AI Readiness Sprint
Where AI can safely go in your business, what your data and licences permit, and what to build first. Ends with a costed, sequenced plan.
Discuss this engagement →African organisations are putting AI into live operations right now — in banks, payment rails, telcos, hospitals, energy operators and government agencies. Very few of them have anyone who can both build the thing and answer the regulator about it.
Europe built its data and technology control frameworks over twenty years, then had to retrofit AI onto them. Much of Africa is skipping that entirely — arriving at AI adoption without the legacy scaffolding, and without the legacy technical debt either.
That cuts both ways. There’s less to unpick, and genuine room to build it properly the first time. There’s also less control infrastructure to fall back on, thinner specialist capacity to hire from, fragmented regulation across jurisdictions, and international partners who increasingly want the controls evidenced rather than asserted.
The result is familiar across the continent: ambitious roadmaps, real progress, and a widening gap between what boards are being asked to attest to and what their organisations can currently demonstrate.
We close that gap from both ends — building the systems, and evidencing them.
The five pillars, the binding regulatory stack around them, the risk register, and an independent assessment of what the strategy gets right and what is missing. Status verified August 2026.
Read the explainer →Where AI can safely go in your business, what your data and licences actually permit, and what to build first.
Function-specific training on people’s real work, so capability is built in-house rather than rented indefinitely.
Frameworks, policies and shadow-AI discovery suited to African operating realities, not lifted from a European template.
Reporting, monitoring, document handling and intelligence pipelines, built to a standard you can evidence and handed over so you own them.
NDPA (Nigeria), POPIA (South Africa), DPA (Kenya), DPA (Ghana), Rwanda’s DPP Law, and sector regulators — CBN, NCC, SEC, NCA, NITDA, ICT Authority, NDPC.
DPO functions, RoPAs, breach playbooks, and reporting to data protection authorities.
Particularly for organisations moving data between African jurisdictions, Europe, the Gulf and Asia. Increasingly an AI question, since that’s where the models sit.
SOC 2, ISO 27001, NIST CSF, and board reporting that satisfies international counterparties.
Locally contextualised crisis scenarios for African executive teams.
Academy design, curriculum, and executive education.
Primary focus market: NDPA, NDPC engagement, fintech, energy, telcos.
POPIA, financial services, listed-company governance, mature private-sector buyers.
Government digitalisation, financial inclusion, regional headquarters work.
Banking, telco, growing fintech ecosystem.
Fintech, mobile money, regional tech HQs.
Multi-country groups, development finance institutions, regional regulators.
Our deepest single-sector depth is physical commodity trading, energy and structured finance — crude grades and differentials, cargo operations and laytime, prepayment and borrowing-base facilities, letter-of-credit document checks.
Each is a bounded piece of work with a duration, not an open-ended advisory relationship.
Where AI can safely go in your business, what your data and licences permit, and what to build first. Ends with a costed, sequenced plan.
Discuss this engagement →Function-specific sessions where each person builds a working tool on their own real files and leaves able to use it without us.
Discuss this engagement →Find the AI your organisation is already using, assess what it’s touching, and decide what to sanction, secure, or shut down.
Discuss this engagement →A half-day closed-door session bringing the board to a working understanding of AI risk, oversight, and the questions to ask management.
Discuss this engagement →Defensible policies for staff use of generative AI, third-party models and customer data. Deployable, not aspirational.
Discuss this engagement →Independent review of an AI system already in production — data flows, residency, vendor terms, approval boundaries, evaluation coverage.
Discuss this engagement →Structured assessment against Nigeria’s Data Protection Act, ending with a remediation roadmap your board can sign off.
Discuss this engagement →Independent benchmark against a jurisdiction-relevant framework, with a prioritised roadmap.
Discuss this engagement →Stand up a credible DPO function — charter, RoPA, breach playbook, board reporting, training plan.
Discuss this engagement →Get audit-ready: scope, gap analysis, control build, evidence library, auditor introduction.
Discuss this engagement →A scenario-driven executive simulation — ransomware, data breach, third-party compromise — with a written after-action report.
Discuss this engagement →Design or refine an academy, curriculum or workforce programme for measurable institutional impact.
Discuss this engagement →Twenty years on the assurance side of the table means the systems we build are designed by people who have spent a career finding out how systems like them fail.
Over two decades across Tier-1 banking, regulated trading technology, and one of South-East Asia’s largest digital platforms.
Sustained engagement with African regulators, media and ecosystem builders, including CNBC Africa, SABC, and the Cyber Security Indaba in Johannesburg.
Equally comfortable presenting to a board and writing the policy, or the system, that sits beneath it.
No acronym walls, no fear-selling, and a straight answer when the answer is that you shouldn’t build it.
We work with trusted local partners rather than parachuting in.
Whether you’re putting AI into a regulated business for the first time, entering Nigeria, preparing for a regulator engagement, scaling an AI product across the continent, or building national capability — we’d welcome the conversation.