Four practice areas, in the order we’d recommend them.
Designed to be commissioned individually — an enablement session, an AI governance gap assessment, a single tabletop exercise — or run in sequence as a programme. Every engagement is senior-led, fixed-fee, and leaves reusable assets your team owns at the end.
AI Enablement & Capability
“Our people aren’t getting anything out of this.”
Your people are already using AI. Most of them are typing five words and hoping. Survey a room of capable professionals and you’ll find a handful prompting deliberately, a majority getting something roughly useful, and almost nobody who has set up persistent context or knows what’s safe to paste. That gap is free capacity sitting on the table.
What we do
- Beyond Search: Using AI as a Practical Work Partner — an 80-minute live session for working professionals and business owners, calibrated against a pre-session survey of the actual room. No code.
- Function-specific enablement programmes — one-to-one sessions where each participant builds a working tool on their own real files and leaves able to use it without us.
- Executive and board AI briefings — closed-door sessions on what AI does, what it doesn’t, and what leaders are now accountable for.
- Follow-up clinics two to three weeks on, because adoption is the risk and not the technology.
- Follow-on curriculum: reusable AI workflows · AI for analysis and decisions · building an AI operating system for your work · automation without coding · agentic coding tools and when they’re worth it.
Typical deliverables
Six-part prompting brief · output-control checklist · each participant’s AI work profile · continuity file template · one reusable work recipe each · verification checklist · written note per function session · end-of-programme summary.
Who this is for
Teams already paying for AI licences and getting nothing back · professional services firms · executives who need to lead on this credibly · organisations where the same three people are the bottleneck on everything.
Enablement is also our discovery instrument. Training people on their live work surfaces in an afternoon what a two-week requirements exercise would only guess at.
AI Build & Automation
“We know what we want. We don’t know how to build it safely.”
Organisations lose time to the same handful of repeating jobs — the report assembled by hand at month-end, the follow-up nobody sent, the customer detail that lives in one person’s phone, the reconciliation that takes three days and one spreadsheet nobody else understands. Those jobs are automatable now. What’s scarce is someone who will be honest about which ones are worth it, and who treats your data like a liability before treating it like an input.
What we do
- Discovery and pain audit — who the business is, where the data is actually trapped, what the system should do, when it should run, and what might stop it. You get a written summary back; it becomes the brief and it’s the first thing we deliver.
- Data classification before design — green, amber, red. Red-tier data sets the architecture before anything is quoted.
- Automation builds — onboarding, invoicing with an approval step, lightweight CRM, morning briefings, document handling, reporting.
- Operating-model transformation for lean, data-heavy firms — platform and access foundations, then module-by-module builds.
- Branded document engines — structured content from the model rendered through version-controlled templates into brand-compliant PDF and Word.
- Concierge pilots — where value is genuinely unproven, we hand-run the workflow and prove the output is worth having before building the pipeline. Sometimes that’s the whole engagement.
- Handover and stewardship — clean transfer to your tenancy, keys rotated, runbooks written during the build, then an optional retainer funding the evaluation discipline.
How it’s priced
Paid discovery ends in firm per-module prices — we don’t quote a build blind. Builds are fixed-fee per module with payment tied to gates: spec signed, working demo on your real data, accepted handover. Tool and model licences are yours, paid direct, so you keep the accounts.
Typical deliverables
Intake summary and pain audit · data classification and handling map · costed per-module delivery plan · the built modules · human-review screens · runbooks and handover pack · evaluation harness.
Who this is for
Lean, data-heavy firms with institutional-grade reporting obligations and no IT function · commodity trading, energy and structured finance · owner-operated firms of two to sixty people · professional services and clinics with confidentiality obligations · anyone whose business currently runs out of WhatsApp and one person’s memory.
Full detail on the AI practice →AI Governance, Assurance & Data Protection
“We already have AI in production and can’t evidence what it’s doing.”
