Home > Our Services

A triage-style 90-minute assessment of the prerequisites for agentic AI, giving you a complete and systematic view of your firm’s readiness, its strengths, and weaknesses – strategic, technical and operational, and organisational. A written report follows within 48 hours, ready to share with your line manager, Head of AI, or CRO. This independent, cross-platform, and risk-led diagnostic will let you set evidence-based and achievable goals for your agentic transformation.
9x - 11x over 12 months
Not applicable
per respondent. Each stakeholder completes their own facilitated assessment; we consolidate the results into a single report showing your firm-wide baseline and where perspectives diverge, plus a collective debrief. Contact us to arrange.
includes a 30-min Stakeholder Debrief one week after report delivery, e.g. for your line manager, CRO, Head of AI, or other stakeholders.
A structured 7-step workflow-level risk assessment that ensures you embed your necessary risk controls into your agentic workflow. Delivered using Gerido©, this service will identify the agentic risks in a planned workflow, design risk treatment plans, and map the necessary agentic KRIs. Culminating in a CRO-ready risk report, you will avoid post-deployment remediation costs, speed up your build cycle, and gain a defensible answer to a regulator’s question, “How did you select the controls for your agentic workflow?”
4x - 5x over 6 months
To create auditable evidence of oversight and control.
Formal test plan for red-teaming the agent’s controls – defines attack scenarios, expected responses, and pass / fail criteria.
Proprietary Methodology:
Gerido© Agentic Risk Management Platform
A facilitated working session of up to 8 hours for function leaders, followed by a written programme initiation plan that converts agentic AI from a technical topic into a clearly defined organisational transformation. In one day, you will build a shared understanding of how AI agents behave and the risks they introduce, define your corporate vision for agentic AI, see your readiness measured against it, develop an evidence-based, achievable strategy for governing agentic AI and record the rationale for it, align on a practical implementation roadmap, and commit to the immediate next steps. On completion, we will consolidate and strengthen your contributions into a transformation plan with workstream milestones, dependencies, and owners.
4x - 9x over 12 months
A planning sprint to convert initial planning assumptions into detailed and consistent workstream plans, including costs and dates
A board-level policy document defining the type and amount of agentic risk your company is willing to accept, giving direction to project and operational teams, and creating regulatory defence.
Independent re-assessment of every workstream at agreed intervals, so your leadership can see programme-wide progress evidenced.
A structured engagement that identifies, evaluates, and sequences the agentic AI use cases that will deliver the greatest value for your organisation. We arrive with a curated library of agentic use cases and capabilities relevant to your business and work with your stakeholders to identify those with the highest potential. We then submit up to two shortlisted capabilities to our Pre-Deployment Agentic Risk Assessment. This produces the controls, effort estimates, and risk profiles you need to prioritise your investment decisions: business impact, feasibility, and expected ROI. The result is an execution-ready plan that tells you exactly which workflows to build, in what order, what each will cost, and what needs to be in place before you start.
~3x - 5x over 12 months
Where more than two shortlisted capabilities warrant full assessment. Priced below the standalone fee because scoping and stakeholder access are already complete.
Slide deck and executive briefing note enabling your sponsor to present to the board or ExCo without further preparation.
A board-level policy document defining the type and amount of agentic risk your company is willing to accept, giving direction to project and operational teams, and creating regulatory defence.
For the first time, a worker that cannot bear legal liability can feature on your org chart. At task level for one or two of your agentic workflows, we will map the tasks the workflows create and remove, link every non-human worker to an accountable human, and write a Span of Agency for each agent: the discretion it holds without returning for authorisation, what rests with people, and who approved the split. You will discover where your role descriptions and statements of responsibility misalign with the new workflow and you will decide how to separate accountability for designing the agent’s decision boundary from accountability for outcomes within it.
5x - 6x over 12 months
We redraft the affected statements of responsibility and role descriptions so they describe the work as it is now performed.
We identify which roles will need new capabilities and skills as a result of the deployment, and what those capabilities are – the input to your skills framework, your Training and Competence records, and your hiring plan.
Slide deck and briefing note enabling your sponsor to present the accountability map.
