AI Governance & Risk Advisory — EU AI Act, ISO 42001, NIST AI RMF

Checklist-driven AI safety and risk evaluations for organisations that need to prove — to boards, regulators and enterprise buyers — that their AI is fit to ship.

What we assess

Model risk (evaluation harnesses, benchmark coverage, failure modes). Data governance (lineage, consent, residency, retention). Process controls (change management, incident response, human oversight). Documentation (model cards, ISO 42001 controls, AI Act conformity assessment).

Frameworks we map to

EU AI Act (risk classification, obligations for high-risk systems, transparency). ISO/IEC 42001 (AI management system controls). NIST AI RMF (govern, map, measure, manage). Sector-specific overlays for BFSI and healthcare on request.

Deliverables

Risk register with severity and owner. Gap-closure roadmap with effort estimates. Board-ready assurance memo. Optional: internal training so your team can maintain the posture.

Frequently asked

Do you certify us against ISO 42001?
No — certification comes from an accredited body. We prepare you for it: gap analysis, control implementation, evidence pack, dry-run audit.
How long does a typical review take?
6–10 weeks for a first review of a single AI product; 10–14 weeks for an organisation-wide baseline covering multiple systems.

pw@prima-partners.com · LinkedIn