AI infrastructure assurance

What your AI costs. Whether it’s secure. Whether it’s governed.

FINSECRA runs fixed-price readiness engagements for ISO/IEC 42001 and the EU AI Act, grounded in how your AI and cloud infrastructure actually runs. Every finding is evidenced. Every report is signed by a named consultant.

Fixed scope, fixed priceRead-only accessYour data stays in your environment

FND-014 · Shadow AIHigh

Unsanctioned LLM API calls from production workloads

Three services call an external model API that is not on the approved vendor list.

Cost
Model API spend outside any budget or cost centreEvidence · billing export line items
Security
Customer records included in prompts sent off-platformEvidence · egress logs, service config
Governance
No approved use case, impact assessment or processor contractMaps to · ISO/IEC 42001 A.9 · GDPR Art. 28
Triaged, reviewed & signedPrincipal consultant
Illustrative example — one finding, three answers.
Readiness work against
  • ISO/IEC 42001
  • EU AI Act
  • ISO/IEC 27001
  • SOC 2
  • GDPR
Approach

Three questions your board is asking, answered in one engagement

Cost tools don’t understand governance. Compliance platforms don’t look inside your infrastructure. AI security specialists rarely see the bill. We work across all three, because the risks overlap.

Cost

What does our AI actually cost?

Spend attributed across the layers where it hides.

  • LLM token and model API spend
  • GPU, Kubernetes and Databricks usage
  • Commitments, rightsizing and idle capacity
Security

Is it secure?

The attack surface that AI systems add to your cloud.

  • Prompt injection surface and output handling
  • Agent and tool permission scope, secrets in prompts
  • RAG corpus access control and model supply chain
Governance

Is it governed?

Evidence that stands up to an auditor and a procurement team.

  • ISO/IEC 42001 AI management system readiness
  • EU AI Act role and obligation mapping
  • Policies tailored to how you actually operate

Shadow AI is all three at once

Unapproved model usage is a cost you can’t see, data leaving your organisation, and a policy gap, all at the same time. That’s why our first engagement starts there.

Start with discovery
Why now

The high-risk deadline moved. The work didn’t.

The 2026 AI Omnibus pushed the EU AI Act’s high-risk obligations back. It did not remove them, and much of the Act already applies. Organisations that start now reach the deadline with evidence rather than a plan.

ISO/IEC 42001, published in December 2023, is the international management-system standard for AI. It turns AI Act readiness into a structured programme with a defined, auditable endpoint.

  1. Prohibited AI practices

    Bans on unacceptable-risk systems apply.

  2. General-purpose AI models

    Obligations for GPAI model providers apply.

  3. Transparency obligations

    Article 50 duties for AI interaction and generated content apply.

  4. High-risk AI in regulated products (Annex I)

    Obligations for AI embedded in products under EU harmonisation law.

Summary as of September 2026, reflecting the AI Omnibus in force from 27 July 2026. Not legal advice — which obligations apply depends on your role and your systems.

Engagements & pricing

Fixed scope. Fixed price. A deliverable on a date.

Every engagement is scoped and priced before work begins. You buy a result, not hours.

00

Shadow AI & AI Spend Discovery

A read-only look at which AI services are in use, what they cost, and what data reaches them.

About 1 week
Findings summary and a recommendation on whether a full assessment is worth it.

FreeNo obligation
02

Policy Pack Implementation

Our information security and AI governance policy suite, including AI usage, model governance and secure AI development, tailored to your organisation.

Fixed timeline
Tailored, versioned policy set mapped to your target framework.

From €6,000Fixed fee
03

Remediation & Hardening Programme

We implement the roadmap: DevSecOps pipeline, identity and access, secrets, cloud posture and AI guardrails.

Milestone-based
Hardened configuration and evidence, delivered milestone by milestone.

QuotedFixed fee per milestone
04

Advisory Retainer

Scheduled expert hours each month to keep governance current as your AI estate changes.

Monthly
Scheduled sessions and reviews. Advisory only, with no on-call or response-time SLA.

From €2,500Per month

Prices in EUR, excluding applicable taxes. USD quotes on request.Never billed hourly.

Cloud cost optimisation

Kubernetes, Databricks and multi-cloud spend, brought under control

Available on its own or alongside a readiness assessment. Same model as everything we do: fixed scope, read-only access, and every recommendation reviewed by a person before it reaches you.

Kubernetes cost optimisation

Right-size pods and node pools, find idle nodes, tune resource requests and limits, and clean up namespace sprawl.

  • EKS
  • AKS
  • GKE
  • Rightsizing
  • HPA

Databricks cost optimisation

Find idle clusters, tune job scheduling and cluster pools, use spot capacity where it’s safe, and right-size compute for Spark workloads to bring DBU spend down.

