What we do
01  Advanced Infrastructure 02  Applied AI & Data 03  AI Cybersecurity 04  AI Assurance
Engagements
AI estate inventory Assurance review
Industries
Financial Services Government & Public Sector Energy & Utilities Telecommunications Healthcare & Life Sciences Transport & Logistics Industrial & Manufacturing Retail, Hospitality & Real Estate
Research
The Trust Maturity Model The GCC Assurance Index Readiness self-assessment Case studies Perspectives Sector briefings Technology evaluations
Company
About us Partners Events Careers Contact العربية Talk to our team
Applied AI & Data  ·  AI Control

Can you stop it? Have you tried?

Every claim about a system being under control resolves to three things: a limit somebody wrote, a record somebody reads, and a stop somebody has actually pulled. We build all three, and we pull the stop before it matters.

6–10 WEEKSCONTROLS BUILT AND EXERCISEDEVIDENCE AN AUDITOR ACCEPTS
The decisions underneath

Three questions decide the design.

Control is not a document. It is a set of things that either happen at the moment they are needed, or do not.

01

Who set the limit, and when

A limit set once, by somebody who has since left, against a business that has since doubled, is a historical artefact rather than a control.

02

Does anybody read the log

A record nobody reads is a record that exists for the audit. Useful, but not a control — and it should not be counted as one.

03

Has the stop ever been pulled

An untested kill switch is a claim. We exercise it on the running system, in daylight, and write down how long it took.

The ladder

The control has to exist before the rung does.

AI Control is the work of building the limits, the logs and the stop. Choose a rung to see what that means at each level of autonomy.

AUTONOMY— OF 5 RUNGS EARNED
Select a rung

Five levels of autonomy. Each one is a different system with different consequences, and each one has a control that has to exist before you stand on it.

A kill switch nobody has pulled is a claim, not a control. Every stop we build gets exercised before the system carries anything that matters.

What you receive

Controls that have been exercised.

Four stages, every engagement. Hover a stage to see what happens in it.

DURATION
6–10 weeks
DELIVERABLE
Control set, exercise results, evidence pack
DELIVERED
Remotely; exercises witnessed live
INDICATIVE FEE
[FEE BAND — pending sign-off]
The boundary

We build it. We do not grade our own work.

Three moves. Two of them are ours, and the one in the middle is deliberately somebody else’s.

MOVE 01 — OURS

We build and run it

Design, integration and operation of the system, with a named human accountable at every gate that matters. This is delivery work and we do not pretend otherwise.

MOVE 02 — NOT OURS

Somebody else forms the opinion

The assurance opinion on anything we built is not written by the team that built it, and where you need it to carry weight externally, not by Orvix at all. A firm that audits its own delivery is offering you a marketing document.

MOVE 03 — OURS

We remediate what the review found

We fix what the independent review says is wrong, and the fix is re-examined by the same reviewer rather than signed off by us.

This is the same independence test we apply to other people’s vendors. It would be difficult to argue for it and then exempt ourselves.
Applied AI & Data

The rest of this pillar.

Three engagements inside this pillar. Start with the question you can name, or take the whole estate at once.

Questions we are asked

Before you ask us.

Is this the same as AI governance?
They meet, but they are different work. Governance decides what should be true and records the decision; AI Control builds the mechanism that makes it true and produces the evidence that it operated. Governance without control is intention; control without governance is unexplained machinery.
We already have a policy and an approval workflow.
Then the useful question is the approval latency. If approvals are being granted in seconds at volume, the control has been abandoned in practice while continuing to exist on paper — and that is a finding worth having before somebody else makes it.
Do you take over running the controls?
We build them and hand them over with a named owner. Where you want them operated, that is an AI Cybersecurity conversation, and it carries the same rule: we do not write the assurance opinion on something we operate.
What if a system has no controls at all?
That is common and it is not a moral failure — it is what happens when a capability arrives faster than the governance calendar. The first useful output is usually just a complete list.

Start with the stop you have never pulled.

Thirty minutes. Name the system you would find hardest to halt on a Friday afternoon, and we will start there.

Book a 30-minute scoping call

ORVIX · INDEPENDENT AI & TECHNOLOGY ASSURANCE · WE DISCLOSE EVERY COMMERCIAL RELATIONSHIP ON THE PAGE FOR THE SERVICE IT BELONGS TO. WHERE LICENSING IS REQUIRED, DELIVERY IS PERFORMED BY NAMED PARTNERS UNDER THEIR OWN LICENCE.