automation ideas by ROI and feasibility, not hype.

    • Boards

      Concise risk picture with clear owners and deadlines.

    Outcomes you can expect

    A full AI system inventory classified by EU AI Act risk tier.

    A prioritised remediation backlog with owners and deadlines.

    A ranked list of automation opportunities with ROI estimates.

    A defensible risk register you can hand to your board or supervisor.

    How we work

    1. 1

      Kick-off

      Scope, stakeholders and access - usually one week to line up.

    2. 2

      Discovery

      Interviews, system walkthroughs and documentation review.

    3. 3

      Analysis

      Classification, gap analysis and risk scoring against the Act.

    4. 4

      Readout

      Written report plus a live session with leadership.

    Frequently asked questions

    How long does an audit take?

    Readiness audits typically run 3โ€“6 weeks depending on the size of the AI estate.

    Do you sign an NDA?

    Yes - mutual NDA is standard before any discovery work starts.

    Can you audit a single high-risk system?

    Yes - we offer targeted Annex IV reviews for individual systems ahead of conformity assessment.

    Do you cover GPAI usage?

    Yes. GPAI deployment risk is a first-class part of every readiness audit.

    Ready to talk?

    Book a 30-minute discovery call and get concrete next steps for your organisation.

    Book a discovery call