Book the week →
AI Audit & Consultancy

Could you defend your AI to a regulator?

An independent AI Business Audit of where AI creates value and where the risk sits — strategy, maturity, use‑cases, data, governance and ROI — assessed for fairness, transparency, human oversight, safety and readiness, and delivered with a clear remediation plan. EU AI Act readiness, with an opportunity map and a prioritised roadmap.

What the audit answers

An AI just decided who gets the loan, the interview, the payout. These are the questions a regulator asks — and the ones the audit answers before they do.

Where does AI create value here?

Use‑cases mapped against the work you actually do, with the opportunity map that says which ones are worth starting and which are not.

Where does the risk sit?

Strategy, maturity, data, governance and ROI, assessed rather than assumed — including the risks that only appear once a model is in production.

Is it fair, and can you show it?

Fairness, transparency and human oversight examined as evidence a third party could check, not as a statement of intent.

Are you ready for the EU AI Act?

An EU AI Act check across the obligations that apply to your systems, with the gaps named and a remediation plan attached to each one.

What you get

A 5‑day first stage: the TCM Transformation Readiness Assessment and the AI Business Audit, run together.

Human in the loop, audit and EU/local compliance support — the right dose. Led by our senior partners and a hand‑picked global network of specialists: PhD‑level expertise, 25 years across business, industry and academia.

Human in the loop — how we work, and what we help you build

A named human is accountable for every piece of work we deliver. Our d‑Employees draft, check and evidence; a senior partner reviews and signs. That is how the audit itself is produced, and it is why we can put our name on the findings.

It is also what we help you build. Human oversight is not a courtesy in an AI system — under the EU AI Act it is an obligation, and a regulator will ask who was accountable, what they could actually see, and whether they could intervene in time. We assess the oversight you have, name where it is decorative rather than real, and design the dose that fits the risk: enough to be defensible, not so much that the system stops being useful.

The rules that apply where you operate

AI obligations are not the same in every market, and they are moving. We work to the regime that governs the place the system actually runs and the people it actually affects — not to a generic checklist.

European Union

The EU AI Act (Regulation (EU) 2024/1689) is in force and phasing in. We check the obligations that apply to your systems by their risk classification, and name the gaps with a remediation plan attached to each. Alongside it: GDPR where the system touches personal data.

Ireland and national implementation

EU regulation lands through national authorities and sector rules. We identify which regulator is yours and what they will expect to see, and we say plainly where a question needs local legal counsel rather than a consultant.

Other jurisdictions

Where you operate outside the EU — the UK, the US, the Gulf, Asia‑Pacific — the obligations differ in kind, not just in detail. We scope which regimes bear on your systems before the audit starts, so the findings are about your actual exposure.

Standards, as evidence

Regulation says what must be true. Standards are how you show it. We map the frameworks that carry the evidence — ISO/IEC 42001, ISO 27001, ISO 31000, the NIST AI Risk Management Framework — onto the obligations they satisfy.

We audit and we advise. We are not your lawyers, and where a matter turns on legal interpretation we say so and tell you what to take to counsel — that is part of the deliverable, not a gap in it.

The audit runs across all 41 dimensions

We check audit matters across 41 dimensions as well. For example the process dimension: we add audit processes, and check existing processes for audit matters. Brief in that week, but comprehensive in a programme after.

Audit is not a separate exercise bolted onto the side, because the thing that fails an audit is rarely the model. It is a process nobody wrote down, a data owner nobody named, a decision nobody recorded.

What that looks like — the Process dimension, as an example

Two directions at once. We check existing processes for audit matters: whether what already runs would survive being examined, and where the evidence trail breaks. And we add the audit processes that are missing — the checks, records and review points that make the work defensible the next time somebody asks.

The same two questions apply to every other dimension: data, governance, risk, people, technology. What is there, and would it stand up? What is missing, and what has to be built?

Brief in the week. Comprehensive in the programme. Five days is enough to cover all 41 dimensions at depth‑one — to find where the exposure is, score it, and tell you the order to fix it in. It is not enough to do the fixing. The comprehensive work — building the processes, embedding the controls, carrying it through the organisation — is the programme that follows, scoped from what the week actually found rather than from a guess made before it.

Further reading: Could you defend your AI to a regulator? · You don’t have an AI problem · Your AI pilot worked. So why won’t it scale?

One week. Then you know.

€2,500 for the 5‑day Readiness Assessment + AI Business Audit. Remote worldwide; onsite in Ireland for +€1,500. After payment, send us a message and we schedule your dates.

Prefer to talk about a programme, a d‑Employee trial or a referral? Message us.