AI Risk · AI Value · AI Governance · AI Literacy

AI you can explain and account for — and a return you can show.

Find where AI creates risk, as exposure and as opportunity. Prove the value it delivers, then govern it so it holds up in production.

AI is already in your organization — in decisions, in processes, in tools that arrived with it switched on. The legal frame is already there too: in the EU, the AI Act puts duties not only on the organizations that build AI but on those that use it. Three questions arrive at once: what are we exposed to, what are we actually getting back, and are our people ready?

AI should create value without surrendering accountability. We help organizations understand where AI affects people, decisions and operations. Then put meaningful boundaries and human oversight around it and prove that what remains delivers a worthwhile return.

We also help you build AI literacy across your workforce. No AI programme succeeds beyond the competence of the people running it. ISO/IEC 42001 puts competence inside the management system rather than beside it, and the EU AI Act asks organizations to support the development of AI literacy. As a PECB Authorized Partner, we offer training in the ISO standards those roles depend on. PECB sets the exams and awards the credentials.

01

AI Risk

Where could the AI deviate — either way?

ISO 31000 sets the purpose of risk management as the creation and protection of value, and defines risk as the effect of uncertainty on objectives. ISO/IEC 42001 states it in the harmonised form and keeps the decisive note: an effect is a deviation from the expected, in a positive or negative sense. The work follows that process across the seven domains where AI creates exposure, and it starts from an inventory, because nothing downstream is reliable without one.

Explore AI Risk
01

Start from an inventory

Every use case and every AI system in one place, proposed as well as running. ISO/IEC 42001's Annex A asks for the resources behind each AI system to be identified and documented (A.4.2); NIST AI RMF asks for the inventory outright (GOVERN 1.6). It is also the asset the value and governance work reads.

02

Set the scope and the criteria

Which systems and processes fall in scope, whether each makes you a provider or a deployer, and what the organization has agreed it will tolerate — approved at board level, not inferred by whoever bought the licence.

03

Assess, then decide what changes

Identify, analyse, and evaluate against those criteria — including classification under the EU AI Act, and assessment against NIST AI RMF and ISO/IEC 42001. Then treat: controls designed, exposure accepted, or an activity stopped. Treatment is where an assessment turns into a decision.

04

Watch it, don't discover it

Indicators measured against the thresholds set earlier, so movement shows up before an auditor, a regulator, or an incident does.

02

AI Value

Does the AI earn what it costs?

Keeping models reliable is only half the job. The other half is finding where AI could deliver more, then weighing that opportunity against what it exposes you to, so investment follows evidence instead of enthusiasm. It runs on the same inventory the risk work builds — the AI portfolio, read for return rather than exposure.

Explore AI Value
01

Value defined before the commitment

The financial outcome comes first — revenue, cost, cycle time, margin — named before you buy, enable, or build, not reverse-engineered afterwards from whatever happened to be measured.

02

A gate every use case passes

Expected value, feasibility, risk, and data readiness assessed before anything goes live — for a bought licence or a switched-on feature as much as for a build. Scrapping weak proposals early is the discipline, not a failure of ambition.

03

Risk and return on one ledger

Every system carries both, and they reach a decision by different routes: different people, different times, different scales. Valued on one scale — return discounted for the confidence it deserves, less what it could cost and what controlling it costs — the portfolio shows where to invest and where exposure has quietly outgrown the benefit.

04

Reliability that protects the value

Models drift, hallucinate, and degrade under context load. Evaluation, monitoring, and traceability keep the return you built the case on from eroding after go-live.

03

AI Governance

Do the controls actually work?

Governance and a management system are two different things. The governing body sets direction: what AI is for, how much judgement it will delegate, what it will tolerate. The management system delivers against that. Most of the effort sits in the second, and the first is what makes the second coherent. Responsible AI is a requirement, not a posture: fairness, privacy, safety, transparency and human oversight become real at the point they are written as requirements a system has to meet and controls somebody has to operate.

Explore AI Governance
01

Direction, before delivery

What the organization will use AI for and what it will not, how much opacity is acceptable where an outcome affects a person, and what it will spend against what return. ISO/IEC 38507 places those with the governing body, and no management system can answer them on its behalf.

02

Accountability that names people

Roles, responsibilities and authorities allocated under ISO/IEC 42001 clause 5.3 and extended across suppliers and third parties. Human oversight assigned to someone with the competence and the authority to intervene, because authority is what makes oversight a control.

03

Controls, and where they are enforced

EU AI Act Articles 9 to 15 state what a high-risk system must achieve. ISO/IEC 42001 Annex A supplies thirty-eight reference controls to compare against, with every inclusion and exclusion justified in the Statement of Applicability. The architectural question is where each one is enforced in the landscape instead of asserted in a policy.

04

Evidence that they still work

A control that was designed correctly and is never tested is an assumption. Assurance, control indicators, and a management system under ISO/IEC 42001 that makes the whole of it auditable and connects to the risk function already running.

04

AI Literacy

The floor everyone stands on, with a ladder above it

Running AI takes a common floor of competence across the organization, and far more than the floor in a few roles. In the EU, the AI Act obliges providers and deployers to support the development of AI literacy among the people who operate their systems; elsewhere, customers, insurers and auditors ask the same question. The structure underneath is the same: first the capabilities an organization needs, then the roles that carry them, and only then the training that builds each role.

Courses

Training courses toward PECB certification, for the roles the maps name, in all four domains and on one ladder: Literate, Lead, Professional. PECB sets the exam and awards the credential. The course is where the role is built.

  • ISO/IEC 42001 Lead ImplementerAI management systems
  • ISO/IEC 42001 Lead AuditorAI management systems
  • ISO/IEC 42001 FoundationAI management systems
  • ISO 31000 Lead Risk ManagerRisk management
  • ISO 9001 Lead ImplementerQuality management
  • ISO 9001 Lead AuditorQuality management
  • ISO 21502 Lead Project ManagerProject management
Capability maps

Training is the last step, not the first. A capability map records what your organization has to be able to do in each domain, who carries that ability today, and which course leads there. Held against a real team, it shows where the gap is before anyone books a seat.

Hold the map against your team
Standards

Every course and every map is written against named instruments: the EU AI Act, NIST AI RMF, ISO/IEC 42001 and the standards beneath them. They overlap, they bind different roles, and they keep moving. The reference page keeps the landscape in one place, so the courses and the maps can be read against what actually applies.

See how they fit together

Start a conversation

Tell us where AI sits in your organization and which question is pressing — what it returns, what it exposes you to, or whether the controls hold. We will respond with a clear read on where you stand and a sensible first step, often a bounded AI risk assessment or an ISO/IEC 42001 gap analysis.