Security & Assurance

AI you can defend.

Deploying AI into high-stakes work means proving it is safe to rely on. With us, security and governance are built into the AI, not bolted on after. These controls support client engagements and AI deployments delivered by Work Transformers.

The principle
Clever is easy. Defensible is the work.

A partner signing a recommendation, an investment committee approving a deal, a board reviewing a decision: none can rely on output they cannot trace or explain. So the engineering that matters is not the model. It is the harness around it.

Guardrails that hold

Boundaries on what the AI will and will not do, enforced rather than hoped for.

Verification

Checks that catch what is wrong before it reaches a person, with every figure traced to its source.

Human checkpoints

A named person accountable for each material decision. AI prepares; a person decides.

The research behind this: Project Thunderpoint™ →
Security
Your data stays yours.

Separated environments

Client work is kept in its own environment, isolated from others, with access controlled and logged.

Least privilege

Systems and people see only what they need. Confidential material is never exposed to public tools without consent and a risk check.

An audit trail

Decisions, inputs and reviews are recorded, so what happened can be produced on demand.

For RICS-regulated firms
The RICS AI Standard, handled.

Since March 2026, every RICS-regulated firm using AI has had to govern it to a published standard. Most of the firms we work with are in scope. We have read the Standard end to end and we build to it, so the AI we deploy is governed from day one, not retrofitted under audit.

Read the plain-English guide
What good looks like
The records a serious firm should hold.

Governance reads as a system: a few policies that set your position, and living records that prove you follow them. When we deploy, these come with it.

Policy

An AI use policy, risk appetite, and clear roles and accountabilities.

Registers

A register of AI systems with materiality reasoning, and a risk register reviewed on a regular cadence.

Evidence

A reliability decision signed per material output, disclosure and explainability records, and a versioned audit trail.

Start here

Deploy AI you can stand behind.

Talk to us about governing the AI you already use, or check where your firm stands before you commit to anything.