AI Risk Management
Measure AI risk in the terms your risk committee already uses
Likelihood, impact, exposure, tolerance, and control effectiveness. AI risk becomes governable at the point it stops being described as a separate language.
What this covers
Four risk capabilities
Enterprise & operational AI risk
Portfolio-level identification, measurement, and treatment of AI risk, integrated with existing enterprise risk reporting.
Third-party & vendor assessments
Independent assessment of the AI inside your suppliers — including the AI they did not tell you about.
AI due diligence
Pre-transaction examination of an AI-dependent business: whether the capability is real, defensible, lawful, and transferable.
Incident investigations
Independent post-incident analysis establishing what failed, why, what it affected, and what would prevent recurrence.
Third-party risk
Most of your AI exposure sits inside someone else’s product
Organisations that have never trained a model still carry AI risk, because the AI arrived embedded in a purchased platform. Vendor questionnaires rarely surface it: the supplier answers about their own controls, not about the sub-processor whose model actually makes the decision.
- Embedded AI discovery
- Sub-processor and model provenance
- Contractual assurance rights
- Vendor evidence review
- Concentration risk analysis
- Exit and fallback viability
Method
Risk categories we assess
- Performance
- Accuracy, calibration, and degradation under distribution shift, measured against the operating conditions the system actually meets.
- Security
- Adversarial manipulation, data exfiltration, supply chain compromise, and the consequences of agentic action.
- Compliance
- Obligations under the EU AI Act, sectoral regulation, and data protection law, including obligations that attach to deployers rather than providers.
- Operational
- Availability, cost volatility, vendor dependence, key-person concentration, and the absence of a workable manual fallback.
- Societal
- Disparate impact, contestability, and the availability of meaningful redress for the people a decision affects.
- Strategic
- Reputational exposure, litigation posture, and the risk of building a business process on a capability that may be withdrawn or repriced.
Related capabilities
Deploy AI with confidence.
Start with an independent assessment of your highest-stakes AI system.