Home
Solutions
For Medium-Sized Business For Small Business & Individuals For Large & Enterprise (AI Governance) About Insights Case Studies Book Discovery Call
The flagship enterprise programme

AI Safety & Assurance Programme

Your board is being asked whether your AI is safe. The honest difficulty is that nobody in the organisation owns that question — it sits across governance, risk, data protection, procurement, and the people quietly using tools nobody approved. This programme puts one accountable structure over all of it.

From £18,000 · typically three to six months · scoped and fixed in writing first

Safety is the outcome. Governance is only the means.

Most organisations buying “AI governance” are buying structure: a policy, a committee, a register. All useful, and none of it is the thing a board is actually being asked about. A board is being asked whether the AI in the business could hurt someone — a customer refused something they should have had, a patient triaged wrongly, an employee screened out, a decision nobody can explain six months later — and whether the organisation would find out if it did.

You can have complete governance and no safety. A policy nobody reads, an approval gate everyone routes around, an inventory last updated in March. The structure exists; the outcome does not follow from it. That gap is what this programme is built to close, and it is why the work does not stop at the documents.

The programme treats safety as the objective and governance as the mechanism, then checks the mechanism actually produced the objective. The full argument is set out here →

Five components, one owner

Each of these is available on its own. Bought separately they are five engagements with five scopes and five sets of findings that have to be reconciled by you. Bought as the programme they are one structure, sequenced, with one person accountable for the result.

Component one · weeks 1–3

Where you actually stand

Both assessments run properly: the AI Readiness and Maturity instrument across eight dimensions, and the ISO/IEC 42001 instrument across Clauses 4 to 10 and all thirty-eight Annex A controls. Not self-reported — the evidence behind each answer is examined.

You end with two scored baselines and a control-by-control gap register. The same instruments are free to self-assess, and doing that first is encouraged.

Component two · weeks 3–6

What could go wrong, and to whom

An impact assessment per AI system against ISO/IEC 42005 and EU AI Act risk-tiering: who the system makes decisions about, what happens when it is wrong, whether anyone would notice, and what the affected person can do about it.

This is the component most governance work skips, and the one a regulator asks about first.

Component three · weeks 5–12

The structure, built

AI policy, approval gate with a named owner, Statement of Applicability, risk methodology, system inventory, impact assessment procedure, and the RACI across risk, legal, data protection, procurement and the business.

Written to be followed, and to survive a Stage 1 documentation review.

Component four · week 10 onward

The board, equipped

A half-day session for the board or executive committee on what they are obliged to do, where liability sits, and the questions to put to their own executives — plus the first quarterly board report, written for them rather than for engineers.

Oversight is a duty that cannot be delegated to a consultant. The session exists so it does not have to be.

Component five · the first quarter after go-live

Someone who owns it while it beds in

The first three months after a governance system goes live are where it either becomes how the organisation works or becomes a folder. Fractional Chief AI Officer oversight is included for that quarter: the policy exceptions get decided, the approval gate gets used in anger for the first time, the inventory gets its first real update, and someone senior is accountable for all three.

After that quarter it continues as a retainer if you want it to, from £3,500 per month, or it hands over to the person you have appointed internally. Both are normal outcomes and the handover is planned either way.

What you hold at the end

A defensible answer

Evidence you can put in front of a board, a regulator, an insurer or a customer’s procurement team, showing what is governed, by whom, and how you would know if it stopped working.

A control-by-control gap register

Against all thirty-eight Annex A controls, with what is missing, what it would take to close, and roughly what that costs — ordered so the cheapest high-impact work comes first.

A working management system

Policy, approval gate, inventory, risk method, impact procedure and Statement of Applicability — in use, not in a folder, with three months of evidence that they are being used.

A certification path, if you want one

Everything a Stage 1 review opens with, ready. Certification itself is issued only by a body accredited under ISO/IEC 42006 — the programme prepares you for that audit; it does not perform it.

What the programme does not produce is a claim that your organisation is compliant, certified or safe. Nobody can sell you that. It produces the evidence, the structure and the oversight that let you make your own claim and stand behind it — and an honest account of what is still open.

Who this is for, and who it is not

Right for you if

  • AI is already in use across more than a handful of systems, and no single person can tell you what all of them are.
  • A board, regulator, insurer or major customer has asked a question you could not fully answer.
  • AI-supported decisions affect individuals — customers, patients, applicants, employees.
  • You want one accountable owner rather than five workstreams you have to reconcile yourself.

Not right for you if

  • You are not using AI in any structured way yet. Start with the free readiness assessment — it will likely tell you this programme is premature, and that will be the right answer.
  • You need one specific thing — just the gap review, just the policy, just the board session. Take that on its own; it will cost less and you will not be paying for structure you do not need.
  • You want a certificate rather than a governed estate. This programme produces the second, which is what makes the first obtainable — but in that order, and not from us.

Delivered personally by Dr. Mahdi Seify

Audit methodology, not opinion

ISO/IEC 27001 Lead Auditor and Lead Implementer. Every finding in this programme is written the way an auditor writes one — the requirement first, the evidence second, the gap third — because that is the form it has to survive in.

A doctorate in the subject

PhD in AI-Driven Business Analytics, University of Liverpool. Senior Lecturer and Programme Leader for an MSc in Business Analytics. The systems being assessed are ones he has built and taught, not only read about.

Governance at real scale

Eighteen years of governance and analytics programmes, including a $200M World Bank multi-ministry programme and technical transformation leadership for a 118-million-subscriber telecom operator.

Stated precisely: Dr. Seify holds working knowledge of, and applies, ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 42005, the NIST AI Risk Management Framework and EU AI Act risk-tiering — built on his ISO/IEC 27001 Lead Auditor methodology. He is not an ISO/IEC 42001 Lead Auditor and is not ISO/IEC 42001 certified; no such accreditation is claimed. Certification against ISO/IEC 42001 is issued only by a certification body accredited under ISO/IEC 42006. VisionXY7 Ltd prepares organisations for certification audits and reviews their systems independently; it does not perform them, and no consultancy can.

Find out whether you need
the whole programme.

Both assessments are free and take under fifteen minutes between them. They will tell you honestly whether this is your next step — and often it is not.

Prefer a single component? All six enterprise options, with prices →