THE BUYER'S FIELD GUIDE

AI Governance Consulting & Assurance Services

Human-delivered engagements rather than software: AI governance consulting, implementation, algorithmic audit and assurance, conformity assessment and certification, and training or certification programs.

16 related offerings · 16 primary listings · 0 overlapping listings

Product research snapshot September 6, 2026 · Editorial guide September 7, 2026 · Published by DutyGraph

When to explore this layer

Consider an external engagement when the organization needs specialist review, implementation help or a repeatable operating process. Define the question the engagement must answer before asking for a broad AI governance program. Separate advisory work, implementation, training and independent assurance in the scope.

ILLUSTRATIVE EVALUATION · NOT A CUSTOMER RESULT

Put a real task in the demonstration.

A fictional company wants to review one department's proposed agents. Ask a provider to scope interviews, work mapping, technical tests, decision workshops and the final handoff. Specify which outputs the internal owner receives and which unresolved questions remain their responsibility after the engagement ends.

Questions to bring to the demonstration

  1. What concrete deliverables and acceptance criteria are included, and what is out of scope?
  2. Which claims rely on interviews, documents, technical testing or independent assessment?
  3. Who performs the work, and how are relevant experience and independence demonstrated?
  4. What training, update process and reusable records remain with the client?

Evidence to request

  • A scoped statement of work and sample deliverable
  • A methodology with evidence requirements
  • A client handoff plan with named responsibilities

Record what was demonstrated, what was only described, and what remains unknown. Preserve the product version, environment and date beside each observation.

Use the editable Markdown worksheet →

Where this layer stops

An advisory engagement is not automatically an audit or certification. Verify any claimed accreditation and its exact scope directly with the relevant body. A software license and a human-delivered engagement should be compared as different offerings.

Connect it to the work

DutyGraph is designed for advisors to gather work evidence and guide a client through discovery. Its pilot is intended to test that delivery method; it does not confer a professional credential or substitute for independent assurance.

Read our perspective on the demand side of agents →

16 offerings to investigate

Alphabetical, not ranked. Membership includes primary and secondary research categories. These products have different scopes; inspect the evidence profile before comparing capabilities.

Primary category

BABL AI audits and AI & Algorithm Auditor Certification

Boutique firm offering independent third-party AI audits and responsible AI consulting, plus a five-course AI and Algorithm Auditor Certification for practitioners ending in a capstone and exit exam. The firm states its audits follow assurance-engagement style practice but names no accrediting body for either the audits or the credential.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how a BABL independent third-party audit engagement is scoped and what assurance wording appears in the final report you issue to a client's stakeholders.

Read sources and limitations →

Primary category

BSI ISO/IEC 42001 certification

Third-party certification of an organisation's AI management system against ISO/IEC 42001, offered by BSI alongside pre-certification gap assessment and training. BSI states it holds UKAS, RvA and ANAB accreditation for this scheme. Certification covers management-system conformity, not the performance or safety of individual AI models.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the audit stages, sampling approach and evidence you require to certify an AI management system covering generative AI agents in production.

Read sources and limitations →

Primary category

CSA STAR for AI

Cloud Security Alliance assurance program extending its STAR registry to AI services, with a Level 1 self-assessment against the AI Controls Matrix questionnaire, an automated validation option, and a Level 2 tier referencing third-party certification. Registry-based transparency for AI providers rather than a regulatory conformity assessment.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a completed AI-CAIQ submission for an agent platform and what the Valid-AI-ted scoring adds over a plain Level 1 self-assessment.

Read sources and limitations →

Primary category

Deloitte Algorithm Assurance

Named specialist assurance offering from Deloitte member firms that reviews client algorithms and the controls around them: definition, identification, classification, assessment, code review, stress testing, and monitoring. Aimed at audit committees and risk functions. Pages describe activities and objectives without naming an assurance standard or reporting format.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how you classify an inventory of production algorithms and what your third-party code review report on one high-risk model actually concludes.

Read sources and limitations →

Primary category

Deloitte Trustworthy AI

Deloitte US consulting practice organised around a Trustworthy AI framework, sold as named workstreams covering AI strategy, risk management and governance, regulatory support, model risk management, and AI audit and assurance. The public pages describe offerings and control activities but publish no methodology, deliverable list, or fee information.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the audit-ready evidence package your AI Risk Management and Governance engagement produces for a single high-impact agentic use case, from use-case tiering through monitoring KPIs.

Read sources and limitations →

Primary category

DNV ISO/IEC 42001 certification and AI assurance

DNV offers third-party certification of AI management systems to ISO/IEC 42001 plus an AI vendor capability assessment delivered as an independent third-party audit of an organisation's ability to develop and operate trustworthy AI and data-driven solutions. Neither page names an accreditation body for the AI scheme.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the topic-by-topic findings structure of an AI vendor capability assessment and how it differs from an ISO/IEC 42001 certification audit.