AI is being deployed faster than it is being governed. Shadow AI, ungoverned model use, unclear data lineage, agentic systems acting on behalf of users, and cross-border residency questions are arriving at audit committees without a credible answer in the room. Underneath all of them sits the same older question — what are we allowed to do with this data — now governed by Nigeria’s NDPA, South Africa’s POPIA, Kenya’s DPA, the GDPR, Singapore’s PDPA and a growing patchwork of transfer rules. We treat these as one practice because buyers experience them as one problem.
What we do
- AI governance frameworks aligned to NIST AI RMF, ISO/IEC 42001, the EU AI Act where in scope, and emerging African and Asian guidance.
- AI risk assessments for in-house and third-party model use, and model validation and assurance approach.
- Shadow AI discovery and remediation — finding the AI your organisation is already using.
- Agentic protocol audits (MCP, tool-use, agent-to-agent communication).
- Independent review of AI systems already in production — data flows and residency, vendor terms, retention and training settings, human-approval boundaries, prompt and template hygiene, evaluation coverage, and the failure modes nobody has tested.
- Privacy maturity assessments, NDPA readiness reviews and remediation roadmaps.
- DPO support — fractional arrangements, coaching, and 90-day onboarding for new appointees.
- RoPA design, cross-border transfer assessments, privacy incident playbooks, and privacy-by-design integration into product and engineering.
Typical deliverables
AI governance matrix · shadow AI report · use-case risk taxonomy · data residency flow map · AI and data usage policy pack · AI assurance review report · privacy maturity report · NDPA readiness scorecard · DPO 90-day plan · RoPA template · cross-border transfer assessment · board privacy dashboard · board and C-suite briefing pack · 12–18 month AI governance roadmap.
Who this is for
Boards uncertain how to govern AI · CIOs and CDOs operationalising it · CISOs absorbing AI into the cyber risk taxonomy · DPOs facing AI-driven privacy questions · organisations entering or scaling in African data-protection regimes · multi-jurisdiction firms managing cross-border flows · regulated firms expecting AI-specific supervisory attention.
We build for clients and we assure for others. Where we have built a system, our review of it is a quality gate rather than independent assurance, and we will say so. If you need independence on something we built, we’ll help you scope it elsewhere.
Cyber Resilience & Readiness
“We have an audit, a finding, or an incident.”
Boards and regulators expect a defensible security story: a risk-based strategy, governance with real teeth, controls that are evidenced, and reporting that translates technical posture into business language. Most organisations have fragments. Few have the full picture — and almost none have discovered which parts are aspirational until they were tested for real.
What we do
- Cybersecurity strategy and 18–36 month roadmaps aligned to NIST CSF 2.0, ISO 27001, MAS TRM, the Singapore Cybersecurity Act and equivalent African frameworks.
- SOC 2 Type I and Type II readiness assessments and pre-audit remediation; ISO 27001 ISMS design, scoping and implementation support.
- Cyber maturity assessments benchmarked against peer institutions.
- Second Line of Defence operating model design — RCSA, KRIs, issue and action tracking; security governance, committee charters, RACI, board reporting packs.
- Cyber resilience simulations and ransomware tabletop exercises for executive teams; incident response playbook design and stress-testing.
- Crisis communication protocols including regulator and customer notification; ransomware decision frameworks; post-incident reviews.
- Cyber academy advisory, curriculum design, cyber range requirements, workforce capability mapping and train-the-trainer programmes.
Typical deliverables
Cyber strategy paper · maturity heatmap · SOC 2 readiness gap report · ISMS scope and Statement of Applicability · RCSA workbook · board reporting templates · tabletop design and after-action report · refreshed incident response playbook · crisis communication templates · post-incident review · academy strategy paper · curriculum architecture · cyber range requirements specification · capability map.
Who this is for
CISOs and CIOs building or rebuilding their function · boards needing independent challenge · companies preparing for SOC 2 or ISO 27001 audit · regulated firms responding to a supervisory finding · Critical Information Infrastructure operators · executive teams never exercised under realistic pressure · organisations that have just had an incident and want an independent post-mortem · universities, national skills bodies and development partners building cyber workforce capacity.
Not sure which one you need?
That’s what the first call is for. Tell us what’s actually costing you, and we’ll tell you which of these — if any — is the right lever on it.
