EW-AiRM™ ADVISORY SERVICES

Enterprise-Wide AI Risk Management: From your first AI policy review to full framework implementation

EW-AiRM™ is the practitioner framework for governing artificial intelligence across a whole organisation: three layers, six pillars, the HAIPECR ethical filter and five non-negotiable governance requirements, proportionate from SME to global enterprise. We assess what you have, build what is missing, and keep it working.

Wiley Finance book, publishing 12 November 2026

HAIPECR listed on the OECD AI Policy Observatory

UNECE WP.6 AI project leadership

ISO/IEC JTC 1/SC 42 standards participation

WHY ORGANISATIONS COME TO US

Most AI policies answer the regulator.
Few manage the risk.

First-generation AI policies restate the EU AI Act's risk ladder and stop. What they typically lack is everything that makes AI risk manageable: a risk appetite with real thresholds, an operational risk taxonomy and controls, indicators worth reporting, vendor standards, a tested human override, and any provision for resilience. That gap between having a policy and managing AI risk is precisely what the EW-AiRM™ service ladder closes.

THE SERVICE LADDER

Seven services. Each one builds on the last.

Our advisory services are designed as a progressive ladder, guiding your organization through increasing levels of AI risk management maturity. Each service builds on the foundations laid by the previous, ensuring a comprehensive and tailored approach to managing the complexities of AI adoption.

1

AI Governance Healthcheck

Fixed fee by tier

A fixed-scope assessment of your existing AI policy, governance and
practice against the full EW-AiRMTM framework.
You receive a scored gap report, a five Non-Negotiables scorecard, and a prioritised 90-day, 6-month and 12-month roadmap, in a Board-ready format.

For: Any organisation with an AI policy that has never been independently tested.

2

AI Policy & AI Risk Appetite Statement

Fixed fee, scoped by tier

Two field-tested instruments tailored to your organisation: an AI policy covering the full lifecycle from intake to retirement, and a Board-level AI
risk appetite statement with qualitative postures and quantitative Green, Amber and Red thresholds, calibrated in two working sessions with your teams.

For: Organisations whose AI Governance Healthcheck showed the appetite and instrument gap, or who are drafting from scratch.

3

Full EW-AiRMTM Implementation Programme

Scoped per tier and estate; fixed Phase 1 price

Enterprise-wide implementation across the Strategic, Operational and Resilience layers: risk taxonomy mapping grounded in the MIT AI Risk
Repository, a proportionate control library, KXI dashboard design, vendor standards, resilience provisions and training rollout, delivered through the five-phase roadmap: Assess, Enhance, Build, Implement, Sustain.

For: Organisations committing to AI governance as a durable capability.

4

Board & Executive AI Briefings

Half-day or full-day sessions

Author-led sessions for boards and executive committees: AI risk in plain terms, the five Non-Negotiables, and appetite-setting workshops.
Supports AI literacy expectations at the top of the house, including Article 4 of the EU AI Act.

For: AI developers, product managers, and all employees interacting with AI systems.

5

Annual EW-AiRMTM Assurance Review

Annual engagement, by tier

A recurring re-assessment against the framework and against your own risk appetite: KXI review, incident learning, horizon scan across the eight
AI Black Swan categories, and an updated roadmap. Governance that stays current between policy review dates.

For: Past AI Healthcheck and implementation clients, and internal audit functions seeking independent input.

6

EW-AiRMTM Instrument Licence

Single-organisation and partner editions

Licensed use of the model AI policy and AI risk appetite instruments, with adaptation guidance, for organisations that will self-implement and for advisory firms delivering to their own clients.

For: Capable in-house teams and professional intermediaries.

7

Retained Advisory / Fractional AI Risk Officer

Monthly retainer, by tier; limited capacity

Standing senior counsel: committee attendance, regulatory horizon updates, incident support and a direct line when something unexpected happens. Reserved for organisations that have completed the EW-AiRMTM implementation programme.

For: Organisations that want the author's judgement in the room, not just the framework on the shelf.

PROPORTIONATE BY DESIGN

Which one is your firm's EW-AiRM™ tier?

Core

Fewer than 100 employees
1 to 5 AI systems,
mostly off-the-shelf tools and AI APIs

Essential governance scaffold, not a reduced framework

Three pre-deployment questions as the assessment floor

Single-page instruments your team can actually run

Access to expert EW-AiRM™ specialists as needed

Standard

100 to 1,000 employees
5 to 25 AI systems
mixed off-the-shelf and custom

All six pillars assessed at proportionate depth

Full seven-dimension HAIPECRTM review per deployment

Prioritised control library and KXI dashboard

Full

More than 1,000 employees
more than 25 AI systems
material foundation model dependency

Complete architecture within three lines of defence

Resilience testing across all eight AI Black Swan categories

Continuous monitoring and Board-level reporting

The floor never moves. Whatever the tier, the five Non-Negotiables apply in full. The tiers are the same framework applied with proportionate resource intensity: a tier changes depth, never the floor.

QUESTIONS WE ARE ASKED

AI risk management, answered plainly

What is EW-AiRM™?

EW-AiRM™ (Enterprise-Wide AI Risk Management) is a practitioner framework for governing artificial intelligence across a whole organisation: three layers (Strategic, Operational, Resilience), six pillars, the seven-dimension HAiPECR ethical filter, eight AI Black Swan categories, five Non-Negotiables and three proportionate implementation tiers.


It augments the enterprise risk management you already run rather than replacing it, and is the subject of a forthcoming Wiley Finance book by Prof. Markus Krebsz.

What is an AI risk appetite statement?

A Board-approved statement of how much AI risk your organisation will take, in which uses, and at what thresholds.


A genuine one is specific, differentiated by use case, operationalisable by the teams deploying AI, and regulatory-aligned. Without specific thresholds, it is a press release, not a governance instrument.

Our AI policy is based on the EU AI Act. Are we ready?

Usually only partly:


Legal classification answers what the regulator requires of a system; it does not answer what can go wrong, how likely it is, and which controls address it.


Readiness also needs an operational taxonomy, indicators, vendor standards, incident pathways, a tested override and resilience provisions.


The AI Healthcheck shows you exactly which of these you have.

Is EW-AiRM™ suitable for a small organisation?

Yes, absolutely.


The Core tier serves organisations with fewer than 100 employees and one to five AI systems, with instruments sized accordingly.


Proportionality is built into the framework; the five Non-Negotiables still apply in full, because responsible AI governance has a floor that does not scale down.

How long does an AI Healthcheck take, and what do we receive?

Typically two to three weeks from document receipt: a scored gap report against the full framework, a five Non-Negotiables scorecard, and a prioritised 90-day, 6-month and 12-month roadmap, presented in a form your Board can use directly.

Who is behind EW-AiRM™?

Prof. Markus Krebsz, founding director of the Human-Ai.Institute and De-Risking Solutions Ltd, author of the Wiley Finance book on EW-AiRM™, contributor to UNECE WP.6, OECD-listed HAiPECR framework author, and participant in international AI standards and policy work.