Nimble AI Free Scorecard
Nimble AI, AI governance and service management

We tell you when to stop buying.

Every rung below is fixed-price and time-bound. Climb it only as far as it actually helps: each one states plainly what you have if you stop there, and who shouldn't buy it at all.

We're a European AI governance and assurance practice because the EU AI Act and UK and EU GDPR can follow where your customers are, not where your office is. Engagements run remotely as standard, at the same fixed prices wherever you're based; on-site work is available on request.

A finished report laid flat on a desk, ready to be handed over
What you actually walk away with
The ladder

Eight rungs. Climb only as far as you need to.

Price and commitment rise as you go down this list, and the page rises with them: each rung sits a little further right, with a heavier rule, than the one before. Nothing here assumes you'll keep climbing.

01
Free / 10 minutes

AI Readiness Scorecard

Ten questions. A RAG-rated position across ten governance dimensions. No salesperson.

Free10 minutes

Most SMEs don't know whether AI rules apply to them at all, and a sales call is the wrong way to find out. So we built a free ten-minute self-assessment you can take anonymously, covering how your team uses AI, whether you make automated decisions about people, whether you sell into the EU, and which UK rules and voluntary frameworks are most relevant to you.

  • A RAG-rated readiness score across ten governance dimensions
  • A plain-English summary of which UK rules and benchmarks apply to you
  • A recommended next step, from "you're fine, here's a checklist" to "book a consultation"
  • No salesperson, no follow-up unless you ask
If you stop here

You have a written RAG position across ten governance dimensions and a plain answer to which rules touch your business. For a team only drafting or summarising with AI, that answer is often genuinely "you're fine," and there is nothing further to buy.

Take the free scorecard

02
Free / 30 to 60 minutes

AI Exposure and Scope Check

A call to confirm what actually applies to you, and what doesn't.

Free30 to 60 minutes

The hardest question for any business using AI is the most basic one: which rules are you actually subject to? The EU AI Act gets the headlines but it's only a legal duty for organisations that touch the EU market. UK GDPR, the reformed Article 22 rules under the Data (Use and Access) Act 2025, and the Equality Act bite far more often, plus your sector regulator. We unpack that with you on a single call, mapping how your business actually uses AI against legal duty and voluntary best practice.

  • A short written summary of which rules apply to you and why
  • A clear split between legal duty and voluntary best practice
  • A prioritised list of next steps, most clients need fewer than they feared
  • Honest scoping for any further work you actually need
If you stop here

You have a written split between what's a legal duty and what's voluntary, and a short prioritised list, if any, of what to do next. Most clients leave this call reassured rather than sold to, and for many that written position is the whole engagement.

Book a free consultation

03
from £3,500 / 1 to 2 weeks

AI Governance Health Check

A structured maturity assessment across ten governance dimensions, grounded in the frameworks that matter.

from £3,5001 to 2 weeks

Most teams using AI know they should have governance in place but don't have a clear picture of where they actually stand. This gives you that picture across the ten dimensions that matter: accountability, fairness, transparency, human oversight, data governance, privacy, security, safety and robustness, third-party communication, and continual improvement. Built on ISO/IEC 42001, the NIST AI Risk Management Framework and the EU AI Act.

  • Completed assessment across all ten dimensions of our governance framework
  • Maturity heatmap showing strengths and the highest-leverage gaps
  • Prioritised action plan with effort estimates
  • A clear pathway toward ISO/IEC 42001 alignment if that's your end goal
  • Board-ready summary
If you stop here

You have a maturity heatmap, a prioritised action plan with effort estimates, and a board-ready summary you can hand to your own team to action. Plenty of businesses stop here for good: the report is built to be actioned without us.

Book your Health Check

04
from £6,500 / 2 to 3 weeks

EU AI Act Rapid Audit

For AI that touches the EU market. Compliance, not best practice.

from £6,5002 to 3 weeks

If you place an AI system on the EU market, provide it to users in the EU, or its output is used there, wherever you yourself are established, the EU AI Act can be a hard legal duty, not a benchmark. The high-risk obligations were recently deferred to 2 December 2027, with transparency duties still landing in August 2026, and the Act is complex enough that most in-house teams can't safely self-assess. The extra time is best spent getting it right, not waiting.

  • Written AI systems inventory across your organisation
  • Risk classification for each system under the EU AI Act
  • Gap analysis against high-risk obligations
  • Prioritised action plan with timescales
  • Executive summary suitable for board or legal review
If you stop here

You have a written systems inventory, a risk classification, a gap analysis and a board or legal-ready executive summary. Many clients implement the fixes themselves from this report alone.

Book your Rapid Audit

05
from £6,500 / 2 to 3 weeks

Automated Decision-Making Audit

For HR, recruitment, credit, insurance and pricing teams. A UK legal duty, today.

from £6,5002 to 3 weeks

The Data (Use and Access) Act 2025 reformed Article 22 of UK GDPR: the rules on solely-automated decisions with legal or similarly significant effects on people. These rules are already in force, and they hit hiring, credit, insurance, pricing and recruitment harder than anything in the EU AI Act. They're also where you have real Equality Act exposure if a model produces biased outcomes against protected characteristics.

