Governance that goes beyond compliance

A range of services for firms on either side of the adoption journey – whether you are preparing to deploy agentic AI safely or governing a fast-growing estate that needs oversight to match. From assessment to a fully governed, audit-ready, and continuously improving agentic transformation programme, at whatever pace your situation requires.

Agentic AI Risk Services - Gerido Agentic Risk Management Tool
assess-readiness
agentic-ai-readiness-assessment
Assess Readiness

Agentic AI Readiness Assessment

A triage-style 90-minute assessment of the prerequisites for agentic AI, giving you a complete and systematic view of your firm’s readiness, its strengths, and weaknesses – strategic, technical and operational, and organisational. A written report follows within 48 hours, ready to share with your line manager, Head of AI, or CRO. This independent, cross-platform, and risk-led diagnostic will let you set evidence-based and achievable goals for your agentic transformation.

Investment

£500
for the Core Diagnosis
Fixed fee · payable on booking

What you get

  • A high-level readiness map.
  • Prioritised next steps.

ROI

20x - 30x over 12 months

When It Is Vital

  • When staff already have access to agent-building tools and you need to understand whether your governance is adequate to manage the agents they are building, sharing, and deploying.
  • When you intend to deploy operational agentic workflows (beyond just admin assistants) and want to know what you should do to be ready to manage them.
  • When a board member, regulator, or auditor has asked a question about agentic workflows that you cannot yet fully answer.

Factors That Determine Price

Not applicable

Customise Your Service

Core Diagnosis Plus+
+£100

includes a 30-min Stakeholder Debrief one week after report delivery, e.g. for your line manager, CRO, Head of AI, or other stakeholders.

govern-agentic-ai
agentic-ai-governance-design
Govern Agentic AI

Agentic AI Governance Design

A structured project to upgrade your traditional AI governance to cover autonomous agents that will 1) pre-empt foreseeable issues, 2) reduce incidents, remediation, and build cycles, and 3) enable clear stakeholder communication. The initiative is also three-fold: ensuring an evidence-based and achievable design based on an assessment of your current state; enabling your informed choice of the most suitable approach to agentic governance for your firm; and developing an implementation roadmap of all deliverables (programme initiation, enabling activities, capability development, pre- and post-go live tasks).

Investment

£15,000 - £35,000

What you get

  • Agentic AI Readiness Assessment.
  • Agentic AI Governance Strategy.
  • Implementation roadmap.

ROI

10x - 25x over 24 months

When It Is Vital

  • When staff access to agent-building tools breaks your non-agentic AI governance model.
  • When your deployed AI agents exceed your existing governance capacity, resulting in ‘shadow agents’ leaving your risk profile ‘unknown’.
  • When you need an independent governance architecture that covers all platforms.
  • Specifically required under ISO 42001 Clauses 5 and 6, DORA’s ICT risk framework, NIST AI RMF 1.0, and EU AI Act Article 9.

Factors That Determine Price

  • Your starting position – firms with strong non-agentic AI governance require less.
  • Extent of agentic-specific governance that has already been implemented.
  • The number and complexity of live workflows, agent types, and human oversight roles to be incorporated.
  • Need to comply with existing regulatory processes (ICAAP, ORSA, DORA ICT framework, ISO 42001 certification programme).

Customise Your Service

Annual agentic governance review
+£6-10k/year

Independent review of governance effectiveness, regulatory developments, changes in risk profile, and best practice.

Agent Tiering Design
+£8-£16k

Risk-based tiering criteria, workflows, and accountability that scales across your entire agent estate.

Agentic Risk Appetite Statement
+£4-£8k

A board-level policy document defining the type and amount of agentic risk your company is willing to accept, giving direction to project and operational teams, and creating regulatory defence.

agentic-risk-assessments
pre-deployment-agentic-risk-assessment
Agentic Risk Assessments

Pre-Deployment Agentic Risk Assessment

A structured 7-step workflow-level risk assessment that ensures you embed your necessary risk controls into your agentic workflow. Delivered using Gerido©, this service will identify the agentic risks in a planned workflow, design risk treatment plans, and map the necessary agentic KRIs. Culminating in a CRO-ready risk report, you will avoid post-deployment remediation costs, speed up your build cycle, and gain a defensible answer to a regulator’s question, “How did you select the controls for your agentic workflow?”

Investment

£15,000 – £25,000

What you get

  • CRO-ready risk report.
  • Controls and KRIs your engineer can encode.
  • Upskill your team.

