Business line · AI Done Right

    AI Transformation & Governance

    Value created, delivered and captured, with the obligations covered on the way. We don't teach AI. We transfer judgment, then build the systems and the governance that hold it.

    Who this is for

    • Owner and CEO

      Wants AI to show up in the P&L, not in a pilot graveyard.

    • COO

      Needs adoption that survives contact with how the business actually runs.

    • Chief compliance officer

      Has to answer for the EU AI Act and for what staff already use.

    • Business development director

      Is being asked by clients what your AI policy says.

    AI rarely stalls on technology

    Most organisations are past the question of whether to use AI and stuck on the question of what it has changed. Licences are bought. Pilots ran. Somewhere in the business a team is already putting client data into a model nobody has classified. And the board still cannot answer, in one number, what any of it returned.

    That is not a technology failure. Three gaps produce it, and all three are organisational.

    The first is alignment. Ask five executives what AI is for in your company and you get five answers — cost, speed, headcount, differentiation, defence. Capital cannot be committed with confidence against five definitions, so it is committed in fragments. Fragments do not compound.

    The second is capability. The people expected to deliver the change are the same people already running the business at capacity, and most have had no structured exposure to what these systems can and cannot do. Enthusiasm substitutes for literacy, and enthusiasm does not survive the first confident wrong answer in front of a client.

    The third is sequencing. There is no route from awareness to production, so effort disperses towards whichever use case had the loudest sponsor. The ones that would have paid back sit unbuilt, because nobody scored them.

    The EU AI Act phases in, and the timetable moved in July 2026. The prohibitions have applied since February 2025 and the general-purpose model obligations since August 2025, while the Digital Omnibus deferred the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for AI embedded in regulated products. The deferral changes the deadline, not the work: the inventory and the classification that everything else depends on take the same number of weeks whenever you start them.

    We work the three gaps in that order, and we design the governance in from the first sprint rather than reconstructing it the week the auditor arrives.

    What is different when this is done properly

    1. 01Your executive team holds one written definition of what AI is for, with a number attached to it.
    2. 02Every use case is scored before it is built — value, feasibility, regulatory exposure — so the sequence defends itself in a budget meeting.
    3. 03Your AI literacy obligation is evidenced by role-based curricula and attendance records, not by a policy nobody opened.
    4. 04The systems you ship carry their controls, their logs and their human-oversight design from the first sprint, so conformity becomes assembly rather than archaeology.
    5. 05When a client's procurement team sends you an AI questionnaire, you answer it from a document that already exists.
    6. 06Shadow AI stops being a rumour and becomes an inventory.

    Enable

    Transfer the judgment

    People decide whether AI works. Consulting-side adoption work lives here; accredited courses and certification sit in our training line.

    See AI certification and literacy courses

    Governance, adoption and value — in parallel, not in sequence

    Programmes that run governance after adoption end up rebuilding what they shipped. Programmes that run governance before adoption never ship. We run three tracks at once and let them constrain each other.

    Governance

    The AI inventory, the risk classification, the policy, the human-oversight design and the evidence trail. Built to ISO/IEC 42001 and mapped to the EU AI Act so one body of work answers both. Governance here is a constraint on design, not a document produced afterwards.

    Adoption

    Guardrails people can follow, role-based working habits, and measured usage. We publish what good use looks like for each role, then track whether it is happening. Adoption is the only track where the deliverable is a behaviour rather than an artefact.

    Value

    Create, deliver, capture. Every use case is scored before build and measured after. Value that is created but never delivered to a customer, or delivered but never captured commercially, is counted as zero. If the number does not move, we say so in the steering committee.

    Where we have done this

    Our current work concentrates in pharma, FMCG and fintech. The pattern below is what we carry into manufacturing, retail and healthcare, where the same governance problem arrives alongside the convergence of IT and OT.

    Pharmaceuticals

    Validated environments raise the cost of getting AI wrong. The work is separating use cases that touch GxP-relevant records from those that do not, then giving the second group a fast route and the first group a defensible one. Quality and IT usually disagree about which is which; the classification exercise is what ends that argument.

    FMCG and consumer goods

    Demand planning, trade promotion and pricing are where the money is, and they are also where model error is expensive and slow to surface. We score these use cases hard on measurability, because a forecasting model nobody can attribute revenue to will be defunded in the second year.

    Financial services and fintech

    Model risk governance already exists here, which helps. The gap is usually that AI systems sit outside it, and that DORA obligations and AI Act obligations are being answered by two different teams producing two different registers. One register, mapped twice, is cheaper and more defensible.

    Professional practices — legal, accounting, notarial, medical

    Small teams, high confidentiality, low readiness. The realistic first step is not a transformation programme. It is an acceptable-use position, a short list of sanctioned tools, and literacy training that stops the practice from putting privileged material into a consumer chatbot.

