Be ready for the AI questions in your next enterprise deal.
We help software, SaaS and fintech companies answer AI questionnaires, DORA clauses and availability requests from their enterprise customers with evidence. Gradiente is a boutique consultancy in AI, governance, risk and compliance (GRC) and Cybersecurity: we help your company use AI with control, prepare for the law and answer with evidence.
What are you facing today?
Start with what you need to solve. Each situation maps to a service with a clear method and named deliverables.
ISO/IEC 42001 · NIST AI RMF · EU AI Act
Your enterprise customers are sending AI questionnaires and you need answers you can prove.
AI governance readiness
ISO 27001 · 42001 · 22301
A buyer asks for certification evidence before they sign.
ISO readiness
DORA · SOC 2 · ISO 27001 A.5.30
A European bank sent you a DORA annex, or a US customer wants SOC 2 availability evidence.
Resilience & availability readiness
ISO 42001 A.7 · EU AI Act art. 10
You want to use AI, but your data isn't ready.
Data governance for AI
CISO · DPO · GRC
You need security, privacy or compliance leadership without a full-time hire.
Fractional compliance
How we work
Four steps, and each one ends with something you can show your board, your regulator or your customers.
Conversation
30 minutes, free of charge. We understand your business before we propose anything.
DeliverableYour next step, agreed in writing.
Assessment
Fixed scope and fee. We measure where you stand against the standard or the customer requirement.
DeliverableInventory, gap against the standard or requirement, risk matrix and prioritized action plan.
Implementation
We build with your team what the plan prioritizes.
DeliverableWhat the plan calls for, up and running, with scope, deliverables and way of working agreed up front.
Ongoing support
We keep the system alive and ready to show.
DeliverableMonthly maintenance, fractional compliance or internal audit.
Services / Resilience
Resilience & availability
Your enterprise customers want to know how long a critical service can be down and how you prove it comes back in time.
We set the tolerance for each service with you and design its recovery tests; your team runs them and we document the evidence. The result is evidence you can share: which services matter, how long they can wait and how recovery was proven.
Operating normallyService downRecoveringRecovered within tolerance
example · fictitious dataWhat you receive
- DORA contract-readiness memoYour customer's contract clauses, mapped to what you already have in place.
- Availability gap reportWhere your availability evidence stands and what to close first.
- Recovery test plan & evidence packWhat gets tested, when, and the evidence each test leaves behind.
- Customer questionnaire responsesAnswers to your customers' resilience and availability questions, backed by evidence.
Let's talk about your next step.
In 30 minutes we review where you stand and suggest where to start.