Fixed-Fee AI Security Assessment: What to Expect

Jason Holloway
AI Security Gap Analysis AI Security Assessment AI Risk Gap Analysis AI Governance

A fixed-fee AI security assessment is a defined piece of work with a defined price: we agree the scope, quote a single fee and deliver a board-ready report within three to four weeks. No day rates, no scope creep, no invoice that arrives larger than the estimate. If you are ready to commission an assessment now, you can commission an AI Security Gap Analysis and we will scope it with you on a single call.

This post answers the four questions buyers actually ask us: what does the assessment cover, how long does it take, what do you receive at the end and what does it cost. If you are still working out whether you need one, our post on rolling out AI tools without a security review is the better starting point.

Why fixed fee matters more than the fee itself

Most mid-market organisations are not hesitant about spending money on AI Security. They are hesitant about commissioning open-ended consulting work with no visible end point.

Time-and-materials engagements transfer all the scope risk to the buyer. The consultancy discovers more work, the work expands and the CFO who approved a number in March is signing off a different number in June. That experience, once had, makes the next assessment far harder to approve internally.

A fixed fee inverts that. We carry the scope risk. If the work takes longer than we estimated, that is our problem to absorb, which gives us a strong incentive to scope accurately rather than optimistically. For the CEO, it means a proposal that can go to the board as a single line. For the CFO, it means a purchase order with a number on it that will not move.

What does the assessment cover?

The assessment covers four areas. Each one produces a specific output that feeds the next.

AI tool inventory. We establish what AI is actually in use across the organisation, including the tools nobody formally approved. This means reviewing procurement records, licence and expenditure data, browser and network telemetry where available and structured conversations with department leads. The inventory almost always contains surprises. In our experience the gap between the sanctioned list and the real list is the single most useful finding of the whole exercise.

Risk classification. Not every AI tool carries equivalent risk. A transcription tool processing internal meeting notes sits in a different category from a model that touches patient data, case files or financial records. We classify each identified use case by the sensitivity of the data it handles, the degree of autonomy it holds and the consequence of a failure. That classification is what allows the remediation work to be sequenced sensibly rather than alphabetically.

Control gap analysis. We compare the controls you currently have against the controls the classified risks require, referencing the frameworks that apply to your sector. For most organisations that means ISO 42001, the NIST AI Risk Management Framework, the OWASP LLM Top 10 and the relevant UK regulatory expectations, including ICO guidance on automated processing. The output is a plain list of what is missing, not a compliance score.

Prioritised remediation roadmap. The gap list is then sequenced into a roadmap: what to fix in the next thirty days, what belongs in the next quarter and what is a twelve-month programme item. Each item carries an owner, an indicative effort estimate and a stated reason for its position in the sequence.

How long does it take?

Three to four weeks from kick-off to final report for a typical mid-sized organisation. Week one is discovery and inventory work. Weeks two and three cover classification and gap analysis, with a mid-point checkpoint so nothing in the final report arrives as a surprise. Week four is drafting, review and presentation.

The internal time commitment is deliberately small. We ask for one nominated coordinator who can open doors, a two-hour kick-off session, six to eight interviews of thirty to forty-five minutes with department leads and IT, and access to procurement and licence records. Beyond that, your teams carry on with their work. Assessments that demand weeks of internal effort tend to stall. A stalled assessment is worth nothing.

What do I receive at the end?

A single assessment report, written to be read by a board rather than interpreted by a security specialist. It contains:

  • An executive summary of two to three pages, stating the current position, the three most material risks and the recommended immediate actions
  • The full AI tool inventory, with ownership and data-handling notes for each entry
  • The risk classification, showing how each use case was assessed and why
  • The control gap analysis, mapped against the frameworks relevant to your sector
  • The prioritised remediation roadmap, with owners, effort estimates and sequencing rationale

You also receive a presentation of the findings to your board or executive team and the underlying inventory in a format your own people can maintain afterwards. No technical appendix needs translating, because the report itself is written for the people who will act on it.

What happens after the assessment is a separate decision. Some organisations execute the roadmap internally. Others need ongoing governance capacity, and whether that is built in-house or brought in is a question the roadmap will help you answer.

Common questions before commissioning

What does an AI security assessment cost in the UK?

We quote a fixed fee once scope is agreed, and the fee is driven by organisational size, the number of business units in scope and the regulatory frameworks that apply. Scoping happens on a single call at no cost, and you receive the number before you commit to anything. We do not publish a rate card because a rate card would misprice most organisations.

Do we need to pause our AI rollout while the assessment runs?

No. The assessment observes the current state rather than freezing it. If we identify something during discovery that requires immediate attention, we raise it with you that week rather than holding it for the final report.

Who needs to be involved from our side?

One nominated coordinator, plus thirty to forty-five minutes each from IT, information governance and the leads of any department using AI tools. The CEO or CFO is typically involved at kick-off and at the closing presentation, not in between.

What if we already know some of our gaps?

That is common and it shortens nothing, because the value is in the completeness of the picture and the defensibility of the prioritisation. Known gaps still need classifying and sequencing against the ones you have not found yet.

Commission an assessment

If you have AI tools in use and no documented view of the risk they carry, an assessment is the shortest route to a defensible position. Scope, fee and timeline are agreed before any work begins.

Commission an assessment with a fixed price

Scope, fee and timeline are agreed before any work begins. You receive a board-ready report in three to four weeks.