Most consultancies price a programme and describe it in adjectives. This is the actual work breakdown behind the AI Safety & Assurance Programme — six workstreams, twenty-six tasks, and the consultant-days each one consumes. You can read it before you commit, and hold us to it afterwards.
This schedule is negotiable, and it is meant to be. It is a considered starting position, not a fixed menu. Workstreams get added, trimmed or resequenced on the Governance Readiness Call to match your estate, your deadlines and what you already hold — if your internal audit programme is already running, you are not paying us to build one. The agreed version is what appears in your statement of work, with a fixed fee, before any work begins.
ISO/IEC 42001 Clause 6.1.3 requires you to consider all thirty-eight Annex A controls and justify your exclusions in a Statement of Applicability. It does not require you to assess controls that genuinely do not apply to you. An organisation that deploys AI but builds none legitimately excludes a large part of the life-cycle and third-party controls — so its programme is shorter, and it should cost less.
That is the honest driver behind “from £18,000”. Your role in the AI ecosystem sets your applicable control count, which sets the effort:
| Your role | Applicable controls | Effort | Programme from |
|---|---|---|---|
| Deployer only You use AI systems. You do not build or supply them. | ~26 of 38 | ~19.5 days | £18,000 |
| Deployer, supplier-heavy You use AI systems and depend materially on third-party AI vendors and APIs. | ~32 of 38 | ~21 days | £20,000 |
| Developer or provider You build AI systems, or supply them to others, or both. | 38 of 38 | ~22 days | £22,000 |
Your applicable count is established in workstream 1 and recorded with its justification in your Statement of Applicability — a document you own, that an auditor reads first, and that you can check this pricing against yourself. Multi-jurisdictional footprints are scoped separately; the figures above assume a single legal entity.
Days shown are the deployer-only base case — the £18,000 scope. Elapsed time runs three to six months because two items in workstream 2 are dated evidence: an internal audit and a management review have to have actually happened, and you cannot compress the passage of time.
Establish what is actually true before anything is assessed against it. The estate is routinely two to three times the size the organisation expects.
| WBS | Task | What it involves | Deliverable | Days |
|---|---|---|---|---|
| 1.1 | AI estate discovery | Interviews with heads of function; procurement list reconciled against actual use; shadow AI and vendor-shipped AI features captured | Verified AI system inventory | 1.5 |
| 1.2 | Scope determination | Draw the AIMS boundary; write the inclusion and exclusion rationale; agree the legal entity and locations in scope | AIMS scope statement | 0.5 |
| 1.3 | Readiness baseline | The 42-question readiness instrument run on evidence rather than self-report, to set the starting position both scores are measured from | Scored readiness and governance baseline | 0.5 |
The heart of the programme, and the reason it is priced as one. Every clause and every applicable control, assessed against evidence you produce rather than answers you give.
| WBS | Task | What it involves | Deliverable | Days |
|---|---|---|---|---|
| 2.1 | Evidence request pack | Issue the pre-built document request, chase it, and triage what arrives against what was claimed in the baseline — the gap between the two is itself a finding | Evidence register | 0.5 |
| 2.2 | Clause 4 — Context of the organisation | Internal and external issues, interested parties and their requirements, the AIMS scope, the organisation's role in the AI ecosystem | Clause 4 findings | 0.25 |
| 2.3 | Clause 5 — Leadership | Policy adequacy and approval trail, roles and authorities, whether the named owner can in practice stop a system | Clause 5 findings | 0.25 |
| 2.4 | Clause 6 — Planning | Risk methodology, AI risk assessment and treatment, Statement of Applicability review with exclusion justifications, AI objectives, planning of changes. The clause auditors spend most of their time in | Clause 6 findings · SoA review | 0.75 |
| 2.5 | Clause 7 — Support | Resources, competence, awareness, communication, control of documented information including version control on the policy | Clause 7 findings | 0.25 |
| 2.6 | Clause 8 — Operation | Operational planning and control, risk assessment and treatment in operation, impact assessment actually executed on live systems | Clause 8 findings | 0.5 |
| 2.7 | Clause 9 — Performance evaluation | Monitoring and measurement, the internal audit programme and the management review — the two items that cannot be produced retrospectively and that set your earliest certification date | Clause 9 findings | 0.5 |
| 2.8 | Clause 10 — Improvement | Nonconformity and corrective action, continual improvement. An organisation with no recorded nonconformities is not careful; it is not looking | Clause 10 findings | 0.25 |
| 2.9 | Annex A controls | A.2 Policies related to AI · A.3 Internal organisation · A.4 Resources for AI systems · A.5 Assessing impacts of AI systems · A.6 AI system life cycle · A.7 Data for AI systems · A.8 Information for interested parties · A.9 Use of AI systems · A.10 Third-party and customer relationships | Control-by-control assessment | 0.75 |
| 2.10 | Gap register build | Severity rating per gap, remediation effort and indicative cost, ordered so the cheapest high-impact work comes first | Prioritised gap register | 0.5 |
The component most governance work skips, and the one a regulator asks about first: not what the AI does for you, but what it does to the people it touches.
