Skip to content
All services
AI you can governAssess

AI risk quick scan

In 1–2 weeks, a read-only review of the AI tools, model keys, agents and data flows in your organisation, with the risks ranked and a 30/60/90-day plan to fix them.

When you need it

Your teams already use AI assistants, model APIs and coding agents, some through personal accounts or shared keys. Nobody has a full list of the tools, the keys or the data that leaves the company, and customer security questionnaires now ask about AI.

What sets the quote

  • Sized by the AI tools and use cases in scope, the teams that use them and the classes of data they touch.
  • One week: up to 10 AI tools or use cases, 3 teams and 3 data classes (for example internal, customer and personal data).
  • Two weeks: up to 25 AI tools or use cases, 8 teams and 5 data classes, including agents and MCP servers in your repositories.
  • Larger scopes are quoted after the call.

What changes

  • You know which AI tools, model keys, agents and MCP servers are in use, and who owns each one.
  • You can tell customers which AI providers receive which data, and in which region.
  • Risks are ranked, so the first fixes go where the exposure is highest.
  • Your legal and data protection advisers get the facts they need to prepare for the EU AI Act.

What you get

  • Inventory of AI tools and use cases: assistants, coding agents, model API keys, agents and MCP servers, each with an owner
  • Data flow map showing which data classes reach which AI provider and region
  • Risk register rated against the OWASP Top 10 for LLM Applications, with evidence and a fix for each risk
  • One-page summary of the biggest risks for management
  • Prioritised 30/60/90-day plan with owners
  • All findings as a CSV file for your ticket system
  • A 90-minute readout with your leadership and engineering leads

Start here if you do not yet know where AI is used in your organisation. The scan often leads to governed AI coding agents for engineering teams, or to AI model access and release gates for product teams.

Not included

  • Fixing the findings (quoted separately, often as governed AI coding agents or AI model access and release gates)
  • Legal advice, data protection impact assessments or EU AI Act classification (your legal and data protection advisers own these; the scan gives them the facts)
  • Penetration testing (we can refer you to a certified partner), red-teaming or prompt-injection testing

What we need from you

  • Microsoft 365: the Entra Global Reader role, to see AI licences and app consents. Google Workspace: a custom admin role with read-only privileges.
  • Read-only access to the admin consoles of the AI tools in scope.
  • Read access to the repositories in scope, to find model keys, agent instruction files and MCP server settings.
  • Where model APIs are called from your cloud: AWS SecurityAudit and ViewOnlyAccess, Azure Reader and Security Reader, or Google Cloud Viewer and Security Reviewer.
  • 30-minute interviews with one lead per team, plus your security owner and your data protection lead.

How it works

  1. Free 30-minute call to agree the tools, teams and data classes in scope, then a written fixed quote.

  2. Read-only review of admin consoles, repositories and cloud settings.

  3. Interviews, team by team, to confirm the tools, keys and data flows.

  4. Risk rating, then the report, the plan and a 90-minute readout.

At a glance

Duration
1–2 weeks
Price
Fixed quote after a free 30-minute call
Delivered by
Our lead architect
Build Popular

Governed AI coding agents

Let your engineers use AI coding agents on real repositories, with written working agreements, grounded answers, read-only cloud access and human consent before every production change.

Duration:1–2 weeks
Build

AI model access and release gates

Give your applications one controlled route to AI models with a keyless fallback, keep model calls in EU regions and hold generative features back until evaluation and data-protection sign-off.

Duration:2–3 weeks
Build Popular

AI platform landing zone

A governed place in your cloud for AI agents and AI-enabled apps, built as code in four to six weeks: inherited guardrails, approved models and regions only, and a keyless identity for every agent.

Duration:4–6 weeks

Not sure where to start?

Book a free 30-minute call. We learn what you need and tell you honestly whether and how we can help. There is no obligation.