Kilwhiss AI Assurance

AI Risk and Readiness Sprint

Kilwhiss AI Assurance

Turn AI uncertainty into an owned, prioritised action plan

A fixed-scope, two-week implementation sprint that identifies your AI systems and agents, assesses material risks, assigns accountability and creates the evidence your leadership, customers and assurance partners need.

Two weeksFocused delivery
Up to fiveAI systems or use cases
£4,950 + VATFixed core price
Practical outputsEditable and ready to use

Governance that changes what happens next

Many organisations have AI principles, scattered risk conversations and incomplete tool lists. What they lack is a defensible operating baseline: what AI is in use, where the material risks sit, who can accept them and which actions come first.

The AI Risk and Readiness Sprint applies the UK Department for Science, Innovation and Technology AI Risk Management Toolkit to your live use cases. This is implementation work, not a policy-only review.

Make AI visible

Create one inventory of in-scope systems, agents, providers, data, users, integrations and owners.

Make risk comparable

Use agreed likelihood, impact, appetite and treatment decisions across priority AI risks.

Make ownership explicit

Define accountabilities, decision rights, escalation routes and acceptance authority.

Make progress measurable

Leave with a 30/60/90-day plan, monitoring measures and a scheduled review cadence.

What you receive

1

AI system and agent inventory

A structured record of purpose, lifecycle, owners, suppliers, data, affected people, oversight, integrations, permissions and initial risk tier.

2

Risk-appetite statement

Agreed tolerance, thresholds, escalation triggers and risk-acceptance authority across the principal DSIT risk categories.

3

Governance roles and RACI

Clear responsibility for approvals, inventory, assessment, supplier assurance, monitoring, incidents and retirement.

4

Completed AI risk register

Risk descriptions, existing controls, inherent and residual ratings, treatments, owners, dates and evidence gaps.

5

Prioritised treatment plan

Immediate and 30/60/90-day actions ranked by risk and dependency, with accountable owners.

6

Monitoring dashboard and cadence

Measures, thresholds, evidence sources, review frequency and escalation triggers, including approval status, exception owners, expiry dates and next reviews.

7

Framework crosswalk

High-level mapping to DSIT, ISO/IEC 42001, NIST AI RMF and relevant EU AI Act duties.

8

Executive readout

A concise account of material risks, decisions required, priority actions and recommended next phase.

9

AI deployment approval records

One prepared decision record for each of the up to five scoped use cases, covering evidence, agent permissions, conditions, accountable owners and review dates. Kilwhiss prepares the records; the authorised client owner approves deployment. Decisions remain pending until that approval is recorded.

10

Time-limited exception records

Where a deviation from an internal control is requested, record its scope, compensating controls, authorised owner, expiry and stop triggers. Exceptions cannot waive legal obligations, contract terms or mandatory specialist approval.

How the two weeks work

StageActivityDecision or output
MobiliseConfirm scope, stakeholders, evidence and success criteria.Agreed delivery plan and evidence request.
DiscoverIdentify systems, agents, data, suppliers, users, decisions and integrations.Validated AI inventory.
Set appetiteFacilitate a two-hour workshop on tolerance, escalation and acceptance.Risk-appetite statement and thresholds.
AssessRecord risks, controls, ratings, evidence gaps and treatment decisions.Completed risk register.
GovernDefine RACI, measures, forums and review cadence.Operating governance baseline.
PrioritiseAgree immediate and 30/60/90-day actions.Owned treatment plan and executive readout.

Built on recognised risk and governance frameworks

DSIT AI Risk Management Toolkit

The primary delivery backbone: identify and assess risk, select treatment, monitor and report throughout the AI lifecycle.

ISO/IEC 42001

Outputs are mapped to the main components of an AI management system to make later readiness work easier.

NIST AI RMF

Evidence is connected to Govern, Map, Measure and Manage outcomes.

EU AI Act

We flag likely role, scope and evidence implications for relevant use cases; detailed classification is available separately.

The crosswalk supports readiness and evidence planning. It is not certification, a legal opinion or a guarantee of compliance.

Clear scope. Fixed price.

£4,950 + VAT
Launch offer: £3,950 + VAT for the first three clients

Launch pricing is conditional on permission to use an anonymised case study and is subject to availability and written agreement.

  • Two-week remote engagement
  • Up to five AI systems, agents or use cases
  • One legal entity or business unit
  • Up to six stakeholders
  • One 90-minute discovery session
  • One two-hour risk-appetite workshop
  • Executive readout and editable artefacts

Not included in the core Sprint

  • Certification or a certification guarantee
  • Legal advice or a formal EU AI Act opinion
  • Penetration testing, red teaming or detailed model evaluation
  • A full DPIA, FRIA or algorithmic impact assessment
  • Technical remediation or supplier contract negotiation
  • More than five use cases or complex multi-entity estates

These can be scoped separately where needed.

