What We Do

Every artificial intelligence system in your business, assessed.

We identify which will fail regulatory scrutiny, and we track every change in the law that follows, so the obligation to keep pace sits with us rather than with you.

Discuss your assessment

The assessment

From inventory to a defensible position.

We turn a complex AI estate into a sequence of decisions your legal, compliance, and technical teams can act on.

1
Inventory

What exists, where it runs, and who owns it.

We document each AI system, supplier, data flow, business purpose, deployment context, and accountable owner to establish a reliable scope.

2
Classification

Risk tier, use case, and affected people.

We classify every system by its use, impact, jurisdiction, affected groups, and regulatory risk so attention is directed where exposure is highest.

3
Obligation mapping

The rules that attach to each system.

We connect each system to the legal duties, governance standards, controls, documentation, and evidence required for its specific operating context.

4
Gap register

Evidence, controls, decisions, and owners.

We record missing controls and evidence, explain the resulting exposure, assign ownership, and distinguish urgent gaps from lower-priority improvements.

5
Remediation plan

A prioritised route to a defensible position.

We turn every confirmed gap into a sequenced action with an owner, priority, dependency, and clear evidence requirement for closing it.

What this replaces

Less internal drag. More certainty.

The alternative is usually a long trail of partial answers. We make the same work legible, owned, and accountable.

Your internal tools

Weeks of fragmented research, competing priorities, and no single owner for the answer.

Strathwill

One scoped assessment, one evidence-led register, and a clear route to action.

A documented position your team can explain, evidence, and maintain.

Strathwill assessment standard

Frameworks we work across

The obligations that shape your exposure.

We connect legal duties to the systems, controls, and evidence that make them real in your business.

EU AI ACT

GDPR

ISO 42001

NIST AI RMF

AICPA SOC

Start here

Assessments are scoped in a single call.

Bring the question you need answered. We will scope the assessment around the systems and obligations that matter.

Start a conversation