NEW The 2026 State of AI Trust Report is now available. Read the report →

AI Risk Management

Measure AI risk in the terms your risk committee already uses

Likelihood, impact, exposure, tolerance, and control effectiveness. AI risk becomes governable at the point it stops being described as a separate language.

What this covers

Four risk capabilities

Enterprise & operational AI risk Portfolio-level identification, measurement, and treatment of AI risk, integrated with existing enterprise risk reporting.
Third-party & vendor assessments Independent assessment of the AI inside your suppliers — including the AI they did not tell you about.
AI due diligence Pre-transaction examination of an AI-dependent business: whether the capability is real, defensible, lawful, and transferable.
Incident investigations Independent post-incident analysis establishing what failed, why, what it affected, and what would prevent recurrence.
Two colleagues reviewing findings on a tablet in an office.

Third-party risk

Most of your AI exposure sits inside someone else’s product

Organisations that have never trained a model still carry AI risk, because the AI arrived embedded in a purchased platform. Vendor questionnaires rarely surface it: the supplier answers about their own controls, not about the sub-processor whose model actually makes the decision.

  • Embedded AI discovery
  • Sub-processor and model provenance
  • Contractual assurance rights
  • Vendor evidence review
  • Concentration risk analysis
  • Exit and fallback viability
See our AI risk models

Method

Risk categories we assess

Performance
Accuracy, calibration, and degradation under distribution shift, measured against the operating conditions the system actually meets.
Security
Adversarial manipulation, data exfiltration, supply chain compromise, and the consequences of agentic action.
Compliance
Obligations under the EU AI Act, sectoral regulation, and data protection law, including obligations that attach to deployers rather than providers.
Operational
Availability, cost volatility, vendor dependence, key-person concentration, and the absence of a workable manual fallback.
Societal
Disparate impact, contestability, and the availability of meaningful redress for the people a decision affects.
Strategic
Reputational exposure, litigation posture, and the risk of building a business process on a capability that may be withdrawn or repriced.

Deploy AI with confidence.

Start with an independent assessment of your highest-stakes AI system.