VIRTICUSRequest Assessment

Virticus Advisory

Can you defend your AI decisions?

We identify how your business uses AI, where decisions become hard to justify, and what practical controls are needed so the business can answer confidently when those decisions are questioned.

Our Approach

Risk first. Consequence second. Solution third.

We do not start with generic compliance language or oversized frameworks. We start with where AI is affecting decisions and what would happen if those decisions were challenged.

The output is practical: what the risk is, why it matters commercially, and what controls make the business more defensible.

Advisory Structure

Assurance

High risk

Independent validation, defensibility review, and litigation support

Governance

Medium risk

Defined controls, registers, ownership, and oversight

Compliance

All risk levels

Foundational control baseline for ongoing AI use

Proportionate by design

Each layer is added only when the risk, consequence, and decision pressure justify it.

Assessment

How we determine what you need

Step 1

What you use AI for

Internal useLower risk
Operational supportModerate risk
Decisions affecting peopleHigher risk

Step 2

Your business context

Micro / smallSimple implementation
MediumStructured controls
LargeFormal integration

Step 3

What you receive

Low risk

Compliance

Medium risk

Compliance + Governance

High risk

Compliance + Governance + Assurance

We adjust the depth based on your business size and complexity.

By Business Type

Structured for your size

The scope of what we do and what you receive is calibrated to your business.

01

Micro Businesses

Scope

  • Identify AI use
  • Highlight immediate risks
  • Provide simple rules

Output

  • Usage summary
  • Basic risk note
  • Short policy
  • 3–5 actions

02

Small Businesses

Scope

  • Map AI across operations
  • Assess customer impact
  • Identify gaps

Output

  • AI register
  • Risk summary
  • Short policy
  • Action plan

03

Medium Businesses

Scope

  • Structured audit
  • Review decision-making and data
  • Define controls

Output

  • System register
  • Risk register
  • Defined controls
  • Governance elements

04

Corporates

Scope

  • Support internal teams
  • Review systems and decisions
  • Provide independent analysis

Output

  • Audit reports
  • Control validation
  • Expert review
  • Litigation support

Differentiators

Focused and proportionate

Only what is required for your business, your risk, and your legal exposure.

No unnecessary frameworks

We work from your actual AI use and legal exposure — not from a pre-built template applied regardless of context.

No generic templates

Each engagement is scoped to your business. The output reflects what you need, not a standard document.

No over-engineering

Smaller businesses receive simple, actionable outputs. Complexity is added only where your risk level requires it.

Get started

Start with an Exposure Check

Answer a short set of questions about your AI use. We will identify your risk level and provide a clear picture of what is required.