Find out exactly where your AI is exposed. In five days.
The Rapid AI Security & Governance Assessment: one fixed week, benchmarked against the standards that matter, ending in an executive report your board can act on. Five days in. Five deliverables out.
Your team is already using AI. The question is what else is.
The AI tools your employees use that never went through IT — and what customer data is going into them right now.
The agent someone connected to your systems with more permissions than any staff member would ever get.
The one prompt-injection trick that turns a helpful chatbot into a data leak — and why most businesses can't detect it happening.
The question a regulator, insurer, or enterprise customer will ask about your AI — that most businesses can't answer today.
You can't secure what you can't see.
AI adoption in most businesses didn't arrive through a project plan. It arrived through a hundred small decisions — a Copilot licence here, a ChatGPT tab there, an agent wired up over a weekend because it was useful. Each one made sense. Nobody was mapping the whole.
Now sensitive data flows into models nobody inventoried, through prompts nobody logs, into outputs nobody reviews. If something went wrong yesterday, would anyone know today? Who would even own the incident?
The uncomfortable part: this isn't a future risk. It's a current unknown. And enterprise customers, insurers, and regulators are starting to ask the questions.
A six-month security programme is the wrong first answer. A clear map of where you actually stand — that's the first answer.
One week. A defensible answer.
Unlike a certification audit that takes months and tells you what you failed, the Rapid AI Security & Governance Assessment is a fixed five-day timebox that tells you where you stand, what matters most, and what to do next — in plain English, prioritized, with owners.
Day 1 — Discovery and AI inventory
Stakeholder interviews. Every AI system, agent, copilot, and shadow tool — mapped, with the data flowing into each.
Output: your AI system and use-case inventory
Day 2 — Governance gap assessment
Benchmarked against ISO/IEC 42001, ISO/IEC 23894, ISO/IEC 27001/27002, and NIST AI RMF — focused, not clause-by-clause.
Output: maturity rating across ten focus areas
Day 3 — Technical threat assessment
Threat modelling on your one or two highest-risk AI systems, using OWASP GenAI as the baseline — prompt injection, data poisoning, excessive permissions, insecure RAG.
Output: threat model and prioritized findings
Day 4 — Risk workshop and remediation design
Likelihood, impact, owners, containment — agreed with your team, not handed down.
Output: AI risk register and control baseline
Day 5 — Executive readout and roadmap
Findings presented to your security, technology, and business leaders — quick wins, 30–90 day actions, and long-term goals.
Output: executive report and prioritized roadmap
From “we think we're fine” to “here's where we stand.”
You can answer the question.
When a customer, insurer, or board member asks “is your AI secure?”, you have a benchmarked, framework-backed answer — not a guess.
You know what to fix first.
Every finding lands in one of three buckets: quick wins now, actions in 30–90 days, goals beyond. No 200-page report that nobody opens twice.
You stop paying the uncertainty tax.
Shadow AI gets inventoried, risky permissions get named, and your team knows the rules — so AI adoption speeds up instead of stalling in fear.
You're ready for what's next.
The roadmap includes the path to ISO/IEC 42001 readiness — when and if you need it.
The person in the room has done this before.
This isn't a junior consultant with a template. Your week is led by someone who has run AI security at the scale where getting it wrong makes the news.

Matt Duckworth
Senior AI Security Consultant, Prime Amigos
- Former Regional AI Security Lead for Asia at MetLife, based in Sydney
- 20+ years leading enterprise cybersecurity strategy, cyber governance, operational resilience, and identity & access governance (IAM/PAM) across highly regulated financial services and enterprise environments throughout APAC
- Proven expertise in APRA CPS 234 and CPS 230 compliance, AI governance, cloud security, and enterprise risk management
- Known for strengthening cyber maturity, modernizing security operating models, and aligning security strategy with business enablement — not blocking it
Five deliverables. Yours to keep.
AI System Inventory
Every AI use case, owner, provider, data flow, and risk classification — including the shadow AI.
Rapid Maturity Assessment
Where you stand across ten focus areas, rated from “not established” to “operating effectively.”
Technical Threat Model
OWASP-based threat assessment of your one or two highest-risk AI systems.
AI Risk Register
Identified risks with severity, existing controls, owners, and recommended treatment.
Prioritized Roadmap
Quick wins, 30–90 day actions, and long-term goals — with effort estimates and accountable teams.
The no-risk first step
The 30-minute consultation is free, and it's a two-way fit check: we'll tell you honestly whether this assessment is the right move for you — including when it isn't. Fixed timebox, fixed scope, five named deliverables. You know exactly what you're getting before you commit to anything.
This is for you if…
- Your business already uses AI — copilots, chatbots, agents, or fifty employees quietly using public tools
- You need a defensible answer for customers, insurers, a board, or a regulator
- You want priorities and owners, not a compliance doorstop
This is not…
- An ISO/IEC 42001 certification audit (we'll map the path if you want one later)
- A penetration test of every system or a source-code review
- A months-long engagement that bills by the ambiguity
The AI Security Blind-Spot Checklist
Not ready for the full assessment? Start with the 15-minute self-check. Ten questions drawn from the same framework areas we assess — so you can see where the gaps are hiding before anyone else finds them.
- The 10 AI security gaps most common in growing businesses — and how to spot each in your own
- The three questions to ask about any AI tool before your data goes into it
- A one-page scorecard you can fill in and share with your leadership team
Get the checklist
Questions worth asking.
How much of our team's time does the week take?+
Stakeholder interviews on Day 1, a threat-modelling workshop on Day 3, a risk workshop on Day 4, and the executive readout on Day 5. For most people involved it's a few focused hours, not a blocked week.
We only have a couple of AI tools. Is this overkill?+
The assessment scales to what you actually have — and in our experience the inventory on Day 1 finds more AI in use than anyone expected. That finding alone is usually worth the week.
Is this an ISO/IEC 42001 certification?+
No, and we say so upfront. It's a rapid assessment benchmarked against ISO/IEC 42001, ISO/IEC 23894, NIST AI RMF, and OWASP guidance. If certification is your goal, the roadmap includes the readiness path.
What happens after the week?+
The roadmap is yours to run — your team, ours, or a mix. Implementation is deliberately out of scope so the assessment stays independent: we have no incentive to inflate findings.
Can it be done remotely?+
Yes. On-site, remote, or hybrid across Hong Kong and Australia time zones.
Every week unassessed is a week unknown.
The shadow AI is already in the building. The only question is whether you find the gaps first — or someone else does. Start with 30 free minutes.