Remediation & environment readiness
Close the gaps the assessment found, then stand up the governance that keeps them closed.
What it is
We close the gaps your readiness assessment found — identity and access, data governance, oversharing controls, security posture — and establish an AI governance framework aligned to ISO 27001 and ISO 42001, so nothing ships into an ungoverned environment. Scope, price and duration all come from your assessment findings, which is why this engagement cannot honestly be quoted before one exists.
Who it is for. Organisations holding a completed readiness assessment with gaps standing between them and a safe deployment.
The steps, in order
The same sequence every time, so you can tell where an engagement is up to without asking. How the phases fit together across a full programme is set out on our approach.
Scope from the findings
The gap analysis becomes a work package with named tasks, named owners and a fixed price, agreed before anything starts.
Fix identity & access
Least-privilege access, joiner-mover-leaver hygiene, and the permission sprawl that quietly turns an AI assistant into a data-leak engine.
Close the oversharing gaps
Classification, retention, and the site-and-file permissions that decide what an assistant is able to see on a user's behalf.
Close the blocking security controls
The controls the assessment flagged as blocking, closed and evidenced rather than promised.
Establish the governance framework
Policy, risk register, model and agent inventory, human-oversight rules and a review cadence — aligned to ISO 27001 and ISO 42001.
Re-score against the benchmark
We re-run the benchmark at the end, so the improvement is measured rather than asserted.
What you walk away with
Named deliverables, handed over as artefacts you own and can use without us.
| Deliverable | What it contains |
|---|---|
| Closed-gap evidence pack | Each blocking gap, what was changed to close it, and the evidence — the artefact your auditor or your board will ask for. |
| Identity & access remediation | Access model, privileged-account handling and review cadence, implemented in your tenancy and documented. |
| Data governance baseline | Classification and retention applied where it matters most, with oversharing exposure reduced and measured. |
| AI governance framework | Policy set, risk register, agent inventory and human-oversight rules, aligned to ISO 27001 and ISO 42001 and written to be maintained by your team. |
| Re-scored readiness result | Your benchmark score before and after, so the money spent has a number attached to it. |
How long it takes, and what it costs
3–6 weeks
Elapsed time from kick-off to handover, assuming your people are available for the sessions the steps above describe.
$35K – $80K Scoped after readiness
The range is wide because the work is defined entirely by what your assessment finds. We quote a fixed price against the gap analysis before any work begins — we will not quote this blind.
All price bands on this site are indicative ranges in AUD, ex-GST. The final fixed price is quoted per engagement once scope is agreed. Software licences (Claude, Microsoft 365 Copilot or another enterprise stack) are client-owned and passed through at vendor pricing — never bundled into our fee.
What it depends on, and what comes next
AI readiness & gap assessment
A completed readiness assessment. Without the gap analysis there is nothing to scope this against, and pricing it blind would be a guess dressed as a quote.
AI readiness & gap assessment →AI deployment & agent build
Deployment and agent build, into an environment that is now safe to deploy into.
AI deployment & agent build →Talk to us about remediation
Already hold a readiness assessment — ours or someone else's? Send us the gap analysis and we will scope the remediation against it.