A structured project that specifies the controls your AI agents need: which agentic risks apply to you, why / why not, the control outside the model or human procedure that treats each risk, the evidence it produces, the risk owner and control owner(s), and the monitoring mechanisms. It is built around a facilitated workshop, with material pre-work: a customised agent risk tiering, statement of applicability, and detailed control log, for your colleagues’ and your approval. We then use the workshop to practice applying the control framework to different use cases and developing workstream-level implementation plans.
7x - 10x over 24 months
Independent review of control effectiveness, ongoing monitoring, drift in risk profile, regulatory developments, and best practice.
A deck and briefing note that let your sponsor present the control design without further preparation.
A board-level policy document defining the type and amount of agentic risk your company is willing to accept, giving direction to project and operational teams, and creating regulatory defence.
A structured review of agentic workflows that are already live. Using our proprietary, systematic, and verifiable agentic risk flags, we will determine whether your workflow is sufficiently controlled, e.g. ownership, behaviour boundaries, and stop authority. Delivered using Gerido©, it produces audit-ready findings and a prioritised risk treatment plan – giving risk managers a fast, defensible basis for action.
6x - 9x over 12 months
Urgent? Let us know on your first call, and we will give you the earliest available time.
Convert the recommendations into an action plan – task owners, sequencing, effort estimates, and deadlines.
Plain-English summary of findings suitable for non-executive directors – framed around regulatory exposure and management response.
Quarterly retainer to review your risk flags for changes to your risk posture.
Proprietary Methodology:
Gerido© Agentic Risk Management Platform
A focused 2-day diagnostic that scores your firm’s operational data against the six characteristics of good training data – Structured, Current, Authoritative, Rich, Verifiable, and Symmetrical (SCARVeS©) – producing a readiness scoresheet, top 3–5 risks identified, and indicative regulatory exposure under Consumer Duty, EU AI Act Article 10, and PRA SS1/23. The Diagnostic is structured to answer one question: “do we have the data we need for our planned agent?” If material risks are identified, the Deep Dive will then scope how to mitigate them defensibly. 50% of the Diagnostic fee is credited toward the Deep Dive if booked within 90 days.
A report that includes:
~3x - 4x over 12 months
Not applicable – fixed fee.
A 30-minute follow-up debrief one week after the readout, e.g. for your CRO, line manager, or AI committee.
Adds one day of light-touch source-system sampling, providing limited ground-truth testing on the highest-risk data domain identified during the diagnostic.
A focused two-day diagnostic that scores one function against the four measures beyond conventional span of control: agent-to-agent handoffs per supervisor, review depth against review volume, the exception-to-routine ratio once agents absorb the routine work, and peak-load headroom. It answers one question: is anyone in this function reviewing more agent output than they can meaningfully assess? If the answer is yes, the full Oversight Capacity Measurement will size the problem more broadly and set defensible limits.
~3x - 4x over 12 months
Not applicable – fixed fee.
A 30-minute follow-up debrief one week after the readout, e.g. for your CRO, line manager, or AI committee.
Independent expert agentic AI governance advice – without the cost of a full-time hire, and with continuity that one-off engagements cannot match. Participation in your Agentic AI Steering Committee (or equivalent) with a monthly briefing on agentic AI developments, their impact on your firm, and proposed responses. At least 4 hours of advisory support each month: risks and issues, project support such as weekly meetings, governance questions, deployment and autonomy decisions, and board or regulator preparation.
2x - 3x over 12 months
Not applicable.
Development of internal or external communications on your firm’s use of agentic AI.
A structured per-use-case audit of the operational data your AI agents will rely on at runtime – covering accuracy, completeness, recency, relevance, and accessibility – producing a defensibility map showing where your data is, where the agent(s) need it to be, and which gaps create exposure under Consumer Duty, EU AI Act Chapter III, and PRA SS1/23. Because errors in operational agentic data will not stop at a single misclassification – they propagate – this independent diagnostic ensures your data compounds accuracy, not inaccuracy, as autonomous workflows scale. Typically follows the Agentic AI Data Readiness Diagnostic, with 50% of the Diagnostic fee (£2,000) credited toward the Deep Dive when booked within 90 days.
~2x - 3x over 12 months
A firm-specific overlay defining what data agents may access, how it is curated and version-controlled, who owns each domain, and how decisions are logged for audit.
