Codigm · Cambridge, UK
Codigm · Cambridge, UK
Teams slow down when they can't tell which risks are real.
We test whether your AI controls actually work, so you know where you can move fast and where you should slow down.
Position
We don't build the controls we assess. That's what makes the answer worth having.
paul@codigm.co.uk · All engagements under NDA
01 / The argument
Most organisations respond to AI risk by slowing everything down. Every output gets reviewed. Every use case needs approval. Nothing is allowed to run without someone checking it first.
It’s expensive, it’s often applied far too broadly, and it can end up pushing people towards using AI unofficially, exactly what the controls were supposed to prevent.
A better approach is to focus the controls where the actual risk is, rather than applying the same level of caution everywhere.
The problem is that most organisations don’t really know which of their controls are working. And it’s difficult to get an honest answer when the people who designed those controls are the ones being asked to assess them.
An assessment gives you a clearer picture. A scored profile shows where you have enough confidence to let people move quickly, and where the risks genuinely justify more oversight.
Governance is what lets you go fast and still be able to defend how you did it.
These are the failures we find most often. Every one of them is quiet, and every one of them shows up late.
In work produced with AI
In AI products released to customers
Confident, well-formed answers that are wrong, and no measurement of how often
Behaviour changing after a vendor updates a model, with no code change and no test to catch it
Costs that scale in a way nobody modelled until the invoice arrived
A kill switch that exists and has never been operated
No way to reconstruct, six months later, why the system told a customer what it did
Every one of these is preventable. Most are cheap to prevent and expensive to discover.
02 / What we do
Codigm is an independent assurance practice. We assess whether the controls an organisation has put around its AI work actually function.
Governance assurance
Your people use AI assistants and agents to produce software, analysis, specifications and client deliverables. Most organisations have written rules for this. Far fewer have a control that stops the rules being ignored, and almost none have tested the controls they do have. We measure that gap.
Release assurance
These systems produce confident output that is sometimes wrong, they can be manipulated through their inputs, their costs move with usage, and their behaviour shifts when a vendor updates a model. The team that built the system is the wrong team to judge it. We give you an independent read before it reaches customers.
Governance assurance, from £7,500
Release assurance from £7,500
Both use the same instrument: a published scorecard that measures what an organisation can actually evidence, rather than what it intends.
03 / The position
This is deliberate. An assessor who also sells the remediation has a commercial interest in finding expensive problems. Everyone understands that, which is why findings from a firm that wants the follow-on work get discounted, even when they are correct.
Every mature assurance profession separated these functions for the same reason: audit, building control, surveying, certification.
Findings come with a written remediation specification: what needs to change, to what standard, and how it will be verified. Your own team can implement it. If you would rather not, we can introduce implementation partners we work with regularly. We take no fee from that work and have no interest in how large it turns out to be.
04 / Why now
The EU AI Act applies in stages, and two of them have started. It reaches UK and other non-EU firms wherever the output of their AI is used in the EU.
February 2025
Prohibited practices, and a duty to support AI literacy among staff who use AI.
2 August 2026
Transparency. People must be told when they are dealing with an AI system, and AI-generated content must be marked.
2 December 2027
High-risk obligations, for AI used in decisions about people in employment, credit, education and access to essential services. Oversight by competent people, logs kept for at least six months, people told when AI is deciding about them, and a right to an explanation.
In the UK the change has come through existing law. Since February 2026, anyone subject to a significant decision made solely by automated means must be told, and can make representations, ask for a human to intervene, and contest it. Regulated financial firms answer for their use of AI through the senior managers accountable for it.
Every one of these requirements asks the same three questions. Who is accountable for this system? What did the AI decide, and who approved it? Were the people affected told? A written policy leaves all three open. The scorecard tests whether you can answer them.
We give technical assurance opinions. For legal advice, speak to your lawyers.
04 / The instrument
Published as ACES, the AI Control Efficacy Standard. You can read it, use it, and assess yourself against it without engaging us. Ten domains, each scored on the same five-level scale, under a release or a governance instrument.
Most organisations assess themselves at level 2 and turn out to be at level 1. The distinction is whether anything actually stops the rule being broken.
05 / Background
Over twenty years in software architecture and engineering leadership, in systems where failure is expensive.
He is currently writing The Full-Squad Developer, on engineering practice and governance in the AI era. The scorecard is drawn from it.
Based in Cambridge, UK.
06 / Contact
Tell us what you are releasing, or where you suspect the gap sits. Come as you are; there is nothing to prepare.
Paul Baker
Cambridge, UK
All engagements are carried out under NDA.