  • DBU spend
  • Spot instances
  • Cluster pools
  • Job tuning

Multi-cloud FinOps consulting

One view of spend across AWS, Azure and Google Cloud: tagging governance, reserved instance and savings plan strategy, showback and chargeback, and a FinOps maturity assessment.

  • AWS Cost Explorer
  • Azure Advisor
  • GCP Billing
  • Reserved Instances
  • Savings Plans
  • Tagging

Rightsizing recommendations

Sizing for virtual machines, managed databases, search clusters and compute, based on actual utilisation patterns rather than peak metrics.

  • EC2
  • Azure VMs
  • RDS
  • Elasticsearch
  • GKE nodes
Platforms we work across
  • AWS
  • Microsoft Azure
  • Google Cloud
  • Databricks
  • Kubernetes
  • Terraform
  • Grafana
Ask about a cost assessment
How we deliver

AI-assisted where it saves time. Human-signed where it counts.

Automation handles the evidence-heavy middle of an engagement. A named consultant owns scope, judgement and sign-off. That split keeps our prices fair, and it is also what ISO/IEC 42001 asks of any AI system, including ours.

  1. Scope

    We agree the scope and fixed price, and you approve the exact read-only permissions we request. Nothing broader.

  2. Collect

    A short-lived, read-only collector runs inside your environment. You can inspect it before it runs, and it is removed when we finish.

  3. Analyse

    Controls are mapped against the stored text of each framework. A finding with no cited evidence is rejected before a person ever sees it.

  4. Sign & present

    A named consultant triages every finding, signs the report, and walks your team through it.

Your data stays with you

FINSECRA hosts no client infrastructure data. Identifiers are stripped inside your environment, and only the minimum abstracted evidence is used for analysis.

Every finding is traceable

Each finding cites a specific artefact, such as a config key, log line or billing record, plus the framework control it relates to. If it can’t be traced, it isn’t in the report.

Know what you’re buying

What your assessment report contains

  • Executive summary written for leadership, not auditors
  • Control-by-control gap analysis with evidence citations
  • Findings ranked by risk and effort to fix
  • A prioritised remediation roadmap
Ask how a report is structured

The illustration shows the structure, not a real client’s data. We’ll walk you through the format on a call.

About

A specialist practice, deliberately small

FINSECRA is a focused practice for organisations deploying AI. You work directly with the person who scopes, reviews and signs your deliverable. No hand-offs, no junior bench.

Juhi Singh

Founder & Principal Consultant

Juhi leads every FINSECRA engagement personally, from agreeing the scope and approving the read-only access requested, through triaging findings, to signing the final report and walking your team through it.

Engagements draw on FINSECRA’s 74-policy information security and AI governance suite, including AI Usage, AI Model Governance and Secure AI Development policies, tailored to each client.

If you’re evaluating us, ask for a call. You’ll speak with the person who would do the work.

Clients

Current retainer clients

  • GettleadsMonthly retainer
  • Qzerofounder-affiliatedMonthly retainer · security, performance & deployment audits

Disclosure: Qzero is affiliated with FINSECRA’s founder. We list it because the work is real, and we disclose the relationship because you should know it when you assess us.

Straight answers

What buyers ask us first

Can you certify us for ISO/IEC 42001 or ISO/IEC 27001?

No, and nobody in a consulting role should. Certificates are issued only by accredited certification bodies. We prepare you for that audit, with a gap analysis, policies, controls and evidence. We never issue or promise certification.

Do you use AI to deliver your work?

Yes, and we’re open about it. AI agents handle evidence gathering and first-pass control mapping. Every finding must cite a specific artefact, framework references are checked against stored framework text rather than model recall, and a named consultant reviews and signs the deliverable. Any model provider involved is named as a sub-processor in your contract.

Does our infrastructure data leave our environment?

Collection runs inside your environment as a short-lived, read-only collector you can review before it runs. Identifiers are stripped there, and only the minimum abstracted evidence is used for analysis. We don’t host or keep copies of your infrastructure inventory. If your policies need analysis to stay entirely in your own cloud account, raise it at scoping.

You’re a small practice. What if you’re unavailable?

That’s why we sell fixed-scope deliverables rather than operations. A report and a hardened configuration belong to you on delivery, and nothing in your production depends on us afterwards. We don’t offer 24/7 monitoring or response-time SLAs, so there’s no operational commitment we could fail to meet.

Where are you based, and how do you work with EU and US teams?

We’re based in India and work remotely with teams in the EU and US, with scheduled sessions in overlapping hours. Engagements are quoted in EUR or USD.

Get started

Start with a discovery call

Thirty minutes to understand your AI estate and what you need to show, and to decide whether a discovery engagement makes sense. No sales deck.

juhi.singh@finsecra.ai