Advisory — fixed scope, defined deliverables, fixed price
Advisory for teams that need answers on a deadline — not an open-ended engagement.
Every engagement starts with a complimentary consultation. Before any work begins, you receive a defined scope, deliverables, timeline, and fixed price. Nothing gets installed and nothing connects to your environment.
Engagements
Three ways to engage.
10 working days
EU AI Act Readiness Review
A fixed-scope assessment mapping your agentic-AI use against the EU AI Act obligations and implementation dates that apply to your role and use case. You receive a prioritized gap list with owners and sequencing — a bounded deliverable, not a compliance guarantee.
Best when implementation dates are on your calendar.
30 working days
Remediation Sprint
Takes a completed diagnostic (ours or yours) and works the highest-severity findings to closure: tightened permissions, review paths, evidence trails, and control ownership — with verification of what actually changed.
Best after a Shadow Audit or internal review.
Half-day or full-day
Executive Briefings
A closed-door session for boards, risk committees, or leadership teams: the current agentic-AI risk landscape, the regulatory trajectory, and what it means for your institution — grounded in our maintained evidence graph.
Best before budget or policy decisions.
Independent Third-Party Evaluation & RFP Advisory
Buyer-side assessment of AI vendors, agentic platforms, and proposed architectures — commissioned by the institution, not the seller. Includes evaluation frameworks mapped to the AgentRisk control taxonomy, structured RFP support, and independent recommendation memos. Available as a fixed-scope engagement or alongside a Shadow Audit.
Practitioner education and certification programs based on the AgentRisk Body of Knowledge are in development with select design partners.
Mitigation network
When findings need a specialist, we can introduce one.
AgentRisk maintains a small network of specialist providers mapped to the risk patterns documented in our intelligence graph. Where a finding calls for implementation work outside our scope, we can make an introduction — and the audit may equally recommend remediation by your own team, an existing provider, or no ongoing engagement at all.
How introductions work
Where AgentRisk introduces a third-party provider, we disclose in advance whether an introduction fee may be paid. Provider relationships are kept separate from our assessment methodology, findings, and risk ratings. Clients are never required to use a referred provider.
Providers interested in the network: partners@agentrisk.io
Start with a conversation, not a contract.
The introductory consultation is complimentary. If we are not the right fit, we will say so.
