Your product won the demo. Then procurement asked for your AI governance documentation, and a six-figure deal went quiet. Without governance attestations, enterprise security reviews run four to eight weeks — and some never end. With the right evidence pack, vendors clear them in days.
We build that pack for you in 14 days. Fixed price. Fixed scope. Built on the 4Ps framework's Protected dimension — the one that holds when challenged.
One pack engagement at a time. Current availability: next slot on request.
The buyer's CISO doesn't doubt your product. They doubt your documentation. Three requests kill AI vendor deals in security review:
You have principles in a Notion doc. They want a signed, versioned policy a regulator could read.
Two hundred questions. Your team improvises answers between sprints, contradicts itself, and the review clock restarts.
Model cards, risk inventory, incident response, audit trail. The things you'd have if you'd been governing all along — and can stand up in two weeks if someone who's done it builds them with you.
Every week in review costs you pipeline, momentum, and the champion who staked their credibility on you.
Everything an enterprise security review asks of an AI vendor. Drafted with you, evidenced from your actual practice, delivered in 14 days.
ISO 42001-aligned, EU AI Act-aware (Article 50 transparency obligations land August 2026), signed-off and versioned.
Your models, use cases, and data flows mapped to a defensible risk classification — including model/vendor concentration and the fallback plan if a provider is restricted.
For each production model/system: purpose, data, limits, evaluation, human oversight.
Canonical answers to the questions every enterprise asks (AI usage, data handling, third-party models, incident response), reusable across every future deal.
What happens when the model misbehaves — or gets restricted, recalled, or withdrawn (as Fable 5 was in June 2026): who decides, who tells the customer, and the tested fallback you switch to.
A two-page document your sales team sends the moment procurement asks. The document that restarts stuck deals.
A certification (we prepare you for ISO 42001 certification as a separate engagement), a binder of theatre, or a 3-month consulting program.
Working session: your models, your deals, the exact questionnaire(s) blocking you. We triage what the reviewer actually needs.
We draft; you review async. Policies, register, model cards, response library — evidenced from your real practice, not boilerplate.
Red-team the pack against the live questionnaire. Sign-off, versioning, and a 60-minute handover so your team can defend every line.
After day 14, the pack is yours. Most clients send the attestation summary to their stuck deal the same week.
48-hour turnaround. We review your stalled questionnaire / reviewer correspondence and your existing documentation, and deliver a gap memo: exactly what's blocking the deal and what the pack must contain. Credited in full against the pack.
The full six-part evidence pack, 14 days, one production AI system/product line.
Invoiced on engagement.
The pack, plus: live completion of one enterprise security questionnaire alongside your team, multi-model coverage (up to three systems), and an ISO 42001 certification roadmap.
Invoiced on engagement.
Continuing support: certification-support engagements from £30k; governance retainers by arrangement.
Governance and risk frameworks delivered at Ogier Group (multi-jurisdiction legal & financial services) — ahead of schedule.
Delivery in regulated environments at GSK and Haleon (40% and 45% performance lifts; ~99% delivery predictability).
Oxford AI Governance (Saïd, 100%) and Wharton AI Strategy & Governance (100%).
Author of the 4Ps AI Governance Framework and Team Performance Uplift.
Five production agentic AI platforms shipped — we govern what we build, and we've answered these questionnaires as a vendor.
The pack is the Protected dimension of the 4Ps AI Governance Framework, applied to the vendor side of the table.
Explore the 4Ps framework ›That is exactly the continuity gap the pack closes. We map your model dependencies, set a concentration limit, build a tested fallback path, and give you a rehearsed playbook — so a government directive, recall, or outage is an inconvenience, not an outage of your business.
Security certifications answer “is your infrastructure safe?” AI reviews ask “is your model governed?” — different documents, different reviewer. The pack covers the AI-specific layer your existing certs don't.
Yes — in the 4–8 weeks your deal doesn't have. You're paying for the 14-day clock, reviewer-tested templates, and answers that won't contradict each other in round two.
No. The pack is built ISO 42001-aligned so nothing is wasted if you certify later. Certification support is a separate £30k engagement.
One technical lead, ~4 hours of workshop time across the 14 days, and access to whatever documentation exists (including none).
Round-one reviewer follow-ups within 30 days of handover are covered. That's the point of the pack.
There's no sales team. You work directly with the operator who builds the pack. Reserve a slot; if it's not a fit, we'll tell you on the call.