17 free courses — no signup wall
Architect-led enterprise cloud, security & AI
320+ downloadable toolkits — instant delivery
Skip to content

Agent Assurance · Fixed scope, published price

Three weeks. $15,000. You end with a governed agent running, not a deck.

The Agent Assurance Assessment finds every AI agent already running in your environment, maps your controls to NIST AI RMF and ISO/IEC 42001, deploys one governed agent on a real workflow in your own environment, and hands your leadership a prioritized rollout plan. The scope is fixed, the price is on this page, and the person who scopes it is the person who delivers it.

  • 3Weeks, fixed
  • $15,000Fixed price
  • 4Named deliverables
  • 1Governed agent live

Ask most enterprises how many AI agents they are running, who owns each one, and what credentials it holds, and the honest answer is that nobody knows. Meanwhile the AI module has arrived in vendor-risk questionnaires, ISO/IEC 42001 is turning into a qualification filter, and the pilot that impressed a steering committee last quarter still has no identity, no autonomy tier, and no audit trail. This engagement is built to close that gap in three weeks, for a number you can see before you call anyone.

Four deliverables, named up front

These are the artifacts the engagement produces. If one of them is missing at the end of week three, the engagement is not finished.

01 · Agent inventory and risk map

What it is
Every AI agent, copilot, assistant, and automation script already running in your environment — including the ones nobody approved.
What you receive
A register of each agent with its owner, the credentials it holds, the systems it can write to, and its current autonomy in practice — scored by exposure.
Why it matters
Most organisations cannot answer "how many agents do we run and what can they touch?" That question is now on vendor-risk questionnaires and in board packs.

02 · Governance evidence pack

What it is
Your controls, gaps, and remediation written up against NIST AI RMF functions and ISO/IEC 42001 themes — in the language your risk committee already uses.
What you receive
A documented mapping per control area, the evidence that supports it, the gaps that do not, and a remediation list ordered by effort against risk.
Why it matters
This is the artifact you hand to your own risk committee, or paste into the AI module of a SIG or CAIQ questionnaire. It is a document, not a slide.

03 · One working governed agent, in your environment

What it is
A single real workflow, agreed in week one, automated by an agent that runs where your data lives — not in a sandbox we control and not a recorded demo.
What you receive
A deployed agent with its own identity, an assigned autonomy tier, scoped ephemeral credentials, an attributable audit trail, and the runbook to operate or switch it off.
Why it matters
A readout is an opinion. A running agent under governance is evidence — and it tells you what the rest of the rollout will actually cost.

04 · Executive readout and rollout plan

What it is
A working session with your leadership on what we found, what we built, and what to do in what order.
What you receive
A prioritized rollout plan sequenced by value against risk, naming which workflows stay human-gated, and what each next phase would cost.
Why it matters
The plan is written so you can take it to budget approval without us in the room.

How the three weeks run

Fixed duration means your team can plan around it. Here is where your people are actually needed.

Inventory and scope

Working sessions with your platform, security, and process owners. We enumerate what is already running, review credentials and integrations, and agree the one workflow the governed agent will take on. You leave week one with the draft inventory.

Week 1

Build under governance

The agent is built and deployed in your environment: its own identity, an autonomy tier set per action, scoped credentials issued for the task, logging wired to your audit trail. Evidence for the governance pack is collected as we build, not reconstructed afterwards.

Week 2

Evidence and readout

The agent runs under observation while the NIST AI RMF and ISO/IEC 42001 mapping is completed and the gaps are written up. The week closes with the executive readout and the prioritized rollout plan.

Week 3

The price, on the page

Two options, both fixed price and both three weeks. There is no third “contact us for a quote” tier. The $15,000 engagement is the same fixed-fee anchor as the Starter Pilot on the AI agents page.

Multi-Environment Assessment

$40,000 fixed price · 3 weeks

Several environments or business units, assessed together rather than one at a time.

  • The same four deliverables, across multiple environments or business units
  • Inventory and risk map consolidated across all units in scope
  • Evidence pack written to cover the group, not a single team
  • Readouts for each unit plus one consolidated executive session

Who delivers it

Delivery is led by Kehinde Ogunlowo, Citadel’s founder and principal architect. He scopes the engagement, runs the sessions, deploys the agent, and presents the readout. Citadel does not staff engagements from a bench, and the four functions below are work performed inside the engagement — not four separate people.

Discovery and inventory

Running the sessions with your teams and building the agent register and risk map.

Governance mapping

Writing the control-by-control mapping to NIST AI RMF and ISO/IEC 42001 and the gap list behind it.

Agent build and deployment

Designing, deploying, and instrumenting the governed agent inside your environment.

