For compliance consultancies and ISO practitioners
You sell the AI policy. We build what has to sit behind it.
If you advise FCA, PRA or SRA regulated firms on compliance, you have probably started selling AI policy work. And you have probably noticed that the client's next question is technical, and that it is not a question you want to answer with a caveat.
In short
EPX Intelligence supplies the technical delivery behind compliance consultancies selling AI governance and ISO work to regulated firms. You keep the client relationship. We implement the controls, remediate the data estate and produce the technical evidence your framework requires. We do not cross sell into your base, and we do not partner commercially with accredited certification bodies, because ISO/IEC 17021-1 does not permit it.
The gap
An AI policy nobody can technically enforce is a liability with a cover page on it.
The market has produced a lot of AI policy documents this year, and rather fewer implementations. That is understandable: writing the policy is inside a compliance consultancy's competence, and configuring sensitivity labels, remediating a decade of SharePoint oversharing and evidencing technical controls is not.
The problem is that the client eventually notices. An auditor asks how the acceptable use policy is enforced, or a client questionnaire asks what technical controls prevent confidential material reaching an unapproved model, and the answer has to be something other than the policy itself.
That is the gap we fill, and we would rather fill it behind you than compete with you for it. You have the relationship, the sector knowledge and the regulatory standing. We have the technical delivery and 20 years of running Microsoft estates for UK firms.
The shape of it
How a partnership actually works
You keep the client
The relationship stays yours, the advice stays yours, and we appear at the level you decide, whether that is named subcontractor, joint delivery or entirely behind you.
We do not cross sell
No managed IT approach, no AI programme pitch, no marketing to your base. If a client asks us directly we tell you. This is the term partners test hardest and we are happy to put it in writing.
Scoped, priced work
Fixed scope technical packages you can quote inside your own proposal without waiting on us: data readiness, control implementation, evidence production, remediation.
| You bring | We bring |
|---|---|
| The client relationship and the regulatory standing. | Technical delivery capability and 20 years of Microsoft estate experience. |
| The management system, the policy and the framework. | The configuration, the remediation and the technical control evidence. |
| Sector knowledge and the auditor relationship. | Data readiness, permissions remediation, Copilot and platform deployment. |
| The commercial conversation with the client. | Fixed scope packages you can quote from without a delay. |
One thing we will not do
We do not partner commercially with accredited certification bodies.
Under ISO/IEC 17021-1, an accredited certification body may not provide management system consultancy, may not market its activities as linked to a consultancy, and a consultancy relationship can bar it from certifying that client for two years afterwards. So no revenue share, no co branded campaign, no referral commission.
Referral onto a published consultant list is fine, and we would be glad to be on yours. But if you are an accredited body reading this page, the honest position is that the commercial partnership models below do not apply to you, and any provider offering you one has not read the standard.
Equally, whoever helps a firm implement its management system cannot then be the body that certifies it. Worth establishing which kind of organisation you are talking to before either side gets attached to an idea.
Who this is for
Three kinds of partner we are looking for
FCA and PRA compliance consultancies
You hold retained relationships with wealth managers, IFAs, brokers and regulated accountancy firms, and AI governance questions have started arriving in their client due diligence.
Start a conversationSRA compliance consultancies
You provide outsourced COLP and COFA support or risk and compliance services to law firms, and live SRA guidance on AI is already forcing your clients to write policy.
Start a conversationISO consultancies and lead implementers
You implement ISO/IEC 27001 and are being asked about 42001. You have the management system expertise and want a technical delivery arm rather than a competitor.
Start a conversationStraight answers
Questions partners ask first
Can an accredited certification body partner commercially with a consultancy?
No, an accredited certification body cannot partner commercially with a management system consultancy. Under ISO/IEC 17021-1 it may not provide that consultancy, may not market its activities as linked to one, and a consultancy relationship can bar it from certifying that client for two years. Referral onto a published consultant list is acceptable; revenue share, co branded campaigns and referral commissions are not. EPX Intelligence therefore works commercially with consultancies and independent lead implementers.
Who owns the client in an EPX Intelligence partnership?
The consultancy owns the client in an EPX Intelligence partnership. EPX Intelligence supplies technical delivery behind the partner's compliance advice, appears at whatever level the partner decides, and does not market managed IT, AI programmes or anything else into the partner's client base unless the partner initiates it.
How this starts
Bring us the client question you did not want to answer.
Thirty minutes. If there is no value exchange here we will say so, and neither of us will have wasted a quarter finding out.