- Scoped engagement
- 3–4 weeks
- NIS2
- DORA
- EU AI Act
AI Risk & Readiness Assessment
I look at what your AI systems actually do, rather than what the documentation says they do, score each one against the published OSRA model, and hand you a remediation roadmap in the order I would work it.
Why now
NIS2 is in force, DORA has applied since January 2025, and the EU AI Act obligations are phasing in through 2026 and 2027. All three assume your documentation describes the system you are running. Supervisors have started asking for the evidence, and the gap between the account and the machine is what they find first.
What you get
- A risk register covering every assessed system, scored and comparable
- A prioritized remediation roadmap drawn from the 22-action OSRA catalogue, sequenced by exposure
- A board-ready summary a director can read in fifteen minutes and defend in a meeting
- The assessment workpapers, so your team can repeat the exercise without me
Who this is for
I do this for CISOs, CTOs and boards at mid-market companies and regulated enterprises in Europe, the US, Japan and APAC, who have AI systems in production or about to be, and who will at some point be asked by a board or a regulator what the actual exposure is and would rather have the answer ready.
The problem
Compliance audits the description. It reads the policy, checks the documentation, confirms the register is complete, and signs off on an account of the system. The system itself keeps operating underneath that account: the models in production, the data they touch, the decisions they influence, the agents they grant access to. The two drift apart from the day of deployment.
NIS2, DORA and the EU AI Act all assume the description and the machine match. Across nearly thirty years of security and technology leadership I have rarely found that they do, and the distance between them is where incidents, findings and liability accumulate. Most organizations discover that distance during an incident, a supervisory inspection or a due diligence process. The purpose of this assessment is to discover it deliberately, on your schedule, while it is still a roadmap rather than a finding.
How it runs
The engagement runs three to four weeks at fixed scope.
The first week establishes the inventory: which AI systems exist, what they can reach, who owns them, and what the documentation claims about each. That covers the systems procurement knows about and, usually more interesting, the ones it does not.
In the second and third weeks I run the Operational Substrate Risk Audit on the systems that matter: I go through the operational substrate under each one, score it against the published model, and interview people across the technical, risk and leadership functions to measure how far the governance account and the operational reality have drifted apart.
The last week is synthesis and delivery. I walk leadership through the findings and the priorities in a working session, so the deliverables arrive understood rather than merely received.
The methodology is public
This assessment is not a proprietary black box. The Operational Substrate Risk Audit is published in full: the methodology, the scoring model, the practitioner templates, the remediation catalogue, and a complete worked example showing what a finished assessment looks like. You can evaluate the entire approach before we speak, and your auditors, regulators or board can trace every conclusion back to a documented method.
What you engage me for is the judgment: nearly thirty years of reading the gap between how systems are supposed to behave and how they behave under pressure.
How the fee works
Fixed fee, agreed before the engagement begins, based on the number of systems in scope. No hourly billing and no scope drift. If the inventory week shows the scope was wrong, we adjust the agreement before going further, in either direction.
What it costs
Low five figures
Fixed fee, agreed before the engagement begins, set by the number of systems in scope. No hourly billing and no scope drift.
Worked example
A completed assessment, published in full so you can read the output before you buy one. No email gate.