← AI compliance services

AI Compliance
Health Check.

Know what AI your organisation is using, where the most important risks sit and what needs to happen next—before committing to a larger governance programme.

Best for first-time assessmentRemote delivery30/90-day roadmap

What this solves.

Many organisations know staff use ChatGPT, Copilot or AI-enabled business systems, but cannot produce a reliable list or explain which uses matter most. The Health Check creates that starting point and separates urgent issues from longer-term improvements.

Outcome: management receives an evidence-based snapshot—not a certificate—and a sequenced plan showing what to stop, investigate, document or improve.

How it is done.

A short, structured engagement designed to minimise disruption while obtaining enough evidence to make useful decisions.

  1. Scope and kickoff

    Agree the legal entity, locations, departments, systems and assessment period covered. Name the client owner and identify available documents.

  2. Discovery workshop

    Interview relevant people from management, IT, HR, marketing, operations, procurement and data protection to find official and informal AI use.

  3. Initial AI inventory

    Record tools, embedded features, vendors, owners, purposes, users, affected people, data categories and approval status.

  4. Risk triage

    Screen for prohibited uses, potential high-risk categories, transparency, AI literacy, personal-data, vendor, transfer and human-oversight concerns.

  5. Evidence review

    Sample current policies, contracts, privacy records, training and controls to distinguish documented practice from assumptions.

  6. Management readout

    Explain the findings in plain English, confirm factual accuracy and agree immediate owners and priorities.

What you receive.

Every output is usable by management and designed to become the starting evidence for further work.

01

Scope statement

A clear record of what was and was not assessed, preventing the result from being mistaken for an organisation-wide certification.

02

Initial AI Systems Register

A structured working list of discovered AI tools and use cases, with owners, purposes, data and status.

03

Risk heatmap

Findings grouped as urgent, important, investigate or good-practice improvement, with the reason for each flag.

04

Gap summary

A plain-English account of missing policies, evidence, training, vendor checks, GDPR records and operational controls.

05

30/90-day action plan

Sequenced actions with suggested owners, priority, target timing and the evidence needed to close each item.

06

Management briefing

A walkthrough of findings, decisions required and recommended next step, with time for questions.

The benefit.

The Health Check replaces uncertainty with a controlled starting point.

Find shadow AI

Surface tools and embedded features management may not know are in use.

Prioritise intelligently

Focus budget and attention on risks affecting people, personal data or important decisions.

Give management clarity

Create a shared, understandable view across technical and non-technical stakeholders.

Avoid buying the wrong project

Know whether the next requirement is policy, data protection, technical control, training or specialist advice.

What we need from you

  • A named engagement owner
  • Access to relevant department representatives
  • Known tool and vendor lists
  • Available policies, contracts and privacy records
  • Honest disclosure of uncertainty and informal use

Not included

  • Legal opinion or regulatory certification
  • A complete organisation-wide GDPR audit
  • Full DPIAs or fundamental-rights assessments
  • Technical penetration testing
  • Implementation of every remediation action

Start with a clear view of where you stand.

Discuss your organisation, current AI use and whether the Health Check is the right starting point.

Discuss a Health Check