Read sources and limitations →

Primary category

EY Responsible AI services

EY advisory offering combining a Responsible AI framework, a GenAI governance framework, and a Responsible AI Readiness Assessment that scores an organisation's readiness to manage AI risk and coming regulation across six categories, plus stakeholder training. Public pages give category names but not the underlying scoring model.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate the Responsible AI Readiness Assessment on one business unit and show the six-category scoring and the gap remediation plan it produces.

Read sources and limitations →

Primary category

Holistic AI AI Audits

Independent AI audit engagements from Holistic AI covering bias, privacy, efficacy, robustness and explainability, plus regulation-specific assessments and a separate independent audit service for Digital Services Act due-diligence obligations. Audits produce reports and mitigation strategies; no accreditation or certification mark is claimed on the pages reviewed.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me an anonymised AI audit report structure and the specific tests you ran for bias and robustness on a deployed decisioning model.

Read sources and limitations →

Primary category

IAPP Artificial Intelligence Governance Professional (AIGP)

Professional certification and matching online training from the IAPP that tests competency in AI development concepts, AI law and policy, and responsible AI governance and risk management. Individuals sit an exam against a published body of knowledge; the credential covers individual competency, not any organisation's AI system conformity.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the current AIGP body of knowledge and exam blueprint and how the training maps to EU AI Act obligations we must operationalise.

Read sources and limitations →

Primary category

Infosys Topaz Responsible AI Suite

Infosys implementation and advisory suite of more than ten offerings arranged as Scan, Shield and Steer, including regulatory watchtower monitoring, maturity and risk assessments, a responsible AI audit offering, and a control centre for compliance telemetry. Delivered as consulting plus proprietary assets; component depth is not documented publicly.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate the Responsible AI Control Center on a live AI portfolio: which compliance signals it ingests and what a violation alert looks like end to end.

Read sources and limitations →

Primary category

JDLA C認証 (AI Governance Core Certification)

Japanese third-party certification scheme run by the Japan Deep Learning Association that reviews an organisation's AI governance structures and operations at legal-entity level, valid two years, with JDLA-accredited consulting firms supporting readiness separately from the review. It certifies governance arrangements, not individual AI tools or systems.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the C認証 review criteria and the evidence a Japanese subsidiary must submit to demonstrate AI inventory and risk assessment practices.

Read sources and limitations →

Primary category

KPMG AI Trust services

KPMG's multi-disciplinary AI governance service suite built on its Trusted AI framework, spanning AI risk assessment, AI systems inventory, governance and policy implementation, AI security and privacy, system cards, and an AI Assurance line offering model validation and independent attestation against defined frameworks such as SOC and HITRUST.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me an AI assurance and attestation engagement scope for an agentic workflow, including which framework you attest against and what the resulting report covers.

Read sources and limitations →

Primary category

ORCAA Algorithmic Audit

ORCAA sells algorithmic audits that assess risks of a specific algorithmic use case using its Ethical Matrix framework, plus quantitative bias testing for regulatory compliance such as New York City Local Law 144 bias audits, AI governance consultation, and metric 'cockpit' design. Deliverables are reports, not certifications.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me how the Ethical Matrix is populated for one hiring algorithm and what a Local Law 144 bias audit report you issued contains.

Read sources and limitations →

Primary category

PwC Responsible AI Toolkit

PwC advisory offering delivered as customisable frameworks, tools and processes for enterprise AI governance: role and responsibility design across three lines of defence, regulatory monitoring, policy development, bias and fairness assessment, and a free entry-level Responsible AI Diagnostic. Pages do not disclose tooling detail or pricing.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me how the Responsible AI Diagnostic output maps to a concrete governance remediation roadmap with three-lines-of-defence ownership.

Read sources and limitations →

Primary category

Resaro Approved Intelligence

Independent AI assurance firm running testing, evaluation, validation and verification workflows in the client's own environment via its Approved Intelligence Platform, producing structured deployment evidence and continuous post-deployment evaluation for civil and defence uses. Marketed as evidence for deployment decisions rather than as certification against a standard.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a TEVV run in our environment for one mission-critical model and show the evidence pack a deployment authority receives.

Read sources and limitations →

Primary category

TÜV SÜD ISO/IEC 42001 certification

TÜV SÜD audits and certifies AI management systems against ISO/IEC 42001, including risk-focused assessments of bias, privacy and security controls and optional integrated audits combining several management-system standards. The pages reviewed name no accreditation body for the AI scheme, so accreditation status could not be confirmed.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how an integrated ISO/IEC 42001 and ISO/IEC 27001 audit is planned for one AI platform, and what nonconformities you have typically raised on AI risk assessment.

Read sources and limitations →

About this guide

The evaluation questions and fictional scenario are DutyGraph's editorial guidance. Product listings use the supplied source-linked research snapshot. We have not independently tested these offerings. Listing is not an endorsement, certification or working integration.

Read the directory methodology · Suggest a correction