Eshalu
AI governance assurance

Evidence, not assertions.

Eshalu helps organisations assess AI independently, make better decisions about where and how to use it, and build the capability to govern it well. Our assessment work is evidence-led and human-reviewed; our consulting and assessment work are kept separate.

Ten governed controlsEU AI Act · ISO 42001 · NIST AI RMFReviewer-governed
ISO/IEC 27001:2022 certifiedTrusted information security management for client engagements Explore Eshalu servicesDiscuss an AI system
Illustrative Eshalu engagement dashboard showing readiness, open blockers and governed releases
Engagement dashboard — synthetic engagement data
Services

Assess. Advise. Train.

Three distinct service lines, with a deliberate independence boundary between advisory work and independent assessment.

01

AI Governance Assessment & Assurance

Productised, evidence-led assessment of individual AI systems and portfolios. We assess governance, risk, data, testing, human oversight, suppliers and operating evidence, with authorised human review and traceable outputs.

02

AI Consulting & Responsible Implementation

AI strategy, use cases, value, design, test strategy, governance and data. We help organisations decide what to do, how to do it responsibly and what good evidence should look like.

03

AI Training & Capability Building

Practical training for boards, executives, governance teams, business users, product teams, data teams and delivery teams — tailored to the decisions they actually need to make.

Independence rule: where Eshalu advises on, designs or helps implement an AI system or control, Eshalu will not independently assess that same work.
Who it is for

Built for organisations that have to show their working

Mid-market

Under buyer pressure

Your customers, insurers or prospects have started asking how your AI is governed, and the honest answer is that nobody has assembled the evidence yet. You need something credible without building a multinational governance function to get it.

Regulated

High-consequence settings

Financial services, healthcare, public sector and critical supply chains, where an AI system touching a customer decision is a question someone will eventually have to answer formally.

Stalled

You already tried a checklist

You have a policy, a register and good intentions, and you still cannot show which control covers which system, who owns it, or who checked it.

Where we are a poor fit: if what you need is a certificate, a compliance guarantee or a legal opinion, we are not it — and we would rather say so now than at the end of an engagement.

Why now

The questions have started arriving before the deadlines

Commercial

Procurement got there first

Enterprise buyers and insurers are asking about AI governance in due diligence today, well ahead of any enforcement date. The pressure arrives commercially before it arrives legally.

Regulatory

Obligations are phasing in

The EU AI Act applies in stages, and ISO/IEC 42001 gives organisations a certifiable management system to be measured against. Both reward organisations that started assembling evidence early.
See the sources we work from →

Lead time

Evidence takes longer than policy

A policy can be written in a week. Demonstrating that the control behind it operates, has an owner and was independently checked takes considerably longer — which is why starting at the deadline does not work.

The problem

Adoption has outrun the proof

A policy document is not evidence. Boards, buyers and regulators ask what is actually true — and a one-off assessment can become stale quickly as models, suppliers and rules change.

Spread

AI arrives from everywhere

Many teams, many vendors, and capability embedded inside products that were bought for something else.

Proof

Assertion is not assurance

Someone has to be able to show the evidence behind each claim, and say who checked it and when.

Change

The picture moves

A model version, a supplier or a rule changes, and an assessment that was true stops being true — quietly.

What you get

One governed engagement. A separate record for every AI system.

Organisation-wide governance is assessed once. Each AI system is then assessed on its own path, according to its use case, impact, autonomy, data and regulatory signals — so a low-risk assistant is never assessed like a decision system.

AI system register

Purpose, owner, vendor, lifecycle, risk band, regulatory signal and control position for every system.

Control results

Every control, its state, and the recorded reason it applied to this system — or did not.

Evidence log

What was requested, provided, accepted, missing or reused, with versions and custody.

Gap and action plan

Findings converted into owned actions with due dates, status and closure evidence.

Readiness view

Server-computed progress and blockers. Never a browser-side score, never a compliance grade.