| WBS | Task | What it involves | Deliverable | Days |
|---|---|---|---|---|
| 3.1 | System classification | EU AI Act risk-tier every system in scope; flag GPAI obligations; identify where output reaches people in the EU | Risk-tiering matrix | 0.75 |
| 3.2 | AI system impact assessments | An ISO/IEC 42005 assessment on every system that makes or materially influences a decision about a person — who is affected, what harm is possible, what mitigates it, what the affected person can do | Completed AIAs · reusable procedure | 1.25 |
| 3.3 | Risk methodology | Define the method, then run the first assessment using it — covering risk to the organisation and risk to individuals, which is the half most registers are missing | Risk method · populated register | 1.0 |
Where the pre-engineered templates earn their place. You are paying for judgement applied to your estate, not for six documents written from a blank page.
| WBS | Task | What it involves | Deliverable | Days |
|---|---|---|---|---|
| 4.1 | AI policy | Template tailored to your estate and sector; approval workflow; an exceptions process that gets used rather than circumvented | Approved AI policy | 1.0 |
| 4.2 | Approval gate | Tiered design so low-risk internal use is fast and anything touching a decision about a person is not; a named owner; tested on a live request before handover | Operating gate · decision log | 1.5 |
| 4.3 | Statement of Applicability | All thirty-eight controls listed, each marked applicable or not, each justified, each applicable one linked to how it is implemented | Signed Statement of Applicability | 0.75 |
| 4.4 | RACI & accountability | Map risk, legal, data protection, procurement and the business; resolve the overlaps; name the single owner of the whole question | RACI · terms of reference | 0.75 |
| 4.5 | Monitoring & audit programme | Internal audit schedule with dates, management review cadence, the measures that get reported — started early so the dated evidence accrues while the documents are finished | Audit programme · review calendar | 1.0 |
Oversight is a duty that cannot be delegated to a consultant. This workstream exists so that it does not have to be.
| WBS | Task | What it involves | Deliverable | Days |
|---|---|---|---|---|
| 5.1 | Board session | Half a day with the board or executive committee: what the EU AI Act and ISO/IEC 42001 oblige directors to do, where liability sits, and the six questions to put to their own executives | Delivered session · board pack | 1.0 |
| 5.2 | First board report | The quarterly report in the shape it will keep, so the second one is comparable with the first. Written for a non-executive, not for engineers | Board report v1 · reporting template | 1.0 |
The first quarter after go-live decides whether a governance system becomes how the organisation works or becomes a folder. This workstream is strictly capped, and the cap is written into your statement of work.
| WBS | Task | What it involves | Deliverable | Days |
|---|---|---|---|---|
| 6.1 | Structured advisory sessions | Up to six sessions, hard cap. Policy exceptions decided, the approval gate defended in anger, the inventory reconciled for the first time | Decision records | 1.5 |
| 6.2 | Steering committee | Bi-weekly attendance across the quarter, with actions tracked to closure between meetings | Minutes & action log | 0.75 |
| 6.3 | Handover | Assessment of who internally could hold this in twelve months and what they would need; transition plan, or conversion to the ongoing retainer | Handover pack | 0.25 |
Beyond the cap, Fractional CAIO Oversight continues as a separate retainer from £3,500 per month. We will tell you when you are approaching the cap, not after you have passed it.
