AI you can explain to your auditor

Our AI governance services find the AI systems you run, classify their risk and build the controls and evidence auditors and customers ask for. We build AI too, so the controls match how the systems actually behave.

  • AI inventory and risk classification
  • EU AI Act, NIST AI RMF, ISO/IEC 42001
  • LLM security testing and red teaming
  • 2–6 week scoping phase
Scope

What do AI governance services cover?

We answer three practical questions. Which AI systems do you run or use? Which rules apply to each of them? And can you prove the controls work? The output is an inventory, a risk classification per system, a gap list against the frameworks you care about, and a plan to close it.

How this differs from our cybersecurity and GRC work. Our cybersecurity and GRC services cover penetration testing, ISO 27001 and SOC 2 readiness, phishing simulation and vCISO support for your whole environment. This page is about the AI layer on top: model risk, AI-specific regulation and the attacks that only exist because a language model is in the loop. Many clients need both, and we scope them together.

Regulation

What does the EU AI Act mean for your company?

It depends on two things: the risk tier of each AI system, and whether you are its provider (you build it or put your name on it) or its deployer (you use it in your business). Most obligations fall on providers of high-risk systems. Companies outside the EU are covered when their AI is sold or used in the EU.

Risk tierExamplesWhat it means
ProhibitedSocial scoring, manipulative techniques that cause harm, untargeted scraping of facial images, emotion recognition at work or in schools (with narrow exceptions)Can't be placed on the EU market or used. These bans have applied since February 2025.
High-riskAI used in hiring and worker management, creditworthiness assessment of individuals, access to essential services, education, and safety components of regulated productsRisk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity requirements, conformity assessment and registration for providers
Transparency obligationsChatbots, AI-generated or manipulated images, audio and videoPeople must be told they're dealing with AI, and synthetic content must be marked
Minimal riskSpam filters, most internal productivity toolsNo specific obligations, beyond the general duty to make sure staff using AI understand it

If you're a provider

For a high-risk system: a lifecycle risk management system, training data governance, technical documentation, automatic logging, design for human oversight, a quality management system, conformity assessment before release and post-market monitoring. General-purpose model providers have separate duties.

If you're a deployer

For a high-risk system you must use it according to the provider's instructions, assign trained people to oversee it, monitor how it performs, keep the logs under your control and inform affected workers. Some deployers, including public bodies and those assessing creditworthiness, also need a fundamental rights impact assessment.

Timing. The Act's obligations phase in between 2025 and 2027, and the European Commission has proposed moving some high-risk deadlines later. We check the current timetable at the start of every engagement. This is our reading of the text, not legal advice.

Frameworks

Which framework should you build your AI programme on?

Pick one as the backbone and map the rest to it. NIST AI RMF is a good working structure for anyone. ISO/IEC 42001 is the choice when customers want a certificate. If you already run ISO 27001 or SOC 2, start by extending those controls to your AI systems, because most of the work is already there.

NIST AI RMF

A voluntary US framework built around four functions. Govern sets roles, policies and accountability. Map describes each system's context and who it can affect. Measure tests and tracks risks such as bias, errors and security. Manage decides what to do about them and monitors over time. NIST's Generative AI Profile adds guidance specific to LLMs.

ISO/IEC 42001

The international standard for an AI management system, published in 2023 and certifiable. It shares the management system structure of ISO 27001, so it fits next to an existing ISMS. We prepare the AI policy, risk and impact assessment process, Statement of Applicability against its Annex A controls, internal audit and evidence. An accredited body does the certification audit.

ISO 27001 and SOC 2 for AI

Existing controls already apply, but need AI-specific detail: model providers treated as suppliers with reviewed retention and training terms; access control on prompts, logs and vector stores; change management for prompts and model versions; data classification before anything enters a retrieval index; incident response that covers AI failures.

Nepal

Nepal Rastra Bank AI guidance for banks and fintechs

For banks, financial institutions and payment companies licensed by Nepal Rastra Bank, we map AI controls to NRB's guidance on AI use alongside its existing IT and cyber security requirements. Credit scoring, fraud detection and customer-facing chatbots are the usual systems in scope. If you also serve EU customers, one control set can be mapped to both. We confirm which NRB directives apply to your licence category with your compliance team at the start.

LLM security

How do you secure an LLM application?

Treat the model as an untrusted component. Anything it reads can contain instructions, and anything it outputs can be wrong or malicious. Security comes from the surrounding system: what data the model can reach, what it's allowed to do, and what checks sit between its output and your users or databases.

