Sector
AI consultancy for central government
Departments are being asked to adopt AI quickly, and assessed against the NCSC CAF annually. Those two pressures meet at the point where somebody has to explain, in a GovAssure submission, exactly how the AI platform is governed. We build so that the answer already exists.
The constraint
Why departmental AI projects stall
A department can usually get a pilot funded. What it struggles to get is a route into production, because production means the platform enters scope for GovAssure, for Secure by Design, possibly for the Algorithmic Transparency Recording Standard, and for a senior information risk owner who has to put their name to it.
GovAssure is the sharp end. Departments are assessed against the NCSC Cyber Assessment Framework, and an AI platform stood up outside the normal architecture process arrives as an unassessed system: no contributing-outcome commentary, no asset ownership, no detection coverage. That is a finding waiting to be written.
Secure by Design changed the timing rather than the bar. Security has to be evidenced continuously through delivery, by the delivery team, instead of assembled for a gate at the end. Departments that treat AI as an exception to that rediscover it at the least convenient possible moment.
And the data is the whole point. The material that would make a departmental assistant genuinely useful is casework, correspondence, policy in draft and citizen records, which is exactly the material that cannot be posted to a commercial API on a shared tenancy.
Where it works
What actually earns its place here
Ordered roughly by how quickly they get approved. The first item on this list is usually the right first project, precisely because it is the least contentious.
Policy and guidance retrieval
Staff querying departmental policy, guidance and operational instruction with citation, so the answer is consistent regardless of who is asked and which version they remember.
Correspondence, PQ and FOI support
Locating relevant material across systems and drafting first-pass responses for official review. High volume, well-defined, and measurable against what the team already produces.
Casework triage and summarisation
Classification, routing and summarising of inbound casework, surfacing urgency and vulnerability indicators for a human to decide on rather than deciding for them.
Legacy records and document processing
Extraction and structuring from scanned records, submitted forms and legacy document stores, reducing rekeying and the error rate it carries with it.
The gate
What your assurance function will ask for
We build so that this evidence is a by-product of delivery rather than a document assembled under pressure afterwards. It is markedly cheaper that way, and considerably more likely to be accurate.
- NCSC CAF contributing-outcome commentary for the AI platform, ready for GovAssure
- Secure by Design artefacts produced through delivery rather than retrofitted at a gate
- ATRS record drafted alongside the build where the tool affects decisions about the public
- DPIA and equality impact assessment completed before processing begins
- DISA STIG and CIS Level 2 build evidence, with justified deviations
- Data flow and residency documentation naming every processor and every location
- A risk position written in the department’s own language, for the SIRO rather than for us
Questions from this sector
How does an AI platform fit into GovAssure?
As a system in scope, like any other. The practical work is producing contributing-outcome commentary against the CAF for the platform specifically: who owns it, what the asset inventory looks like, how identity and access are managed, what is logged and monitored, and what happens during an incident. Done during the build it costs very little. Reconstructed for a submission it costs a great deal, and it tends to expose gaps at exactly the point they are most expensive to close.
Can we use a hyperscaler UK region instead of on-premise?
Often, yes, and we will say so when it is the right answer. Dedicated capacity in a UK region resolves most departmental workloads at a fraction of the operational burden. On-premise becomes correct when the classification, the network position or the sustainment model genuinely require it, which is a smaller set of cases than the market implies and a larger one than a cloud-first policy tends to assume.
Do we have to publish an ATRS record?
The Algorithmic Transparency Recording Standard applies to algorithmic tools used by public sector organisations that affect decisions about members of the public, with scope guidance from the Central Digital and Data Office. Our advice is to draft the record during the build regardless of the conclusion you reach on publication: the exercise surfaces gaps in oversight and data documentation while they are still cheap to fix.
Can you work through an existing framework?
Yes. Tell us your route to market, including framework options and direct award thresholds where they apply, and we will work with your commercial colleagues on the compliant path rather than steering you toward whichever route happens to suit us.
Start with a straight answer
A 30-minute call, no pitch deck. Tell us what you are trying to do and we will tell you whether AI is the right tool, what it would take, and what it would cost, or that you should not bother.