Skip to main content
AS-03 Verify stage · Launch priority: 2nd

Simor Assurance

AI security assessments and governance readiness.

Independent verification — because the team that builds a system cannot be the team that certifies it.

OWASP

LLM Top 10 coverage baseline

3

Regulatory frameworks mapped

100%

Findings shipped with remediation plans

01 Capabilities

What this division does

Adversarial testing

Red-team exercises probing your AI system for prompt injection, jailbreaks, data exfiltration, and indirect attack vectors. We use the OWASP LLM Top 10 as a baseline and go beyond it.

Governance readiness

Gap assessments against ISO 42001, EU AI Act, and UK AI Code of Practice. We produce evidence packages and remediation roadmaps — not just audit findings.

Threat modelling

Structured threat modelling sessions mapping your AI architecture to adversarial surfaces. We identify attack paths before they become incidents.

Compliance preparation

Translating regulatory requirements into engineering tasks. NCSC guidelines, EU AI Act obligations, and sector-specific rules mapped to concrete controls you can implement.

02 Approach

How this division works

01

Independence is non-negotiable. We do not certify systems built by other Simor divisions. This separation of duties is a deliberate governance choice.

02

Testing is adversarial and realistic. We use the same techniques as real attackers, not academic checklists.

03

Every finding includes a remediation path with effort estimates and priority ranking. We do not hand you a list of problems and walk away.

03 Use cases

Where this division delivers

Pre-deployment security review

Full adversarial assessment of a production AI system before launch: prompt injection testing, data exfiltration probing, supply-chain review, and OWASP LLM Top 10 coverage with remediation roadmap.

ISO 42001 readiness

Gap assessment against the AI Management System standard, evidence package preparation, and remediation plan prioritised by certification timeline.

EU AI Act classification

Risk-tier classification of your AI systems, obligation mapping, and technical documentation preparation for high-risk system compliance.

04 Lifecycle

Position in the lifecycle

Simor Group covers the full AI infrastructure lifecycle. This division operates at the Verify stage.

05 Services

Full service list

  • AI security assessments and threat modelling
  • Adversarial testing and red-teaming
  • Penetration testing of AI systems (OWASP LLM Top 10)
  • ISO 42001 (AI Management System) readiness assessments
  • EU AI Act compliance preparation
  • UK AI Cyber Security Code of Practice alignment
  • NCSC guidelines mapping
  • AI governance framework design

Governance note

Simor Assurance provides readiness assessments and evidence preparation. It does not formally certify systems built by another Simor division. This separation of duties is a deliberate governance choice.

Note Separation of duties

07 Engage

Work with Assurance

Tell us about your system, your timeline, and your constraints. We will come back with a scoping conversation — not a sales pitch.