Assess

Bounded review

AI Governance Diagnostic: find out what is actually running

Five to seven business days to establish what AI is actually in use in your company, what data reaches it, and which uses carry enough consequence to need controls. It ends with a ranked list of gaps, each with an owner and a date - not with a policy document nobody asked for.

Published range
$750–1,500 / engagement
Timing after intake
5–7 business days
Quoted in India
₹35,000–75,000 / engagement

Fixed scope, not hourly. Quoted before we start, with the exclusions written down. The India figure is a separate price for a separate market, not a conversion.

Bounded review

How this is actually delivered

One defined thing examined properly - a vendor, a feature, a questionnaire - with findings, decisions and the evidence behind them. It does not cover the rest of the business.

The scope is fixed before the work starts, which is why the price is a published range rather than an hourly estimate. Anything outside it is quoted separately rather than absorbed quietly or billed by surprise.

Why companies buy this
Most companies cannot answer the first question a buyer asks - which AI is in use here, and who decided that - because nobody has ever written it down. Everything else is guesswork until that exists.
What we actually do
Three interviews across leadership, engineering and the teams actually using the tools, plus a survey of accounts, vendors and configurations. We build the register of up to five use cases, map what data reaches which system, classify each use by consequence rather than by a mysterious score, and set out the gaps in priority order with an owner and a date against each.
Where it stops, and who takes over
Whether a specific obligation applies to your company in a given jurisdiction is a legal question. We identify it, scope it and route it to counsel qualified in that market rather than answering it ourselves.
What you can show afterwards
An owner-attested inventory, a prioritised gap list and a roadmap - enough to brief a board, a buyer or the sprint that follows, and honest about what discovery could not reach.

What you receive

A register of the AI actually in use, the gaps that matter, and a ranked roadmap with owners against each line.

One entity and up to five use cases. Additional entities, more use cases, or deep technical assurance such as evaluations and security testing are outside this scope and are quoted separately.

  • An AI tool and use-case register covering up to five use cases, attested by the owner of each
  • A data-flow summary: what goes into which system, where it is processed and what the vendor retains
  • An internal risk classification, explained in reasoning rather than as a numeric score
  • A note on which questions are legal questions, and which jurisdiction each belongs to
  • A prioritised gap list with an owner and a target date against every line
  • A roadmap sized to your situation, saying what to fix now, next quarter and later
  • Explicit discovery limitations - what we could not see, and what that means for the register

What it costs, and what it replaces

Both figures are published ranges for the same unit of work. Ours is fixed before we start; if our process gets faster, that is our gain and your price does not move.

How engagements are structured →
Per engagement · against every fixed-scope engagement
$750AI Governance Diagnostic: $750–1,500$12,000

Published range for this engagement, against the span of the whole card. In India the same scope is quoted at ₹35,000–75,000 — a separate price for a separate market, not a conversion. Where in the range a quote lands is set by scope, entities and how much usable evidence already exists.

Midpoint $1,125 per engagement

How the work runs

  1. 01

    Scope and conflicts

    We confirm the entity, the sponsor, the countries involved and the data categories in play, and run a conflicts check before receiving anything sensitive. Scope, exclusions and the legal boundary are written down before work starts.

  2. 02

    Secure intake

    Existing policies, contract clauses, vendor terms and any incident history come into a controlled workspace with least-privilege access and a documented deletion schedule. Redacted examples are preferred over raw customer records.

  3. 03

    Interviews and survey

    Three structured interviews, plus a survey of accounts, subscriptions and configurations. Self-reporting is one input and we treat it as one input - it does not by itself prove the inventory is complete.

  4. 04

    Classification

    For each use case we record purpose, affected people, inputs, outputs, autonomy, geography, consequence of failure, existing controls and residual risk. Internal risk is classified separately from any statutory classification, which is a legal question.

  5. 05

    Gaps and roadmap

    Findings are ranked by consequence and by how quickly they can be closed, each with a named owner and a date. We present them to the sponsor and record what is accepted, deferred or disputed.

What we need from you

  • Access to three people: usually leadership, engineering or IT, and whoever handles delivery or support
  • A list of the AI tools and accounts you know about, including anything on a personal subscription
  • Any existing policies, acceptable-use rules or staff guidance, even if outdated or ignored
  • Customer contract clauses that touch confidentiality, data use or subprocessors
  • Vendor terms for your main AI tools, or permission to retrieve the published versions

What we check before delivery

  • Every factual statement about your systems is confirmed by the owner of that system before it enters the register
  • Legal assertions are linked to dated primary sources, or flagged as questions for counsel rather than answered
  • Discovery limitations are written into the deliverable instead of being left for the reader to infer
  • A second reviewer checks any material conclusion before handover

When firms send us this

  • A customer questionnaire arrived and nobody could answer the first three questions
  • A board or investor asked who owns AI risk in the company
  • You are about to commission a larger governance programme and want it scoped against facts
  • An acquisition or a new market made the existing informal arrangement untenable

Questions about ai governance diagnostic

  • Is this just a questionnaire you send us?

    No. The interviews are the point. A self-assessment form records what people believe is happening; the gap between that and what the account settings and vendor terms actually show is usually where the real findings are.

  • Will you tell us whether we are compliant?

    No, and nobody honestly can in five days. We tell you what you are running, which uses carry consequence, where your controls do not match your commitments, and which questions need a qualified lawyer in a named jurisdiction to answer.

  • Does this lead to a bigger engagement?

    Often, but it is bought and priced as a complete piece of work. Plenty of companies take the roadmap and implement it themselves, and that is a perfectly good outcome.

This engagement

Scope it in fifteen minutes.

AI Governance Diagnostic at $750–1,500 per engagement, delivered in 5–7 business days after a complete intake. Scoping costs nothing, and we will say if a smaller engagement would serve you better.

Schedule a Call