- in the advisory report for leadership
- 31 pages Client advisory report · 2026
- vendor policies reviewed
- 35 Vendor policy library reviewed · 2026
- independent evidence sources examined
- 4 Advisory working papers · 2026
- prioritised list to take to the vendor
- 1 Client advisory report · 2026
The situation
What arrived on the table
The client runs its business on a third party SaaS platform that holds its most sensitive client data. It wanted an independent advisory review rather than a penetration test. The questions were practical. How does the platform handle our data? What is its AI footprint? Does the assurance evidence stand up when an enterprise customer asks for it?
The intervention
What we did
Sat with the team on site and watched the platform being used, then put a structured question set to the platform's developer.
Worked through the vendor's policy library, its independent penetration test results and a third party risk assessment commissioned by one of the client's enterprise customers.
Mapped how AI is used inside the platform and what data reaches it.
Rated every area for likelihood and impact, then wrote it in plain English for leadership rather than engineers.
The outcome
Where it landed
Leadership received a report it could use. Every area was rated, every rating was explained, and the reasoning remained visible rather than buried in an appendix.
The practical output was a prioritised conversation list for the vendor. The client now knows what to ask, in what order and what evidence to expect back. That matches the assurance position its enterprise customers expect.