  • Inventory of solely-automated and significantly-automated decisions
  • Article 22 conditions and safeguards assessment
  • Equality Act bias-risk review against protected characteristics
  • Contestability and human-review process recommendations
  • DPIA template and ICO-aligned documentation
If you stop here

You have a full inventory of automated decisions, a safeguards assessment, a bias-risk review and a DPIA template you can complete and file yourselves. That's a complete, defensible position without any further work from us.

Book your Article 22 Audit

06
from £12,500 / 4 to 6 weeks

ISO 42001-Aligned Framework

Know what your AI is doing. Prove it to anyone who asks, against a certifiable standard.

from £12,5004 to 6 weeks

Audit findings are only useful if you act on them. Most businesses that complete an AI audit then struggle to build the governance infrastructure around it: the AI register, policies, decision audit trails and human oversight controls that regulators, insurers, customers and procurement teams increasingly demand. We build that infrastructure and align it to ISO/IEC 42001 so you have a credible, certifiable end state.

  • AI systems register with risk classifications
  • Decision audit trail design and implementation guidance
  • Transparency and explainability documentation
  • Human oversight control framework
  • Staff guidance and AI literacy training materials
  • Board-ready AI governance policy, ISO 42001-aligned
If you stop here

You have a complete governance framework: a register, an audit trail design, training materials and a board-ready policy. It stands on its own indefinitely; certification is optional, not implied.

Get your governance framework

+
Add on / £450 fixed / about 1 week

AI Use Policy Pack

Your team is already using ChatGPT. Get a plain-English policy around it in about a week.

£450 fixedabout 1 week

Most SMEs have staff using generative AI tools without a policy, without staff guidance, and without a clear view of the risks. This pack closes that gap, and it's the direct remedy for shadow AI: the tools your team is already using without governance around them.

  • Tailored AI acceptable use policy in plain English, written around the tools your team actually uses
  • One-page staff "dos and don'ts" quick reference
  • Short risk note: the three to five things to watch, each tied honestly to UK legal duty or best practice
  • 30-minute handover call to walk you through the pack
If you stop here

You have a policy, a one-page staff reference and a short risk note, handed over and explained. For a team just starting with generative AI tools, that's the entire deliverable; nothing else is required.

Get your AI Use Policy Pack

->
Build / from £25,000 / 6 to 12 weeks

Agentic AI Implementation

Stop using AI to advise. Start using AI to act, governed from day one.

from £25,0006 to 12 weeks

Most businesses use AI reactively: a chatbot here, a summarisation tool there. The real advantage comes from agentic AI, systems that independently take actions, manage workflows and make decisions within defined parameters. Building it correctly, with the governance, oversight and controls regulators and customers expect, demands specialist expertise most organisations don't have in-house.

  • Discovery and scoping workshop
  • Agentic AI system design and architecture
  • Build, test and deployment
  • Compliance documentation for the deployed system
  • Staff handover and training
  • 30-day post-deployment support
If you stop here

You have a live, working system your team can run, with compliance documentation and 30 days of support already used. That's the end state; there's nothing further to buy for this use case.

Discuss your implementation

Beyond the ladder

Two things that aren't a step. An add-on, and a retainer.

These sit alongside the ladder rather than on it: a security assessment you can take at any point once you know your AI estate, and an ongoing retainer for organisations that have decided certification itself is the goal.

Hands reviewing a printed document at a desk

AI Controls and Security Assessment

Your AI estate is growing. Aligned to NCSC and DSIT AI cyber-security guidance.

from £8,5003 to 4 weeks

AI systems introduce new attack surfaces, data risks and operational vulnerabilities that traditional IT security frameworks weren't built to address. Most organisations have accumulated a sprawling, undocumented AI estate, including shadow AI, the tools your team is actually using, sanctioned or not, with little visibility over what data it processes or where it's exposed.

  • Full AI estate discovery and mapping
  • Security vulnerability assessment
  • Data handling and privacy risk analysis
  • Controls gap analysis against NCSC AI guidance
  • Prioritised remediation roadmap
  • AI security controls framework documentation
If you stop here

You have a full estate map, a vulnerability assessment and a prioritised remediation roadmap you can hand to your own IT team. That stands alone whether or not you buy anything else from us.

Book your Security Assessment

ISO/IEC 42001 Certification Pathway

The end state. The only certifiable international AI-management-system standard.

from £1,500 a monthongoing retainer

ISO/IEC 42001:2023 is the only certifiable international standard for AI management systems. Under 100 organisations worldwide are currently certified. It's becoming a powerful procurement and trust signal, particularly for SaaS firms, regulated sectors and anyone selling enterprise. Getting there is a multi-year journey if you go it alone; this retainer shortens it.

  • ISO 42001 gap analysis against your current state
  • Controls implementation roadmap with quarterly milestones
  • Documented AI management system aligned to Annex A controls
  • Internal audit programme and management review cycle
  • Certification body liaison and stage 1 and stage 2 audit preparation
If you stop here

Cancel at any point and you keep the gap analysis, the roadmap and whatever controls work has already landed. Nothing is held hostage to reaching certification.

Discuss ISO 42001 Certification

Wherever you land on this, we'll tell you when to stop.

Start with the free scorecard Ten minutes, no sales call attached