TwoAeon

AI Governance & Implementation Audit

We audit what your AI systemsactually do.

Not what your policy says they do. Not what your vendor claims they do. We read the implementation — the code, the configuration, the data flows — and tell you where reality diverges from intent.

Ten years of technical consulting practice. Independent from all software and platform vendors.

10+

Years of practice

4

Core service tiers

0

Vendor relationships

100%

Written disclosure

What we do

Four service engagements. No platform, no lock-in.

Each engagement is scoped in writing before it starts. What was assessed and what wasn't is stated explicitly in the engagement letter.

S1

AI Implementation & Behaviour Audit

€10,000 – €25,0004-week engagement

We review what your AI systems actually do: what data they touch, what decisions they inform, and whether that matches what your documentation, your vendors, and your internal policy say. We look at code and configuration — not just interviews.

What you get

  • Written findings report with evidence and risk classification
  • Executive summary suitable for board or leadership
  • Scoped engagement letter stating exactly what was and wasn't assessed
  • No software to install, no ongoing system access required
EU AI Act · GDPRCEO / CTO / DPO
S2

AI Control & Exposure Assessment

€12,000 – €22,0003-week engagement

We trace decision paths: where AI outputs go, who acts on them, and what the blast radius of a failure or manipulation looks like. Impact scoring is qualitative and explainable — not model-driven. Output is a risk-ranked map with specific, prioritised remediation steps, not a maturity score.

What you get

  • Decision-path diagram per AI system in scope
  • Impact matrix: financial, legal, and operational exposure
  • Prioritised list of missing controls or human-approval gaps
  • Recommendations for where kill-switches or escalation paths must exist
EU AI Act (high-risk) · ISO 31000CEO / Board / CISO
S3

Employee AI Usage Governance

€15,000 – €40,000 / yearOngoing retainer

Most organisations don't know what AI tools their people are actually using. We build an accurate inventory — including shadow usage — provide a clear policy framework, and set up visibility without surveillance. We use progressive controls: observe first, then steer, then enforce.

What you get

  • AI usage inventory at organisational level
  • Policy framework with evidence of current usage
  • DNS, identity, and network-level visibility design (no spyware)
  • Monthly governance report against established baseline
EU AI Act · GDPR · ISO 27001 / SOC 2CISO / Legal / HR
S4

AI Security & Data Sovereignty Review

€15,000 – €30,0003-week engagement

We review your vendor DPAs, data flows, and architecture to identify where your data goes and whether it meets your GDPR, NIS2, or contractual obligations. No scanning, no traffic inspection — methodical reasoning from documentation and system architecture.

What you get

  • End-to-end AI data-flow diagram per system in scope
  • Data sovereignty matrix: jurisdiction, vendor access, leakage risk
  • Enforceable data-boundary definitions (cloud vs. on-site criteria)
  • Written gap analysis against applicable regulation
GDPR · NIS2 · ISO 27001Legal / DPO / CISO

AI Orchestration Oversight Retainer

Continuous drift monitoring — vendor changes, regulatory updates, model changes — reviewed monthly against your original baseline.

€2,000 – €5,000 / month

How we work

Method, not software.

Our methodology produces a written, evidence-based assessment. There is nothing to install, no persistent access to your systems, and no vendor lock-in of any kind. The output is a document you own.

Typical engagement

Four weeks from kick-off to delivered report. Continuous monitoring runs on a fixed calendar cadence set at engagement close.

01

Discovery

Structured interviews with the teams actually using AI, plus a review of vendor contracts, data processing agreements, and existing tooling — official and shadow. We do not require system access at this stage.

02

Implementation mapping

We trace what AI systems actually do: what data they touch, what decisions they inform, and who acts on their output. Where the scope permits, we read the code and configuration directly — not just vendor documentation.

03

Risk & gap findings

A written, evidence-based report classifying each finding by likelihood and operational impact, with specific, prioritised recommendations. Every finding is cross-referenced against interview statements so you can see where stated policy and actual implementation diverge.

04

Continuous monitoring (optional)

A fixed-cadence check — monthly or quarterly — for material changes to implementation or behaviour since the last audit. Reported against the original baseline. No ongoing system access is required or held between checks.

Why independent matters

Independence is not a marketing position. It is the basis of the work.

No vendor relationships

We earn no commission, reseller margin, or referral fee from any software or platform vendor. Where your next step involves a governance tool or monitoring platform, we may point to one — but we are never selling it.

No ongoing system access

We hold no persistent access to your systems between engagements. Access granted for an audit is explicitly revoked at engagement close. This is stated in the engagement letter.

Written disclosure on every engagement

The engagement letter states exactly what was and wasn't assessed, what access was granted, and how independence is maintained. Not as a formality — as the basis of the work.

Ten years of practice

TwoAeon has operated as a technical consulting practice since 2014. Our work in AI governance is an extension of that practice — applied to a domain that now warrants dedicated rigour.

“We audit how AI is actually implemented — not how policy says it should be — and, where useful, continue checking on a fixed schedule for when that implementation or its behaviour changes.”

Get in touch

Schedule a conversation.

We start every engagement with a scoping call — no charge, no commitment. You describe the AI systems you want assessed, we explain what we would look at and what we would not, and we agree on scope in writing before any work begins.

Response within two business days
Portugal · EU · Remote

No commitment. Scoping calls are free.