Ongoing independent review as policies, regulations, and agent scope evolve – reducing the risk of gaps emerging between agent behaviour and firm procedures.
Slide deck and executive briefing note enabling your sponsor to present the defensibility map and remediation plan to the board or ExCo without further preparation.
Conventional measures mask underlying change: staff numbers, costs, and span of control indicate stability while, underneath, supervisory work has multiplied. We will measure dimensions beyond span of control – agent-to-agent handoffs per supervisor, review quality alongside volume, and the shift in the mix of work once agents absorb the routine tasks that provide vital variety and recovery within the working day. On completion, we will have defined and measured your oversight capacity, recommended hard limits on how much agent output one person can meaningfully review, and stress-tested those limits – because peak load determines capacity. Typically follows the Agentic Oversight Capacity Diagnostic, which tests a single function and answers whether a firm-wide measurement is warranted. 50% of the Diagnostic fee (£2,500) is credited toward this service when booked within 90 days.
~3x - 4x over 12 months
Measurement taken before your agents go live, so you can directly evidence the change afterwards.
Independent re-measurement as the agent estate grows, showing whether oversight capacity has kept pace with it.
A non-agentic incident management procedure will not protect you in an agentic environment. Agentic incidents can be autonomous, gradual, cross-system, and invisible to conventional alerting – leaving your detection, containment, and evidence capabilities configured for human-initiated failures when they need to respond to autonomous ones. This three-stage service will upgrade your current incident management procedure to ensure it is fit-for-purpose for agentic AI. It does this by 1) identifying gaps in your current procedure, 2) defining your upgrade requirements customised to the level of risk your agents will take, and 3) providing a prioritised project plan to close the gaps.
~4× - 6x over 12 months
To review progress against the Stage 3 implementation project plan.
A design and implementation service for organisations that want support with deploying a specific agentic workflow. Our dedicated experts will ensure you navigate the process from design, risk assessment, and platform selection, to build, testing and deployment. Working either alongside your technology team or independently, we will deliver an agentic workflow and organisational capability that is structured, governed, and audit-ready from day one.
2x - 6x over 12 months
Structured post-deployment risk flag review, satisfying DORA’s continuous monitoring requirement.
Proprietary Methodology:
Agents absorb the routine work that formed the apprenticeships through which people historically built professional judgement. For a few years, a firm can hire experienced practitioners; over the longer term, it will need to develop them internally. Our programme builds the delegation and judgement you will need from agent supervisors who may still be early in their careers. We achieve this by developing the practical and professional judgement that ‘on-the-job’ routine work once provided, adding agent-supervision skills as a distinct entry on your skills framework set alongside technical skill, and building the new management layer whose subordinates mainly supervise non-human workers. Delivered over two facilitated days per cohort, by an Investment Association approved trainer on agentic AI, and experienced, award-winning leaders.
2x - 4x over 24 months
Judgement forms through repeated exposure to edge cases, alternative viewpoints, and experienced evaluation. Cohorts bring live examples of an agent output they disagreed with, a boundary that looked wrong, an escalation they were unsure about – and work them through together.
We model your future pipeline of managers and senior managers, so agentic workforce planning enters the business case early.
A recorded decision on which capabilities you will preserve in your human workforce, with the reasoning, ready for annual review.
A structured programme to return a paused or flagged agentic workflow to safe, controlled operation. Where a workflow has been halted or identified as inadequately controlled – whether following incident management, an audit finding, a regulatory challenge, or a proactive controls review – we diagnose the root cause, redesign and implement the controls that failed or were absent, retrain the agent where required, and produce the documented evidence that the remediated workflow is fit to relaunch or continue safely.
6x - 13x over 3 months
A structured debrief with business, technology, and risk stakeholders that captures lessons learned and embeds them in the firm’s governance documentation, suitable for regulatory disclosure and directly informing the firm’s Agentic AI Governance Design.
We use some cookies - read more in our policies below.
Fill in this form and get access to our
Template Agentic Risk Appetite and Adoption Strategy for free

Fill in this form and get access to the
Enterprise-Wide Agentic AI Controls Framework.

Fill in this form and stay up to date