Report suite

Board, CXO, buyer, investor and detailed outputs — each scoped to what that audience may see.

See the methodology
The product

What the client actually sees

The current product interface, shown with data from a synthetic engagement rather than a client one.

Engagement dashboard showing overall readiness, open blockers, entitled readiness metrics and the snapshot each figure came from

The engagement dashboard: where the engagement stands — readiness and open blockers, the metrics the client is entitled to see, module states, prioritised next actions and the latest governed releases.

Prioritised next actions, each showing whether it blocks, who it is assigned to and when it is due

Gaps arrive as ranked work, not a list of failures. The server does the ranking — blocker status, risk, due date, assignment and the next milestone — so the order is the same for everyone looking at it.

Progress view showing each readiness metric with its numerator, denominator and the reasons behind it

Every readiness figure carries its own arithmetic and the reasons behind it. Nothing is a score; each number can be opened and argued with.

Report suite and template library showing governed deliverables with released, update-available and superseded states

The governed deliverables, each with its release state stated plainly — released, update available, superseded or withdrawn — so nobody circulates a report that has since been overtaken.

Nothing on these screens is calculated in the browser. Every value is read from the frozen, hash-verified assessment record — and a client sees no outcome at all until an authorised reviewer has confirmed it.

Want to see the output rather than the screens? See the sample reports — the executive summary, the control-level assessment and the evidence trail, as a client receives them.

Assessment engagements

Start focused. Scale the independent assessment when it earns value.

Assessment is the productised Eshalu service line. Scope can begin with one AI system, extend across a portfolio, and then be maintained where Eshalu remains independent of design and implementation.

Focused Assessment

Scoped and proposed in writing

One AI system or one clearly defined governance concern.

Portfolio Assurance

Scoped and proposed in writing

An agreed portfolio of systems, suppliers, functions or business units.

Continuous Assurance

Scoped and proposed in writing

Maintains an independently assessed baseline, including a full annual reassessment within scope.

If you want Eshalu to help design or implement remediation, that work moves into the consulting service line and Eshalu will not independently assess the same work afterwards.

View engagement options
Insights

Practical thinking on governing AI

View all insights →
Founder

Built by the person who reviews the work

RS

Raghuram Saripalli

Founder & Principal Assessor, Eshalu

Twenty-three years inside enterprise transformation programmes — at organisations including AstraZeneca, Roche, GSK, Jaguar Land Rover, British American Tobacco and Philips, across more than fifteen countries — taught Raghuram that critical decisions get made in workshops and spreadsheets while the evidence that would settle them sits inside the systems, untouched. Eshalu closes that gap with a governed record rather than a document. ISO/IEC 42001 Implementer (PECB); AI: Law, Policy and Governance, LSE. He leads the methodology, the reviewer standard and every client engagement personally. More about Eshalu →

Partnership

Your AI will keep evolving — we stay with you

We are not here to interrogate your teams. We work alongside them: understanding the portfolio, finding what needs attention, helping you address it and keeping the record true for as long as you use AI.

Scope changes

When a system grows

An existing system takes on new data, users, a supplier or a new purpose. We reassess that system in full — straight away when it matters, otherwise at the annual assessment.

Drift

When the ground moves

Models, suppliers and rules keep moving. We stay alongside you through the year, then complete a full annual assessment of the agreed baseline.

New systems

When new AI arrives

New AI arrives through teams and vendors. We help bring each new system into the governed portfolio when needed, or as part of the next annual assessment.

Independent assessment can stay with you as the portfolio evolves. If you instead need hands-on advisory or implementation support, we scope that separately under AI Consulting and preserve the independence boundary.

Start here

Start with the problem you need to solve.

Need an independent view of an AI system? Help deciding where and how to use AI? Or practical training for the people who need to govern and use it? We will scope the right starting point and keep the boundaries clear.

Explore servicesStart a conversation