Our approach
Most consultants hand you a strategy deck and leave. Every stage below ends with something you can use on Monday.
A customer's procurement team sent an AI due-diligence questionnaire. Sales needs it answered this week, and nothing you have in writing answers it.
You're paying for licences. Half the team avoids them rather than get something wrong, and the other half can't tell a good answer from a confident wrong one.
You already know which process is costing you. Slow, repetitive, document-shaped, and still manual because nobody has had the time to fix it.
Discover, then Foundations, then Takeoff, broken into the six stages below. This is the order we recommend, not a queue you have to join at the front. Each stage is a fixed price with a fixed scope tailored to you, listed in full here. Start anywhere, stop after any of them.
Ask a leadership team how many AI tools are in use and you'll get a number like three. The real answer is usually north of twenty, and nobody owns the list.
We go looking for every place AI has got into the business, including the tools nobody put through procurement. You get a map of what’s running, ranked by what’s worth acting on, and a straight recommendation on what to do next.
What you get
Staff who aren't sure what's allowed do one of two things. They freeze, and you get none of the upside. Or they go underground, and you get all of the risk.
This decides what you permit, internally. We write the rules, then run the session that gets your leadership to commit to them. What this does not do is prove any of it to an outsider; that’s stage 04.
What you get
Adoption is where this succeeds or dies. Nobody reads a policy and comes away better at their job.
The point of the whole arc is a workforce that works differently at the end of it. We run days pitched at the level of the room until people know where these tools help, where they go wrong, and how to check. Cultural change is what unlocks value.
What you get
A signed policy has never answered a questionnaire. They don't ask what your rules say. They ask you to show the rules are followed.
This is what you put in front of an outsider, and it’s the stage that unsticks deals. A fixed-fee gap assessment maps your controls against ISO/IEC 42001 and tells you how far off you are. Then we close the gaps and build the evidence trail, quoted against what the assessment found. If a questionnaire is what brought you here, start at this stage and we’ll work backwards.
What you get
Every business has a list of things AI could fix. But a fancy demo that never ships achieves nothing.
By now we know where your money is going. We prototype the most promising process in a few days on simulated data, then build and ship whatever proves worth building, with the before-and-after measured.
What you get
Management systems rot. A year after the audit the register is stale, nobody's run a review, and the next surveillance visit becomes a scramble.
Management systems need an audit cycle and fresh evidence every year, and anything we build needs upkeep. We stay on as a monthly retainer rather than handing over a folder that goes stale.
What you get
Your regulatory classification is a question for a solicitor, and you should want it in writing from one. We build the inventory, risk process, documentation and oversight controls that hold up whichever way the answer goes, and hand you the short list of questions worth paying a lawyer to settle.
Certification is done by an accredited certification body, and no consultancy can both advise and certify. We build the management system and get you ready for that audit.
ISO/IEC 42001, the EU AI Act and UK GDPR/ICO guidance. We leave out NIST's AI RMF because it's US-focused and adds little to a UK engagement. A longer framework list isn't a better one.
Book a call and we'll tell you which of the six stages you need, or take the free twelve-question check first and find your gaps.