TRU-01 / TRUST / LEAD
Trusted AI and Agent Risk Assessment
A clear enterprise risk position, accountable owners and a funded remediation path for material AI and agent use.

Best for
Best when an organisation uses AI or agents without a complete inventory, risk class, authority model or control evidence. Primary buyers: Board, CRO, CISO, DPO, CIO and risk committee.
Business outcome. A clear enterprise risk position, accountable owners and a funded remediation path for material AI and agent use.

What the engagement covers
4-8 weeks. Responsible AI Lead, Enterprise AI Architect, business and data representatives, with security or privacy specialists where required. Fixed fee.
- 01
AI inventory
- 02
use-case and risk classification
- 03
data and privacy review
- 04
model and provider review
- 05
agent authority
- 06
human oversight
- 07
evaluation evidence
- 08
monitoring
- 09
incidents
- 10
lifecycle and governance readiness.

Deliverables and acceptance
Owners are assigned; high-priority gaps are accepted, stopped or funded; authority limits are clear; governance roadmap and reporting path are approved.
- Executive risk report
- AI register
- risk heat map
- control-gap list
- authority matrix
- priority remediation roadmap
- management action plan and board briefing.
Client commitments. System and business owners; model and tool list; policies; contracts; data flows; logs and evaluation records; decision-maker access; DPO, CISO and legal participation as needed.

Find the right entry point for your operating outcome.
Assessment is not a certification or legal opinion. Licensed technical tests are separately contracted through an appropriate entity or partner. Typical next services: TRU-02 to TRU-06 and OPS-06.