    Why us

    • ISO/IEC 42001 Senior Lead Implementer on the delivery team, not on the org chart.
    • Not a Big 4, not a freelancer. Certified practitioners who implement, not consultants who read the regulation.
    • 15+ years across regulated industries in Europe and Africa.
    • Prices published for engagements delivered from our European entity.
    • Anonymised but specific case records across pharma, FMCG and fintech.
    • We work across Claude, OpenAI, Mistral, Kimi, DeepSeek and self-hosted Ollama — model choice is an architecture decision, not a loyalty.

    What it costs

    Published ranges for engagements delivered from our European entity. Work delivered from our African and Middle Eastern entity is quoted on request, because the cost base and the certification economics differ.

    EngagementIndicative priceNotes
    AI value assessment€8,500–19,000 per engagementFixed scope, four to six weeks, ends in a costed plan.
    EU AI Act readiness assessment€8,500–19,000 per engagementRole and risk-tier classification per system, with the obligations that follow.
    ISO 42001 gap analysis€8,500–19,000 per engagementThe distance between today and a certifiable AI management system.
    Implementation of the gaps€25,000–65,000 per engagementScoped from the gap analysis, so the number is evidence-based rather than indicative.
    Fractional Chief AI Officerfrom €2,500 per monthSenior AI leadership on retainer, minimum six months.

    All prices exclude VAT. Ranges reflect scope and estate size; the assessment fee is credited against implementation if you proceed with us within ninety days.

    Certified practitioners, not readers of the regulation

    • ISO/IEC 42001 Senior Lead Implementer
    • ISO/IEC 27001 Lead Implementer and Lead Auditor
    • ISO/IEC 27005 Risk Manager
    • EBIOS Risk Manager
    • ISO/IEC 20000 Lead Implementer
    • Microsoft data and BI certifications
    • PECB Certified Partner and accredited trainer

    Frameworks we work in

    • COBIT
    • TOGAF
    • ITIL
    • Zachman
    • NIST AI RMF

    Questions

    Frequently asked questions

    Does the EU AI Act apply to my company?

    If you build, sell or use an AI system inside the European Union, some part of it applies to you. The obligations depend on your role and on the risk tier of each system. The readiness assessment establishes both, in writing, before you commit budget.

    What is the difference between an assessment and an audit?

    An assessment gives you a roadmap: where you stand and what to do next. An audit gives a conformity opinion against a standard. We run both, and we never present one as the other.

    What does an EU AI Act readiness sprint cost?

    Fixed scope, four to six weeks, €8,500–19,000 per engagement. A Fractional Chief AI Officer retainer is from €2,500 per month.

    Do you train our people, or do the work for us?

    Both, but never as the same engagement. Consulting work is adoption and change management. Courses and certification sit in our training line, with its own catalogue and calendar.

    How do you measure whether AI actually created value?

    Every use case is scored on value, feasibility and regulatory exposure before it is built, and measured against that score afterwards. If the number does not move, we say so.

    What is an AI management system?

    An AI management system is the set of policies, roles, controls and records by which an organisation governs the AI it builds and uses across the whole lifecycle — from use-case approval through data sourcing, testing, deployment, monitoring and retirement. ISO/IEC 42001 is the international standard that specifies one, and it is certifiable by an accredited body in the same way ISO 27001 is. It is not a technical control set; it is the management structure that decides which technical controls apply.

    What is the difference between the EU AI Act and ISO 42001?

    The EU AI Act is law. It classifies AI systems by risk, assigns obligations by your role — provider, deployer, importer, distributor — and carries penalties. ISO/IEC 42001 is a voluntary management-system standard. Conformity with ISO 42001 does not make you compliant with the Act, but it builds most of the structure the Act expects you to have: an inventory, a risk process, oversight roles and an evidence trail. In practice we run one body of work and map it to both, because doing them separately means paying twice for the same inventory.

    We already use Copilot and ChatGPT without a policy. Where do we start?

    With an inventory, not a policy. A policy written before you know what is actually in use is a document that describes a company you do not have. We start by finding what people already use and for what — usually through a short structured survey and expenditure review rather than surveillance — then classify it, then write the acceptable-use position around the reality. That sequence takes weeks rather than months and it survives contact with staff, because it does not ban something they depend on without offering a sanctioned alternative.

    Which AI models do you work with?

    Claude, OpenAI's models, Mistral, Kimi, DeepSeek, and self-hosted open-weight models via Ollama. Model choice is an architecture decision driven by where the data may reside, what latency the use case tolerates and what the workload costs at volume. We are not resellers of any of them, and we will design for a model we do not otherwise favour if the constraints point there.

    Related insights

    Leave with your top three risks documented

    Thirty minutes with a senior practitioner. No slideware, no sales engineer.