Separately scoped follow-on

AI Evaluation Readiness Pack

Plan the evidence you need to evaluate one AI application before commissioning technical testing.

Quoted after scoping. Confirm effort, available evidence and any specialist costs before agreeing the statement of work. Existing Sprint and sector prices are unchanged.

A clear delivery boundary

  • One AI application, one intended workflow and one agreed configuration
  • Up to four stakeholder participants and ten prioritised evaluation scenarios
  • Five working days of remote delivery after evidence access and scope are agreed
  • A 60-minute scoping session, a 90-minute design workshop, a readout and one consolidated factual review round

Practical planning deliverables

  • Intended-use and impact profile
  • Evaluation matrix linking scenarios, risks, methods and acceptance criteria
  • Evidence-gap register with accountable owners
  • Test delivery brief defining responsibilities, access and safety limits
  • Reevaluation plan for changes and incidents

Kilwhiss facilitates planning and evidence coordination. The client approves the intended purpose and acceptance thresholds; qualified specialists confirm methods in their domain. Criteria and responsibilities are agreed before test execution.

Requires an AI inventory entry, intended use, available risk register, supplier material and a named decision owner. If these are missing, discovery comes first. The pack can be bought separately when equivalent discovery evidence is supplied.

This is evaluation planning, not evidence that a system has passed. Actual testing, red teaming, statistical bias analysis, clinical validation, full DPIAs, legal opinions, remediation, certification and continuous monitoring are excluded. Technical testing requires a separate authorised scope and statement of work.

Discuss your AI deployment

Options for the next step

OptionPrice + VATPurpose
AI Evaluation Readiness PackQuoted after scopingPlan scenarios, acceptance criteria, evidence and responsibilities. Technical testing is separate.
Additional AI system/use case£450 eachExtend the inventory, assessment and treatment plan.
AI policy pack£1,250Core acceptable-use, governance and lifecycle policies.
Public-sector evidence pack£1,250Procurement- and assurance-oriented evidence packaging.
Detailed ISO/IEC 42001 gap assessment£2,500Deeper management-system readiness assessment.
EU AI Act applicability assessmentFrom £1,250Detailed role, scope, risk classification and duty mapping.
Quarterly reassessment£950Refresh the inventory, risks, actions and dashboard.
Fractional AI governance supportFrom £695/monthOngoing governance coordination and review support.

Frequently asked questions

Is this an audit?

It is a structured risk and readiness implementation engagement. It creates evidence that can support later audit or assurance work, but it is not an independent certification audit.

Do we need an AI policy before starting?

No. Existing policies are useful evidence, but the Sprint can identify the policy and control gaps that should be addressed next.

Can you assess generative AI agents?

Yes. The inventory captures agent permissions, integrations, provider dependencies, human oversight and the business decisions or actions the agent can influence.

What if we have more than five systems?

We can select the five highest-priority systems for the core Sprint or add further use cases at £450 each, subject to complexity.

Does the Sprint make us ISO/IEC 42001 or EU AI Act compliant?

No single sprint can responsibly guarantee that. You receive a defensible baseline, a crosswalk and a prioritised plan for the additional work your context requires.

Reference frameworks

Move from AI experimentation to governed deployment.

Use a free 30-minute scoping call to confirm the five in-scope systems, stakeholders, evidence availability and start date.

Discuss your AI deployment

Evidence that controls are working

For each scoped AI use case, record who can approve, challenge and suspend its use, what its controls are intended to do, and what evidence shows those controls are operating. Gaps become named actions with escalation and review dates.

Approval and exception records capture control-effectiveness evidence reviewed, independent-review findings where relevant, and the escalation recipient and response deadline. We distinguish controls that are documented, implemented and supported by effectiveness evidence.

The framework crosswalk records the source, status, applicability rationale and evidence required for each relevant requirement.

Evaluation and ongoing review

Our Evaluation Readiness Pack defines independent-review requirements where appropriate. Our Quarterly AI Governance Review considers control failures, evidence freshness, independent findings and overdue remediation. Technical testing and independent audit require separate scope.

Clear framework boundaries

We distinguish applicable legal and contractual obligations from standards requirements and voluntary commitments. The U.S. Joint Commitment on Frontier Responsibilities informs our governance approach; it does not create a general compliance obligation for our customers. Framework mapping does not constitute certification or legal assurance.

NIST AI RMF is voluntary guidance; ISO/IEC 42001 is a management-system requirements standard. Legal duties are assessed separately by jurisdiction, organisational role, system use and applicable dates. A supplier signing a voluntary commitment is not evidence that its model or your application is safe.

Measure the value of each AI use

For each scoped use case, the Sprint prepares a compact benefits record: baseline effort or error rate, expected benefit, accountable owner, measurement date and stop-or-scale criteria. The two-week engagement establishes a way to measure results after implementation; immediate financial returns are not promised.

Next steps after the Sprint