Consulting Desk · AI Governance & Assurance
An audit trail that still
answers the question
a year later.
The governance layer a scrutinised organisation needs: model inventory, risk classification, review gates before deployment, and evidence that holds up when someone asks about a decision long after the people involved have moved on.
You hold: a model inventory you can defend, risk classification per system and pre-deployment review gates.
Mapped to your obligations, not to our preference
The framework you are actually judged against is the one that matters.
There is a version of this work that maps your organisation onto whichever framework the consultancy knows best. It produces a tidy gap analysis against something no regulator is going to ask you about. We map to the obligations you are genuinely under — the EU AI Act where it reaches you, ISO 42001 where certification is the goal, NIST AI RMF where that is the house standard, and your sector regulator’s existing expectations, which in UK financial services are already being applied to AI without new rules being written.
The deliverable is not a policy library. It is a working control set: a model inventory that is accurate, a risk classification with a stated basis, review gates that fire before deployment rather than after, and an audit trail designed around the question it will one day have to answer.
That last point is the whole discipline. Most AI governance evidence is assembled to satisfy an internal review this quarter. We design it to answer a specific question — why was this system approved, on what basis, by whom — asked by someone hostile, a year later, when nobody who was in the room is still available.
We claim no certification
Aligning to a framework and being certified against it are different things, and the difference matters legally. We will tell you where you stand, what a certification body would want, and what remains open. We will not imply an outcome we cannot deliver.
How it runs
Inventory, classification, gates, trail.
In that order, because each depends on the one before it. Classifying an inventory you do not have is guesswork with a spreadsheet.
- EngagementProduction Build — 6–12 weeks
- MethodMapped to your obligations
- GateAn audit trail that answers a question a year later
- FrameworksEU AI Act · ISO 42001 · NIST AI RMF · FCA, PRA, ICO, SRA, CQC as applicable
- Platform optionCitadel, where the evidence has to stay live
The inventory, established or corrected
Governance over an inaccurate inventory is theatre. Where the estate is unclear, an estate review or a Sentinel engagement establishes it first.
Risk classification with a stated basis
Tiering against what a system touches and what obligations attach to it — and the basis written down, so the tier can be challenged and defended rather than merely asserted.
Review gates before deployment
What must be evidenced before a system goes live: evaluation results, an accountable owner, a rollback, and a decision recorded with conditions and an expiry where conditional.
The audit trail, designed backwards
Start from the question — why was this approved and by whom — and design the record that answers it. Coverage reported as what is not implemented, never as a reassuring percentage.
The evidence pack
Obligations mapped onto individual systems, evidence held behind each, expiry tracked. Assembled so a per-system compliance position can be produced on demand rather than reconstructed.
The two lists that matter
What you hold, and what we will not do.
Both are in the engagement letter before you sign it. The second list is the one worth reading twice — it is where most disappointment in this market actually comes from.
What you hold at the end
- A model inventory you can defend, with its discovery method stated
- Risk classification per system, with the basis for each tier written down
- Pre-deployment review gates, and what must be evidenced at each
- An audit trail design built around the question it will have to answer
- The evidence pack behind it, with expiry tracked per item
What we won’t do
- Claiming certification or a compliance outcome on your behalf
- Gap analyses against a framework nobody will judge you on
- Coverage reported as a reassuring percentage
- Governance over an inventory nobody has verified
- Policy libraries in place of working controls
Where this becomes continuous
Evidence with an expiry date needs somewhere to live.
A governance layer delivered as documents starts decaying immediately — evidence expires, owners change, systems arrive. Citadel exists because of that: obligations mapped onto systems, evidence held behind each with expiry tracked, an audit log that cannot be edited or deleted, and a ROGS score — Risk and Operational Governance Score — snapshotted daily.
How Citadel holds it →Testing is part of assurance
A control set nobody tested is an assumption. Model evals and red teaming produce the evidence that a system behaves as claimed — and the failures become risk findings with owners and due dates.
Before you commit
Frameworks, evidence, and why we will not claim certification.
Which framework do you work to?
The one you are actually judged against. Obligations are mapped onto individual systems — EU AI Act, ISO 42001, FCA expectations and NIST AI RMF as applicable. We claim no certification for any of them.
Does this get us certified?
No. Certification is awarded by a certification body, not by an adviser. What you hold is evidence assembled against each obligation, with expiry tracked, which is what an assessment needs to see.
How is coverage reported?
As the number of controls not implemented, never as a reassuring percentage. A figure of 94% hides which 6% would fail an inspection, which is the only part anyone needs to know.
Could you answer that question today?
Why was this system approved, on what basis, and by whom. Thirty minutes with a founder — and if your existing evidence already answers it, we will tell you that.
Fixed fee · Quoted in writing before we start · NDA available