Executive readout

Presenting the findings and the rollout plan to your leadership and answering to them directly.

The person who scopes it is the person accountable for it

What that means in practice

No handoff
The person on your scoping call is the person in your environment in week two and in front of your leadership in week three. There is no transfer from a partner who sold it to a team that inherits it.
Fixed means fixed
The price does not move because the work took longer than expected. An overrun inside the agreed scope is Citadel’s cost, not a change order.
Scope changes in writing
If what you need turns out to be larger than what was scoped, that is a written amendment agreed before any further work — never an invoice you find out about afterwards.
We will turn it down
If the scoping call shows the engagement is the wrong shape for you — too early, too large, or better served by an independent assessor — we say so on the call rather than sell it anyway.

What this assessment is not

Stated plainly, because the deliverables reference control frameworks and it would be easy to read more into that than is there.

Four limits, stated up front

Certification
This is not one. Nothing in the engagement certifies you against ISO/IEC 42001, NIST AI RMF, or any other framework. Citadel is not a certification body and holds neither framework itself.
Audit
This is not one either. There is no audit opinion, attestation, or assurance report in the accounting sense. The evidence pack documents what we found and mapped; it does not attest to it.
Independence
We do not have it. Citadel builds and operates governed agents commercially, and would expect to bid on the rollout this assessment recommends. Where your process requires an independent assessor, use one — we will say so rather than take the work.
Your risk function
This does not replace it. The deliverables are built to be used by your risk, security, and compliance teams. They are inputs to your governance process, not a substitute for it.

The wider posture — where agents run, how they authenticate, how autonomy is bounded, and what happens to your data at exit — is on the security & governance page.

Questions before you book

The things a CIO, a head of platform, or a risk lead asks before putting $15,000 through discretionary budget.

Why publish the price when nobody else does?

Because a number you can see is a number you can budget. Across the large firms we benchmarked, every path ends at "contact sales" — which means a procurement cycle before you learn whether the engagement is even affordable. A fixed $15,000 can usually be routed through discretionary budget without an RFP. The trade is that the scope is fixed too: what is on this page is what the engagement covers, and anything beyond it is a written change to the statement of work.

We do not think we have any agents running yet. Is this still worth it?

Usually yes, and the inventory is the reason. Copilots inside developer tooling, vendor features switched on by default, scripts calling model APIs, and departmental automations built without a ticket all count as agents once they hold credentials and can write somewhere. The first week regularly finds more than the sponsor expected. If it genuinely finds nothing, the engagement still leaves you with a governed agent running on a real workflow and the evidence pack to govern the next ten.

What does the working agent actually do?

You choose the workflow in week one, from what your own teams already do repetitively. It runs in or adjacent to your tenancy, grounded in your data, with its own identity, scoped ephemeral credentials, an autonomy tier set per action, and a full audit trail. Most first agents are read-and-report — triage, extraction, drafting — because that is the lowest-risk place to prove the governance model works before anything writes to a system of record.

What does the $40,000 tier add?

Scope, not extra deliverables. It is the same four outputs applied across several environments or business units in one pass, with the inventory and evidence pack consolidated at group level rather than written for a single team. If you are one team on one cloud account, the $15,000 engagement is the right one and we will tell you so on the call.

Does this make us ISO/IEC 42001 certified?

No. Certification is issued by an accredited certification body after an audit, and Citadel is neither. The evidence pack maps your controls and gaps against the framework so that a certification effort, a customer questionnaire, or an internal risk review has something concrete to work from. Citadel holds neither ISO/IEC 42001 nor a NIST AI RMF attestation and does not present itself as holding them.

How much of our team’s time does it take?

Plan for a workshop and a handful of working sessions in week one, technical access and a named engineering contact in week two, and a leadership session in week three. It is deliberately built to fit around delivery work rather than pull a team off it. The single biggest cause of delay is waiting on environment access, so that is agreed before the engagement starts.

Who is accountable if it slips or the deliverables miss?

The person who scopes the engagement is the person who delivers it — there is no handoff from a salesperson to a delivery team. The price is fixed, so an overrun is Citadel’s cost rather than a change order. If the scope itself changes, that is a written amendment agreed before further work, not an invoice afterwards.

What happens after the readout?

Nothing automatically. The rollout plan is written so you can act on it with your own team, another vendor, or Citadel. If you continue with us, the usual next step is a scoped pilot or a monthly engagement to operate and expand the agents; pricing for those is on the enterprise page.

Book the scoping call

Thirty minutes to confirm which tier fits, agree the workflow the governed agent will take on, and set the start date. If it is not the right engagement for you, you will hear that on the call. Not ready to talk? Start with the free Enterprise AI Agent Blueprint.