Total, deployer-only base case: 26 tasks across 6 workstreams, 19.5 consultant-days, three to six months elapsed.
Critical path: 1.1 → 2.1 → 2.4 → 4.3. The Statement of Applicability cannot be signed until the gap assessment is complete, and the gap assessment cannot start until the inventory is honest. Workstream 4.5 is deliberately started early, because the dated evidence in 2.7 is what sets your earliest possible certification date.
Days and tasks are the input. This is the output — the things that exist in your organisation on the last day that did not exist on the first.
Evidence you can put in front of a board, a regulator, an insurer or a customer’s procurement team showing what is governed, by whom, and how you would know if it stopped working. The question “is our AI under control?” stops being rhetorical.
Every applicable Annex A control, with what is missing, what it would take to close, and roughly what that costs — ordered so the cheapest high-impact work comes first. A document your own team can execute against without us.
Policy, approval gate, AI system inventory, risk method, impact assessment procedure and Statement of Applicability — in use, not in a folder, with a quarter of dated evidence that they are being used.
Everything a Stage 1 review opens with, ready, including the two dated items nobody can produce at short notice. Certification itself is issued only by a body accredited under ISO/IEC 42006 — this prepares you for that audit; it does not perform it.
Someone inside your organisation who can hold this after we leave, with an honest assessment of what they still need. A governance function that cannot survive its first owner leaving was not built properly.
Directors who know what they are obliged to do, where liability sits, and what to ask their own executives — plus a reporting format that makes the next four quarters comparable.
What the programme does not produce is a claim that your organisation is compliant, certified or safe. Nobody can sell you that. It produces the evidence, the structure and the oversight that let you make your own claim and stand behind it — and an honest account of what is still open on the day we finish.
Most organisations should not start at the programme. Every other rung has its own finished outcome, and each one is a complete piece of work rather than a teaser for the next.
| What you take | From | What you hold at the end |
|---|---|---|
| AI Readiness & Maturity Assessment | Free | A Readiness score and a Governance score across eight dimensions, a maturity band for each, and exactly one recommended next step — emailed the moment you finish, with no call required to receive it. |
| ISO/IEC 42001 Quick Check | Free | A maturity index against the structure of the standard, the status of all eight Stage 1 gates as Met, Partial, Open or Unknown, and a risk exposure figure — on screen the moment you finish. |
| Specialist AI Consultancy Tier 1 · ad-hoc advisory | £950 / day | A written answer to the specific question you brought — a vendor contract reviewed, a board paper argued, a technical position settled — with the reasoning recorded so your team can reuse it. |
| EU AI Act Applicability Assessment Tier 2 · 2–3 days | £2,500 | A formal written determination of your exposure to the EU AI Act and to ISO/IEC 42001, system by system, each risk-tiered — the document that tells you whether the programme is your problem or somebody else’s, and often the answer is narrower than feared. |
| Executive Board AI Governance Training Tier 3 · half a day | £2,400 / session | Directors who can discharge their oversight duties knowingly: what the law obliges, where liability sits, and six questions to put to their executives at the next meeting. Plus the board pack, to circulate to anyone who missed it. |
| Fractional Chief AI Officer Tier 5 · Q2 onwards | £3,500 / month | A named senior owner accountable for the AI estate, a quarterly board report in a repeating format, policy exceptions decided rather than deferred, and an inventory that stays true — audit readiness as a state you remain in, not one you reached once. |
| Full AI & Business Analytics Audit Mid-market entry point | £2,000 | A prioritised roadmap across the whole business using the DBA Business Connectivity Map, plus a live debrief. 100% creditable against this programme if your board later requires formal regulatory alignment. |
Bring this schedule to the Governance Readiness Call and we will cut what you already hold, add what your sector needs, and fix the fee in writing. Or start with a free assessment and find out which workstreams you actually need.
All five rungs, with prices: the enterprise ladder →