ROI

5x - 10x over 6 months

When It Is Vital

  • Vital when you want to launch an agentic workflow but are unfamiliar with the risks and controls you will need.
  • Required under DORA’s ICT risk framework obligations for all financial entities, and under EU AI Act Article 9 for high-risk systems.
  • Vital when you want your new agentic workflow to work first time avoiding costly post-deployment remediation.

Factors That Determine Price

  • Workflow complexity, organisational capability, expected scale of attack surface, and compliance requirements
  • Availability and completeness of documentation.
  • Number of stakeholders.

Customise Your Service

Presentation to AI Governance Committee
+£1,000

To create auditable evidence of oversight and control.

Adversarial testing specification
+£2,500

Formal test plan for red-teaming the agent’s controls – defines attack scenarios, expected responses, and pass / fail criteria.

Proprietary Methodology:

Gerido© Agentic Risk Management Platform

design-delivery-remediation
agentic-ai-use-case-prioritisation-roadmap
Design · Delivery · Remediation

Agentic AI Use Case Prioritisation

A structured engagement that identifies, evaluates, and sequences the agentic AI use cases that will deliver the greatest value for your organisation. We arrive with a curated library of use cases relevant to your business and work with your stakeholders to identify those with the highest potential. We then submit each shortlisted use case to our Pre-Deployment Agentic Risk Assessment. This produces the controls, effort estimates, and risk profiles you need to prioritise your investment decisions: business impact, feasibility, and expected ROI. The result is a execution-ready plan that tells you exactly which workflows to build, in what order, what each will cost, and what needs to be in place before you start.

Investment

£24,000 - £56,000
~4 - 8 weeks · fixed fee

What you get

  • Consensus on a prioritised, justified, phased roadmap designed for quick wins first and scale second.
  • Highest-impact lowest-risk rollout.

ROI

4x - 15x over 12 month

When It Is Vital

  • When you know agentic AI matters to your business but are unsure where to start or what to prioritise.
  • When you want to avoid costly, uncoordinated adoption – building the wrong workflows first, or building without proper risk controls.
  • When you need a defensible, board-ready plan that connects agentic AI ambitions to measurable business outcomes.

Factors That Determine Price

  • Number of business lines and asset classes in scope.
  • Number of stakeholders to interview.
  • Complexity of existing technology and data landscape.
  • Volume and complexity of use cases.
  • Regulatory jurisdictions to consider (e.g. DORA, EU AI Act).

Customise Your Service

Board presentation pack
+£3,5k

Slide deck and executive briefing note enabling your sponsor to present to the board or ExCo without further preparation.

Agentic Risk Appetite Statement
+£4-£8k

A board-level policy document defining the type and amount of agentic risk your company is willing to accept, giving direction to project and operational teams, and creating regulatory defence.

agentic-risk-assessments
post-deployment-agentic-risk-assessment
Agentic Risk Assessments

Post-Deployment Agentic Risk Assessment

A structured review of agentic workflows that are already live. Using our proprietary, systematic, and verifiable agentic risk flags, we will determine whether your workflow is sufficiently controlled, e.g. ownership, behaviour boundaries, and stop authority. Delivered using Gerido©, it produces audit-ready findings and a prioritised risk treatment plan – giving risk managers a fast, defensible basis for action.

Investment

£10,000 - £20,000

What you get

  • Report of risk flags discovered, potential impact.
  • Recommended risk treatment plans.
  • Fast path to compliance.

ROI

8x - 20x over 12 months

When It Is Vital

  • When an agentic workflow is displaying issues, and you need a fast, defensible risk treatment plan.
  • When you need assurance that your agentic controls are effective, e.g. in preparation for an audit.
  • When you need to include a live agentic workflow within a documented risk framework, e.g. DORA compliance.
  • When you operate a governed agent estate and need a systematic, recurring assurance process to confirm that live agents remain adequately controlled as they learn and adapt.

Factors That Determine Price

  • Workflow complexity.
  • Single or multi-agent architecture.
  • Whether the agent is live, paused, or in pre-production.

Customise Your Service

Express Service
+15%

Urgent? Let us know on your first call, and we will give you the earliest available time.

Remediation plan
+£3,500

Convert the recommendations into an action plan – task owners, sequencing, effort estimates, and deadlines.

Audit committee briefing
+£500

Plain-English summary of findings suitable for non-executive directors – framed around regulatory exposure and management response.

Quarterly risk flag retainer
+£3,500

Quarterly retainer to review your risk flags for changes to your risk posture.