We test against the OWASP Top 10 for LLM Applications and add cases specific to your system. These are the risks we find most often:

RiskWhat it looks likeWhat we test and put in place
Prompt injectionInstructions hidden in a user message, an uploaded file, an email or a web page the model readsDirect and indirect injection test sets; separation of instructions from data; limits on what injected text can trigger
Sensitive data leakageThe assistant reveals another customer's data, internal documents or secrets in its contextPermission checks at retrieval time based on the user's own access rights; redaction in logs; output filters
Excessive agencyAn agent with broad API keys deletes, sends or pays when it shouldn'tLeast-privilege tool access, confirmation steps for irreversible actions, per-action audit logs
Model and data supply chainUnverified open-weight models, poisoned datasets, unvetted pluginsPinned model versions, verified sources, safe weight formats, an inventory of models and datasets alongside your software bill of materials
Unbounded consumptionLong or looping requests that run up cost or take the service downRate limits, token budgets per user and per request, alerts on spend

Red teaming. Beyond the checklist, we run adversarial sessions against your application with the goals a real attacker would have: extract data, make the system act outside its role, or produce content that embarrasses you. Findings come with reproducible prompts and a severity rating, and we retest after fixes. If we also build your LLM features, those attack cases go into the evaluation set from day one.

Policy

Policies that people actually follow

A governance programme lives or dies on a few short documents: an AI acceptable use policy, an approval process for new AI tools and models, an AI incident procedure, and system cards that record what each model does, what data it uses and who owns it. We write them to fit how your teams work.

Our own AI ethical use policy is public. It limits where our team uses generative AI and requires senior review of any AI-assisted code. Your policy will look different, but it's an example of the level of detail that makes a policy enforceable.

Our own product

Certifyi AI SaaS GRC platform

Certifyi is the AI SaaS GRC platform Dignep designed and built end to end. It maps controls across frameworks including the EU AI Act, ISO/IEC 42001, NIST AI RMF and SOC 2, automates evidence collection and tracks control status continuously. We use what we learned about where these frameworks overlap in client work.

Read the Certifyi case study

Deliverables and pricing

What you get and how it's priced

How pricing works: every engagement is scoped and quoted after a free 30-minute discovery call, and you get a written proposal with pricing within two working days. Cost depends mainly on how many AI systems are in scope and which frameworks apply. The first 2–6 weeks are scoping: we build the inventory, classify each system and measure the gaps. Remediation is quoted once we know the size of the job.

DeliverableWhat it isPhase
AI system inventoryEvery AI system you build, buy or embed, with owner, purpose, data used and vendorScoping
Risk classificationRisk tier and your role (provider or deployer) per system, with the reasoning written downScoping
Gap assessmentCurrent controls against the EU AI Act, NIST AI RMF, ISO/IEC 42001 or NRB guidance, as relevantScoping
Remediation planPrioritised fixes with owners, effort estimates and target datesScoping
Policies and proceduresAcceptable use, model and tool approval, AI incident handling, system cardsRemediation
LLM security test reportFindings with reproducible prompts, severity and retest resultsRemediation
Evidence pack and risk registerDocumentation ready for an auditor, a customer security review or a regulator's requestRemediation
  1. Discovery call

    A free 30-minute call about your AI use and what's driving the work. A scoped proposal follows within two working days.

  2. Scoping, 2–6 weeks

    Interviews, system walkthroughs and document review, ending in the four scoping deliverables above.

  3. Remediation and evidence

    Policies, control changes and LLM testing, done with your engineers or by ours, then the evidence pack.

When we're not the right fit: if you need a legal opinion, hire a law firm; we'll work with them. If you need a certificate issued, that's an accredited certification body's job. And if your only AI use is one internal tool with no personal data, you probably don't need a full engagement yet. Tell us on the call and we'll say so.

Questions about AI governance and security

Does the EU AI Act apply to a company based in Nepal, India or the US?

It can. The Act applies to providers who place AI systems on the EU market and to providers and deployers outside the EU when the output of their AI system is used in the EU. If you sell software with AI features to European customers, assume it applies and check which risk tier your system falls into.

Is this legal advice?

No. We're engineers and compliance practitioners, not a law firm. We explain how we read the regulation, map it to controls and build the evidence. For a formal opinion on whether a system is high-risk, or on your contractual position, involve your lawyers. We regularly work alongside counsel.

Can Dignep certify us to ISO/IEC 42001?

No. Certification is issued by an accredited certification body after its own audit. We prepare you for that audit: gap assessment, AI policy, risk and impact assessment process, Statement of Applicability, internal audit and evidence. Keeping preparation and certification separate is how the standard is meant to work.

We already have ISO 27001. Do we need ISO/IEC 42001 too?

Not necessarily. ISO 27001 covers information security, including for AI systems, but not AI-specific concerns such as impact on individuals, data quality for training or human oversight. ISO/IEC 42001 uses the same management system structure, so it extends an existing ISMS rather than starting from scratch. Whether you need the certificate depends on what your customers ask for.

Do you review AI tools we buy, not just ones we build?

Yes. Most organisations use more third-party AI than they build: coding assistants, chat tools, AI features inside SaaS products. We include them in the inventory, review data handling and retention terms, and set approval rules so new tools go through a check before staff start using them.

How is an AI governance engagement priced?

We quote after a free 30-minute discovery call, with a written proposal within two working days. Each engagement starts with a 2–6 week scoping phase that produces the inventory, risk classification and gap assessment. Remediation work is quoted after scoping, once we know how many systems are in scope and which frameworks matter to you.

Start with an honest picture of your AI use

A 30-minute call is enough to tell you which rules are likely to apply and what a scoping phase would cover.

Scroll to Top