Most firms don't have an AI problem.They have an AI pilot problem.
Copilot trials. Chatbots. A spreadsheet quietly wired into something nobody formally approved. This assessment finds what is actually running in your environment, tells you where the risk sits, and gives you a plan, in two to three weeks, not a six-month consulting cycle.
Nothing shows up until something goes wrong
Most organisations cannot answer three basic questions about the AI already in their business. What AI and agents are running right now, sanctioned and shadow? What data do they touch, and where does it go? And if a regulator or auditor asked us to prove any of this is governed, could we?
None of that surfaces until the failed audit, or the agent that had no logging. By then it is not a config tweak, it is an incident. The assessment names that risk before it becomes one.
What AI and agents are running right now, sanctioned and shadow?
What data do they touch, and where does it go?
If an auditor asked us to prove this is governed, could we?
What's Included
Discovery
A full inventory of AI systems and agents across Microsoft 365 and Azure, including unsanctioned shadow AI: Copilot usage, third-party tools on company devices, and citizen-built agents in Copilot Studio.
Risk Classification
Each system mapped against EU AI Act high-risk categories (recruitment, credit scoring, employment decisions and similar) and the obligations specific to your sector.
Data-Flow Mapping
What data reaches which models, where it is stored, and where the gaps are, so the conversation about exposure is based on evidence rather than guesswork.
Posture Snapshot
A current-state view of your governance controls across Microsoft Entra, Purview and Defender for Cloud, scored against a governed baseline.
90-Day Roadmap
A prioritised action plan with owners and effort estimates, not a wish list. Ranked so your team knows exactly what to fix first and why.
Readout
A written report plus a working session with your technical and compliance leads, so the findings land with the people who have to act on them.
Regulated firms where getting AI wrong has real consequences
Heads of Engineering, CTOs and Compliance or Risk leads at mid-market firms, roughly 50-300 users, in financial services, legal, recruitment or professional services.
Best fit: organisations already running AI pilots and starting to ask "why are we suddenly responsible for something we didn't design properly?"
A complete, written inventory of what AI is running
A risk-classified backlog that removes the guesswork
A defensible written compliance position for boards and examiners
A clear, costed next step
Scoped to typical mid-market estates (50-300 users, up to 5 subscriptions). Reduced when bundled with the Governed AI Landing Zone.
Light on your team, by design
Read-only access (Reader, Security Reader and Purview), granted under NDA and time-boxed to the engagement
A list of the AI tools, pilots and agents you already know about
One engineering contact and one compliance or risk contact, roughly 2-3 hours each across the engagement
The timeline runs from access being granted. We share a full pre-kickoff checklist once an engagement is agreed, and we chase access hard in week zero because it is the only thing that ever slips a timeline.