Proprietary Methodology:

Gerido© Agentic Risk Management Platform

govern-agentic-ai
agentic-ai-executive-workshop
Govern Agentic AI

Agentic AI Executive Workshop

A facilitated session of up to 8 hours for ExCo members that converts agentic AI from a technical topic into a clear policy direction ‘from the top’. In the session, you will gain the knowledge needed to lead an agentic organisation, set an evidence-based and achievable strategy on how you will govern agentic AI, align on a practical implementation roadmap, and commit to the immediate next steps.

Investment

£8,000 – £24,000
Up to 8hrs · in-person or virtual

What you get

  • Agentic AI Readiness Assessment.
  • Agentic AI Governance Strategy.
  • Implementation roadmap.

ROI

5x - 12x over 12 months

When It Is Vital

  • At the outset of any agentic AI programme, when the organisation needs clear, strategic direction, informed decisions, and momentum from the top.
  • When you want to develop a strategic agentic capability and avoid risky, costly, and uncoordinated agent proliferation.
  • Vital when a regulator or auditor asks for evidence of board-level AI oversight.

Factors That Determine Price

  • Length of workshop.
  • In-person vs virtual delivery (travel costs additional for in-person).
  • Size of the leadership group (standard is 7 to 10; extended up to 20).
  • Number of Agentic Risks consultants needed, e.g. to run breakout sessions.
  • Degree of pre-session customisation and pre-read materials.

Customise Your Service

Coaching support
+£tbc

Customisable packages for your agentic AI executive sponsor.

Agentic Risk Appetite Statement
+£4-£8k

A board-level policy document defining the type and amount of agentic risk your company is willing to accept, giving direction to project and operational teams, and creating regulatory defence.

design-delivery-remediation
agentic-workflow-delivery
Design · Delivery · Remediation

Agentic Workflow Delivery

A design and implementation service for organisations that want support with deploying a specific agentic workflow. Our dedicated experts will ensure you navigate the process from design, risk assessment, and platform selection, to build, testing and deployment. Working either alongside your technology team or independently, we will deliver an agentic workflow and organisational capability that is structured, governed, and audit-ready from day one.

Investment

£8,000 – £60,000
Scope-dependent · discussed on consultation

What you get

  • Live agentic workflow and controls.
  • Measurable productivity gains.

ROI

4x - 15x over 12 months

When It Is Vital

  • When you want to leverage the benefits of agentic AI but need additional resource and capability to do it safely.
  • When speed and risk management are important to you.
  • When you need a properly documented project that will withstand regulatory scrutiny.

Factors That Determine Price

  • Single or multi-agent architecture.
  • Extent of configuration and training needed.
  • Degree of enterprise system integration required.
  • Timeline and sprint structure – phased delivery programmes are priced differently from single-sprint engagements.
  • Nature of post-launch support requirements.

Customise Your Service

Controls audit at 90 days
+£5,000

Structured post-deployment risk flag review, satisfying DORA’s continuous monitoring requirement.

assess-readiness
agentic-ai-training-data-readiness-diagnostic
Assess Readiness

Agentic AI Training Data Readiness – Diagnostic

A focused 2-day diagnostic that scores your firm’s operational data against the six characteristics of good training data – Structured, Current, Authoritative, Rich, Verifiable, and Symmetrical (SCARVeS©) – producing a readiness scoresheet, top 3–5 risks identified, and indicative regulatory exposure under Consumer Duty, EU AI Act Article 10, and PRA SS1/23. The Diagnostic is structured to answer one question: “do we have the data we need for our planned agent?” If material risks are identified, the Deep Dive will then scope how to mitigate them defensibly. 50% of the Diagnostic fee is credited toward the Deep Dive if booked within 90 days.

Investment

£5,000
fixed fee · 50% credited to Deep Dive
Fixed fee · payable on booking

What you get

A report that includes:

  • Six-characteristic data readiness scoresheet (RAG-rated).
  • Top 3–5 risks identified with indicative regulatory exposure.

ROI

~4x - 5x over 12 months

When It Is Vital

  • When you are scoping your first medium or high-risk agentic workflow and need a fast read on data risks before committing to build.
  • When you want to know whether your data is fit for agentic AI before committing to a larger assessment.
  • When your AI committee or risk function has flagged data as a concern, but you need a systematic and complete way to size the problem.

Factors That Determine Price

Not applicable – fixed fee.

Customise Your Service

Stakeholder debrief
+£500

A 30-minute follow-up debrief one week after the readout, e.g. for your CRO, line manager, or AI committee.

