What We Do
Every artificial intelligence system in your business, assessed.
We identify the blind spots that will fail regulatory scrutiny, and we track every change in the law that follows, so the obligation to keep pace sits with us rather than with you.
Discuss your assessmentThe assessment
From inventory to a defensible position.
We turn a complex AI estate into a sequence of decisions your legal, compliance, and technical teams can act on.
What exists, where it runs, and who owns it.
We document each AI system, supplier, data flow, business purpose, deployment context, and accountable owner to establish a reliable scope.
Risk tier, use case, and affected people.
We classify every system by its use, impact, jurisdiction, affected groups, and regulatory risk so attention is directed where exposure is highest.
The rules that attach to each system.
We connect each system to the legal duties, governance standards, controls, documentation, and evidence required for its specific operating context.
Evidence, controls, decisions, and owners.
We record missing controls and evidence, explain the resulting exposure, assign ownership, and distinguish urgent gaps from lower-priority improvements.
A prioritised route to a defensible position.
We turn every confirmed gap into a sequenced action with an owner, priority, dependency, and clear evidence requirement for closing it.
Engagements
Choose the scope your decision requires.
Each engagement sets the question, evidence boundary, outputs and delivery window. Scope expands only when the evidence requires it.
Rapid review
Standard audit
Enterprise programme
Regulatory change watch
Indicative only. Final scope and delivery timing depend on the facts, evidence available and agreed engagement terms.
What this replaces
Less internal drag. More certainty.
The alternative is usually a long trail of partial answers. We make the same work legible, owned, and accountable.
Your internal tools
Weeks of fragmented research, competing priorities, and no single owner for the answer.
Strathwill
One scoped assessment, one evidence-led register, and a clear route to action.
A documented position your team can explain, evidence, and maintain.
Strathwill assessment approach
Frameworks we work across
The obligations that shape your exposure.
We connect legal duties to the systems, controls, and evidence that make them real in your business.
GDPR
ISO 42001
NIST AI RMF
AICPA SOC
Start here
Assessments are scoped in a single call.
Bring the question you need answered. We will scope the assessment around the systems and obligations that matter.
Start a conversation