What we do
Trust, assurance, and intelligence across the AI lifecycle
Independent services spanning assurance, security, governance, risk, compliance, certification, intelligence, and research — delivered by teams with no commercial stake in the outcome.
Service lines
Eight disciplines, one institution
Most organisations buy these capabilities from firms that also build, sell, or operate the AI being examined. We do none of those things, which is the point.
How an engagement runs
A defined path from first conversation to signed opinion
Every engagement follows the same sequence, whatever the service line. Scope is agreed in writing before work begins, and the conclusion is never negotiated.
-
Scoping
We establish which systems are in scope, what claims are being made about them, who relies on those claims, and what evidence would be sufficient to support or refute them. Scope is documented and signed before any testing starts.
-
Evidence gathering
Documentation review, technical testing, data and model inspection, control walkthroughs, and interviews with the people who actually operate the system — not only those who designed it.
-
Analysis
Findings are assessed against the applicable framework, quantified where quantification is honest, and ranked by the consequence of the failure rather than the ease of the fix.
-
Reporting
A written report stating what was examined, what was found, what could not be determined, and what our opinion is. Limitations are stated as prominently as conclusions.
-
Remediation and re-test
Where findings are remediated, we re-test the specific claims affected. A remediated finding is only closed once we have evidence, not once we have been told.
-
Continuous assurance
AI systems drift. Ongoing monitoring keeps the opinion current between formal assessments, so assurance does not quietly expire.
Frameworks we work to
Aligned to the standards your regulator, auditor, and board already recognise
We do not invent private criteria and then certify against them. Assessments are anchored to published, externally maintained standards.
- ISO/IEC 42001:2023
- Artificial intelligence management system (AIMS) — the certifiable organisational standard for governing AI.
- ISO/IEC 23894:2023
- Guidance on AI risk management, aligning AI-specific risk to the ISO 31000 process.
- NIST AI RMF 1.0
- The Govern, Map, Measure, Manage functions, plus the Generative AI Profile (NIST AI 600-1).
- EU AI Act
- Regulation (EU) 2024/1689 — the first comprehensive, risk-tiered statutory regime for AI.
- ISO/IEC 27001:2022
- Information security management, still the substrate under any credible AI security claim.
- OECD AI Principles
- The intergovernmental baseline for trustworthy AI, adopted across the OECD and G20.
Independence is the product
Deep Heuristics does not build AI systems, resell AI platforms, or take contingent fees. There is nothing for us to protect except the accuracy of our opinion.
Deploy AI with confidence.
Start with an independent assessment of your highest-stakes AI system.