Extended diagnostic
+£2,000

Adds one day of light-touch source-system sampling, providing limited ground-truth testing on the highest-risk data domain identified during the diagnostic.

training
audit-risk-compliance-agentic-bootcamp
Training

Audit, Risk & Compliance Agentic Bootcamp

A specialist two-day programme for risk managers, compliance officers, and internal auditors. You will learn how AI agents behave and the new class of risks they introduce. You will become familiar with the different levels of autonomy, their risk profiles, and how to control them. You will practice developing and challenging agentic risk treatment plans, navigating the regulatory landscape, and preparing for an agentic audit.

Investment

£16,000 – £36,000
Up to 30 participants · virtual or in-person

What you get

  • Control and governance artefacts.
  • Audit readiness checklists.
  • ISO 42001 and NIST AI RMF and compliant templates.

ROI

2x - 4x over 24 months

When It Is Vital

  • When you want your organisation to govern agents and keep them on track.
  • Vital for firms pursuing ISO 42001 certification or DORA compliance, where the risk and audit functions need to own the ongoing operation of the AI management system.

Factors That Determine Price

  • Virtual versus in-person delivery across three sessions.
  • Size of the project team (standard up to 8; extended up to 15).
  • Number of Agentic Risks consultants needed, e.g. to run breakout sessions.
  • Degree of pre-session customisation and pre-read materials.

Customise Your Service

Coaching support
+£tbc

Customisable packages for your agentic AI executive sponsor.

Additional training packages
+£tbc

Sign up for other training solutions within 7 days of completion and receive a 15% discount on subsequent purchases.

Training provider to the global Institute of Risk Management and the UK Investment Association.

design-delivery-remediation
agentic-workflow-remediation
Design · Delivery · Remediation

Agentic Workflow Remediation

A structured programme to return a paused or flagged agentic workflow to safe, controlled operation. Where a workflow has been halted or identified as inadequately controlled – whether following incident management, an audit finding, a regulatory challenge, or a proactive controls review – we diagnose the root cause, redesign and implement the controls that failed or were absent, retrain the agent where required, and produce the documented evidence that the remediated workflow is fit to relaunch or continue safely.

Investment

£8,000 – £30,000
Scope-dependent · discussed on consultation

What you get

  • Redesigned controls.
  • Retrained agent.
  • Relaunch assurance report.

ROI

8x - 20x over 3 months

When It Is Vital

  • When you have identified workflows operating without adequate controls.
  • Post-incident, when you need to diagnose root cause, remediate controls, and relaunch safely.
  • When you have identified control weaknesses requiring remediation before the workflow can continue.
  • When a live workflow is exhibiting risk flags, and you need rapid expert intervention.

Factors That Determine Price

  • Extent of diagnosis already conducted.
  • Number and severity of control failures.
  • Whether agent retraining is required or whether controls reconfiguration alone is sufficient.
  • Urgency.

Customise Your Service

Incident debrief facilitation
+£2,000

A structured debrief with business, technology, and risk stakeholders that captures lessons learned and embeds them in the firm’s governance documentation, suitable for regulatory disclosure and directly informing the firm’s Agentic AI Governance Design.

govern-agentic-ai
retained-agentic-ai-governance-advisory
Govern Agentic AI

Retained Agentic AI Governance Advisory

Independent and expert agentic AI governance advice, on a retained basis – without the cost of a full-time hire, and with the continuity that one-off engagements cannot match. Participation in your Agentic AI Steering Committee (or equivalent) with a monthly briefing on developments relating to agentic AI, their impact on your firm, and proposed responses. A minimum of 4 hours of advisory support for the management of agentic risks and issues, governance questions, deployment decisions, or board and regulator preparation.

Investment

£ 4,750 per month
retained.
Minimum 3-month term.

What you get

  • Dedicated and flexible access to ‘best in class’ strategic capability.
  • Adopt agentic AI safely and with confidence.
  • Evidence of oversight.

ROI

3x - 5x over 12 months

When It Is Vital

  • You are deploying or evaluating agentic AI but have no dedicated governance resource internally.
  • Your board, CRO, or regulator is asking questions about agentic AI risk that your current team cannot confidently answer.
  • You need ongoing expert oversight without the cost or commitment of a full-time senior hire.

Factors That Determine Price

Not applicable.

Customise Your Service

Additional advisory hours
+£300 per hour
Communications content
+£300 per hour

Development of internal or external communications on your firm’s use of agentic AI.

