The proven sequence
Four pillars, in order, with a number at the end of each one.
This page is the one to forward. It sets out the order we work in and why it is that order, what we do and explicitly do not do, how we price, and how you will know at the end whether it worked.
In short
EPX Intelligence works in four connected pillars: governance, enablement, transformation, development. Governance comes first because it makes everything after it defensible. Every engagement starts with a fixed price readiness assessment that records a baseline, so the benefit can be measured. Most firms start at pillar one or two and move along the progression. Nothing is bundled into a managed IT contract.
The sequence, and why
Skipping governance is faster for six weeks and slower for two years.
Almost every firm we meet wants to start at pillar two, because Copilot is the visible thing and governance is the homework. We understand the instinct, and occasionally we agree with it, particularly where a firm has a live and well maintained ISO 27001 already doing much of the work.
The reason for the order is practical. Data remediation is the first real task in a Copilot rollout, and the thing that tells you what to remediate is a risk assessment. An approved tool list is what makes it reasonable to stop people using unapproved tools. A baseline is what turns a rollout into a business case. All three of those are governance artefacts, so a firm that starts with governance is not delaying enablement, it is starting it.
Where we will agree to skip ahead
If you hold a live 27001, your permissions model is in reasonable order, and you have a current acceptable use position, we will run governance and enablement in parallel rather than in sequence. We will say so on the discovery call and put it in writing. What we will not do is start bespoke development in pillar four with no framework underneath it.
The engagement
What happens, in what order
Discovery call
Thirty minutes, no proposal. What has been asked of you, by whom, and which pillar you should start at. If we are not the right people we will say so on the call.
No costReadiness assessment
Data estate, permissions, licensing, policy position, current AI usage, and a measured baseline of the workflows you want to change. Your IT manager is in this from day one.
Fixed scope, fixed price, two to three weeksProgramme, pillar by pillar
Phased, with named owners, a decision point at each quarter, and reporting against both the baseline and the evidence an auditor would ask for.
Priced after the assessment, in writingBeing clear
What we do, and what we do not
| We do | We do not |
|---|---|
| Get your firm ready for ISO/IEC 42001 and support ISO/IEC 27001 implementation. | Certify anyone. A separate UKAS accredited body does that, and the roles have to stay apart. |
| Work alongside your in house team and your incumbent IT provider. | Require you to change IT provider, or treat this as a route into a support contract. |
| Sell AI programmes standalone, on their own merits. | Bundle AI services into a managed IT contract. They are separate propositions. |
| Publish a fixed price for the readiness assessment so you can budget step one. | Quote programme prices before the assessment, or move a price after we have written it. |
| Record a baseline before we change anything. | Quote a saving for a process nobody measured beforehand. |
| Recommend a product where a product does the job. | Build bespoke because the build is more profitable for us. |
| Deliver governance and enablement nationally. | Treat geography as a reason to say no. We work with firms across the UK. |
| Hand over documentation, runbooks and source you own. | Leave you dependent on us to maintain what we built. |
The three gates
Three people, three different tests.
In a firm of your size this decision is not one person's. The compliance lead gates on evidence, the IT manager gates on practicality, and the MD, FD or COO signs on confidence. All three can stop it, and only one of them can start it.
So we run the process to suit that. The readiness assessment produces three different outputs from the same piece of work: an evidence position for compliance, a technical scope and change plan for IT, and a one page business case with a baseline for the board. Same facts, three readings, which is considerably less work than three separate conversations that end up contradicting each other.
If your IT manager has not been told this conversation is happening, tell them before the discovery call. It costs you nothing and it removes the single most common reason a promising programme stalls.
Straight answers
Questions about how we work
Do we have to do all four pillars?
No, an EPX Intelligence client does not have to buy all four pillars. Most firms buy one or two and move along as the evidence stacks up. The progression describes how the pillars relate. It is not a minimum order. The one hard rule is that we will not start bespoke development without a governance framework underneath it.
Why are there no prices on this site?
Because the honest answer depends on user count, sector and what the assessment finds, and a number invented for a web page would be wrong in one direction or the other. What we will commit to publicly is that the readiness assessment is fixed scope and fixed price, and that programme prices are put in writing after the assessment and do not move afterwards.
How will we know whether it worked?
Because we recorded a baseline before we started. Elapsed time, touch points and rework rate on the target workflows, adoption measured, and the specific evidence items your auditor or your client questionnaire asked for. Reported quarterly, against that baseline.
What if we want to stop?
Each phase has a decision point at the end and the readiness assessment is deliberately a standalone purchase. If the assessment tells you the honest first step is remediating your existing management system rather than adopting AI, that is a legitimate outcome and you should stop there.
Where to start
Thirty minutes to work out where you should start.
Bring the question your last tender asked you, or the Copilot licensing question sitting in your inbox. We will tell you which pillar answers it.