AI governance advisory, built on operating experience.
Axiom Verity is open for advisory engagements across AI governance, compliance, and security — each grounded in board-reported risk experience and hands-on AI systems architecture, not just frameworks. Get in touch to scope a piece of work.
Five areas, each mapped to direct operating experience.
AI Governance & AIMS Implementation
Build and operate an ISO/IEC 42001 AI management system that can withstand external audit, not just pass a policy review.
- AIMS scope, roles, and accountability structure (Clause 4–5).
- Risk treatment plan and Statement of Applicability (Clause 6, Annex A).
- Evidence artefacts and audit-readiness review ahead of certification.
Grounded in: ISO/IEC 42001 Senior Lead Implementer (GAICC).
EU AI Act & Regulatory Compliance Advisory
Map your AI systems against EU AI Act obligations and UK regulatory expectations, with a clear view of what's active now versus deferred.
- Obligation and risk-tier mapping for existing and planned AI systems.
- Crosswalks between the EU AI Act, ISO/IEC 42001, and UK regulatory expectations.
- A timeline of what applies now, what's deferred, and what to prepare for next.
Grounded in: Practising UK/European regulatory focus across FCA, PRA, and EU AI Act obligations.
AI Security Architecture & Threat Modelling
Threat-model AI and agentic systems with the same rigour applied to critical payment infrastructure.
- OWASP LLM and agentic-AI threat modelling for your specific architecture.
- Control design for prompt injection, output handling, and excessive agency.
- Human-in-the-loop checkpoints for privileged or irreversible actions.
Grounded in: Global Head of Cryptography (HSBC); Director, Information Integrity & Protection (Barclays) — cryptographic infrastructure at ~£1tn/day scale.
Board & Executive Risk Reporting
Independent risk opinions and board papers on AI risk, written for a Board Risk Committee, not a technical audience.
- Independent risk opinions on AI programmes and third-party AI dependencies.
- Board and committee papers framed around risk appetite and tolerance.
- Executive briefings that translate technical AI risk into board-level language.
Grounded in: Director, Technology & Resilience Risk, Royal London — GEC-1 role, reporting to the Group CRO.
Third-Party & Operational Resilience Risk
Extend existing third-party and operational resilience frameworks to cover AI vendors and AI-dependent critical services.
- AI vendor and model risk assessment within existing third-party risk frameworks.
- Mapping AI dependencies into critical/important business services.
- Gap analysis against SS1/21, SS2/21, and SYSC 15A for AI-specific scenarios.
Grounded in: Oversight of critical third-party risk under SS2/21 and operational resilience under SS1/21 and SYSC 15A.
Scope a piece of work.
Every engagement starts with a short conversation about what you're trying to govern, and what evidence you'll need to show for it.