Discount for 12 months
10%
Discount on all other services
15%

Often Leads Clients To:

Clients who maintain an ongoing advisory relationship typically experience low-friction agentic transformations – because the context, trust, and shared understanding are already in place.
assess-readiness
agentic-ai-operational-data-readiness-deep-dive
Assess Readiness

Agentic AI Operational Data Readiness – Deep Dive

A structured per-use-case audit of the operational data your AI agents will rely on at runtime – covering accuracy, completeness, recency, relevance, and accessibility – producing a defensibility map showing where your data is, where the agent(s) need it to be, and which gaps create exposure under Consumer Duty, EU AI Act Chapter III, and PRA SS1/23. Because errors in operational agentic data will not stop at a single misclassification – they propagate – this independent diagnostic ensures your data compounds accuracy, not inaccuracy, as autonomous workflows scale. Typically follows the Agentic AI Data Readiness Diagnostic, with 50% of the Diagnostic fee (£2,000) credited toward the Deep Dive when booked within 90 days.

Investment

From £18,000
for 1 use case – multi-use-case discounts
Fixed fee per use case · agreed upon scoping

What you get

  • Defensibility map of your data estate.
  • Prioritised remediation plan.

ROI

~10x - 16x over 12 months

When It Is Vital

  • When you are preparing to deploy a medium or high-risk agent and need to know whether the data it will rely on is fit for autonomous use.
  • When your operational data sits across silos – email, SharePoint, vendor platforms, individual heads – and has not yet been curated for autonomous consumption.
  • When a supervisor, auditor, or regulator, has asked how you know the data your agents use is reliable.

Factors That Determine Price

  • Number of use cases in scope: 1 use case £18,000; 2 use cases £30,000; 3 use cases £40,000; 4+ bespoke.
  • Within each use case: number of source systems, data domain complexity, and regulatory scope (e.g. Consumer Duty, EU AI Act Ch. III, PRA SS1/23, GDPR).

Customise Your Service

Agentic Data Governance Policy
+£15,000 – £30,000

A firm-specific overlay defining what data agents may access, how it is curated and version-controlled, who owns each domain, and how decisions are logged for audit.

Assure Retainer
+£3,000 / month

Ongoing independent review as policies, regulations, and agent scope evolve – reducing the risk of gaps emerging between agent behaviour and firm procedures.

Board Briefing Pack
+£3,500

Slide deck and executive briefing note enabling your sponsor to present the defensibility map and remediation plan to the board or ExCo without further preparation.

govern-agentic-ai
agentic-incident-management-procedure
Govern Agentic AI

Agentic Incident Management Upgrade

A non-agentic incident management procedure will not protect you in an agentic environment. Agentic incidents can be autonomous, gradual, cross-system, and invisible to conventional alerting – leaving your detection, containment, and evidence capabilities configured for human-initiated failures when they need to respond to autonomous ones. This three-stage service will upgrade your current incident management procedure to ensure it is fit-for-purpose for agentic AI. It does this by 1) identifying gaps in your current procedure, 2) defining your upgrade requirements customised to the level of risk your agents will take, and 3) providing a prioritised project plan to close the gaps.

Investment

Stage 1: £3,500 – £5,000
Stages 2 & 3: £12,500-£30,000 (total).

What you get

  • Gap analysis.
  • Customised requirements definition.
  • Prioritised project plan.

ROI

~15× – 25× over 12 months

When It Is Vital

  • When you are deploying medium or high-risk agents and need to know your incident management procedure is fit for this new purpose.
  • When you have experienced an incident and need to strengthen your procedure.
  • When your procedure has not been reviewed against agentic-specific obligations, e.g. EU AI Act Arts 9, 20 & 73, FCA / PRA resilience rules, ISO 42001 (s. 8 & 10), DORA Arts 17–20, GDPR Art 33.

Factors That Determine Price

  • Extent of gaps identified in Stage 1.
  • Number of in-scope agent workflows.
  • Complexity of tool and API ecosystem.
  • Single or multi-agent architecture.
  • Maturity of existing logging infrastructure.
  • Regulatory reporting obligations.

Customise Your Service

Post-implementation review
+£4,500

To review progress against the Stage 3 implementation project plan.

Integration with operational resilience programm
+£3,500
Navigate Services

Template Agentic Risk Appetite and Adoption Strategy download

Fill in this form and get access to our
Template Agentic Risk Appetite and Adoption Strategy for free

Agentic AI Risk Appetite Statement and Adoption Strategy

Enterprise-Wide Agentic AI Controls Framework

Fill in this form and get access to the
Enterprise-Wide Agentic AI Controls Framework.

Subscribe to our newsletter

Fill in this form and stay up to date

Get in touch