Enigma Partners Global

AI Governance Review

Know exactly where AI exposes you — in weeks, for a fixed fee.

Most organisations are using AI faster than they are governing it. The AI Governance Review tells you — in plain English a board can act on — exactly where you stand against the rules that now apply, and what to do next.

Why now

01

The EU AI Act is live

Transparency obligations land on 2 August 2026, and high-risk rules are close behind. "We didn’t know it applied to us" is not a defence.

02

ISO 42001 is the new bar

Boards, customers and auditors are starting to ask for it. It maps directly onto the EU AI Act — a clean way to get ahead.

03

The exposure is real

97% of AI-related breaches hit organisations with no AI controls in place. Shadow AI adds hundreds of thousands to the cost of one.

What you get

A diagnosis you can act on.

  1. 01

    A clear picture

    Your AI estate mapped — systems, vendors, and the shadow AI nobody logged — scored for risk and regulatory exposure.

  2. 02

    Mapped to the standards

    A gap analysis against the EU AI Act, NIST AI RMF and ISO/IEC 42001 — what applies to you, and where you fall short.

  3. 03

    A plan, not a lecture

    A prioritised, costed remediation roadmap — the few things that matter most, in the order that matters.

  4. 04

    Something to act on

    A board-ready report and a 45-minute readout — evidence you can show customers, auditors and investors.

How it works

  • Fixed scope, fixed price, fixed timeline. Typically 2–4 weeks end to end. No open-ended day-rate creep.
  • Led by a senior practitioner — an ISO 27001 Lead Auditor with deep AI-governance and defence-grade security experience.
  • Built to convert into action. The fee credits in full against a follow-on 90-day remediation retainer.

Investment

From £5,000

Fixed price, scoped to your size — typically £5,000–£12,000. 2–4 weeks, board-ready. The fee credits in full against a follow-on remediation retainer.

Book a scoping call

Why Enigma

We don't sell AI transformation we haven't done ourselves.

Our own operation runs on governed AI agents under human control. We build, we don't just advise — and when we review your AI, we're describing our Tuesday, not a slide.