Three hours with the people who own the deployment and the people accountable for it, and an hour at the end to present the results. We prepare the assessment beforehand, so the session is spent resolving the things only they can resolve. Three weeks later the deployment sits in your register with one agreed view of its risks, the requirements that apply and what is still open.
Start to finished record
The session, then the readout
Risk assessment completed
Fixed, all inclusive
The business owner believes the risks are manageable. Legal is not sure what applies. Security has questions nobody has written down. Nobody disagrees exactly, and nothing moves.
Getting those people into one room is expensive and rare, so the Sprint is built to waste none of it. AIQURIS arrives with the deployment already assessed and a draft risk profile on screen. The session is spent testing that derivation against what your people know, not producing it from scratch.
You nominate one deployment. Everything else is scheduled around a single three-hour block in your calendar.
A short structured intake on the deployment you have chosen, with your business owner and one technical contact.
AIQURIS arrives with the impact screening done and a draft risk profile on screen, derived from the intake. Your people confirm the facts, close the unknowns and challenge anything that does not match what they know:
The completed assessment is finalised in your deployment register and issued within five working days, then presented in a one-hour session.
The alignment outcome depends entirely on the attendee list. Four roles, or their equivalents in your organisation.
Attendance is confirmed at intake.
Without those roles the session cannot produce an agreed view.
The deployment owner
The person accountable for getting it live and running it
Risk or legal
Whoever will be asked to sign off, or to answer for it later
Security or IT
Whoever knows what the system actually does and touches
Someone who can decide
Or who can get a decision without another meeting
A completed assessment in your deployment register: the risk profile across safety, legal, ethics, security, performance and sustainability, the requirements that apply with the regulations and standards they come from, the derived controls and the open findings. Every output states what it rests on: the facts you declared, the sources applied and what was not assessed.
Not a generic control list. Each control is derived from a risk this deployment presents, carries the evidence it calls for, and can be assigned to an owner.
The assessment is prepared beforehand and worked through on the platform during the session, with your team in it. They have now seen the method applied to a deployment of their own, and can take on more of the next one.
ONE THING A PARTICIPANT NOTICED
“The structured approach of AIQURIS has helped to uncover risks that have not surfaced before.”
AI Specialist, law enforcement agency, Singapore
Fixed. One deployment, start to finished record. No scoping exercise, no day rates.
The intake and preparation are credited against a CONTROL+ engagement started within 90 days of issue. CONTROL+ is a full compliance assessment against every applicable regulation, standard and policy.
Each Sprint is prepared by an AIQURIS assessment lead and led by Dr Andreas Hauser or Dr Martin Saerbeck, who built TÜV SÜD’s global AI quality practice and sit on the international committees developing the standards for AI quality and risk management. Four founder-led Sprint slots are available each month; next available dates on request.
Not sure it is the right deployment? Request a 30-minute call.
The Sprint is an assessment, not a certification or an approval. AIQURIS is not an accredited conformity assessment body. The assessment reflects the deployment as described at intake and in the session; control status is recorded as you declare it, and nothing is verified against evidence or system access. Evidence review is a separate service, and independent assurance is separately scoped and separately delivered. Your organisation decides whether the deployment proceeds, and on what basis.
The one closest to a decision. A deployment already in production works as well as one waiting to launch, and one that is stuck in review is usually the most useful of all. We will help you pick during intake.
No. This assessment works from a description of the deployment: its purpose, users, data, operating context and what the system is permitted to do. No system access is required for it.
Unknowns are recorded as unknowns rather than assumed. They appear in the assessment as open items with an owner, which is usually more useful than a guess.
Yes. The session works remotely provided the right people are present and engaged for the full three hours.
That is the point of running it. The output states what the deployment requires and what is still open. What you do about it is your organisation’s decision.
Not as a Sprint each time, and it is not meant to. Use the first as a calibration deployment, then assess the rest on the platform at the depth each one needs. Discuss a portfolio rollout.
Already familiar with the method? The same assessment is available self-service on the platform, without the intake, the preparation or the facilitated session. See RISK+ →
Tell us which one, and we will tell you whether a Sprint is the right way to assess it.consultation to discuss your AI use case, key risks, and next steps. Or book a 30-minute call →