Service Offering

ANG AI Trust Compass

Safe AI adoption, from exposure to proof

Use AI confidently, and be able to prove it. ANG Associates helps mid-size and large companies protect confidential data and know-how while adopting AI, with services that answer the questions boards, auditors, insurers and customers ask.

Why now

The question is no longer "are we using AI?"

It is "can we show that we control it, and are we moving fast enough?" Recent surveys point to a gap between how widely AI is used and how well leaders can prove it is under control.

78%

of surveyed executives lack confidence they could pass an independent AI governance audit within 90 days

Grant Thornton, 2026 AI Impact Survey, 950 business leaders
47%

of surveyed CISOs say they can identify every AI agent in their environment

Okta-sponsored survey, 306 CISOs, July 2026
56%

of surveyed CEOs report no significant financial benefit from AI to date

PwC 29th Global CEO Survey, 4,454 CEOs, fielded autumn 2025

These are self-reported surveys, and several were run or sponsored by firms that sell services in this area. Grant Thornton and Okta both do, and the PwC survey predates 2026. We use them as signals, not verdicts. Our related articles discuss each source in detail.

Our Services

Six services, one path from exposure to proof

Each service stands alone and can be bought on its own. We suggest starting with the Exposure Check or Audit Readiness, then adding the others as your questions become specific.

01Recommended starting point

AI Exposure Check

Where is AI really being used in our company, and which confidential information is at risk?

Best for

CISO, General Counsel, R&D and business heads

You receive
  • A map of actual AI usage across teams and tools
  • Your crown-jewel information, named and ranked
  • A ranked gap list, approved tool paths and a one-page usage policy
Read: Shadow AI and data leakage
02Recommended starting point

AI Audit Readiness

If an auditor, insurer, customer or board member asked, could we prove that we control AI?

Best for

Board, CFO, CIO, General Counsel

You receive
  • An AI inventory with owners and risk classification
  • A gap assessment against ISO/IEC 42001, the NIST AI RMF and, where relevant, the EU AI Act
  • An evidence pack, rehearsal questions and a board-level summary
Read: The AI audit proof gap
03

Agent Access Review

Which AI agents can reach our data and systems, and who reviews that access?

Best for

CISO, COO, CIO

You receive
  • An agent inventory with identity, permissions and data reach
  • A least-privilege remediation plan
  • Design for approvals, logging and shut-off, plus an incident tabletop
Read: AI agents and access risk
04

Safe Fast-Track

How do we move faster on AI without creating risk nobody has priced?

Best for

CEO, CIO, business leaders

You receive
  • Risk tiers and approval routes that teams can self-classify against
  • A short list of use cases for concentrated investment, with baselines and success measures
  • A one-page board view of what is live, what it costs and which risks were accepted
Read: Falling behind or wasting the spend
05

AI Coverage Gap Review

If an AI system causes a loss, would our insurance actually respond?

Best for

CFO, General Counsel, risk managers

You receive
  • An AI exposure map and the controls you already have, documented
  • An evidence pack and question set for your broker and underwriters
  • A clear view of the gaps between AI exposures and current policies, run alongside your broker and counsel
Read: Is your insurance ready for AI?
06

Sovereign Path

Which data and workloads must stay under our own control, and how do we get there?

Best for

CEO, CIO, General Counsel

You receive
  • Your data tiered by sensitivity, and AI vendors mapped to hosting and jurisdiction
  • An independent comparison of deployment options for your most sensitive workloads
  • A verification checklist and a pilot plan
Read: AI sovereignty for Swiss and EU companies
Relevance to Pharma and Life Sciences

Where ANG AI Trust Compass fits in Pharma and Life Sciences

Pharma combines valuable confidential data, validated systems and regulators who are writing their AI expectations now. That makes it hard to show that AI is under control, and it is why we position this offering with Life Sciences in mind. ANG Associates comes from Life Sciences and IT delivery, so we can work with R&D, Quality, IT and the board in one conversation.

Jan 2026

EMA and FDA published ten guiding principles of good AI practice in drug development, covering the medicine lifecycle from early research and clinical trials to manufacturing and safety monitoring. They are broad guidance, not binding law.

EMA news release, 14 January 2026
Draft

EU GMP Annex 22 on AI in manufacturing is, as far as we can tell, still a draft. As reported, it covers static, deterministic models and keeps generative AI and LLMs out of critical GMP uses. The final text may differ.

Pharmaceutical Technology, 2026 (trade press; check the EMA for the current text)
83%

of organizations surveyed across industries, not only pharma, said they lack automated controls that stop sensitive data leaking through AI tools. This is a vendor-run survey of 461 professionals.

Kiteworks survey, reported by Contract Pharma, July 2025

The Kiteworks figure is cross-industry, vendor-run and from 2025, so we read it as a signal. Regulatory status changes; please verify against the EMA and your own regulatory team before relying on any of it.

What this means for each of the six services

AI Exposure Check

Where do R&D, clinical and process data meet AI tools?

Discovery data, trial data, formulations and process know-how are the assets. We map where they reach public or unapproved AI tools, and which vendor terms and retention settings apply to them.

AI Audit Readiness

Can we show auditors and inspectors how our AI is controlled?

We prepare the evidence pack: AI inventory, intended use, risk classification, validation and change control records, monitoring and human oversight. This follows the direction of the EMA and FDA principles and draft Annex 22. We prepare you; we do not certify.

Agent Access Review

What can AI agents reach inside validated and regulated systems?

We review agent identities, permissions and logging around systems such as document management, quality, laboratory and ERP platforms, and how agent actions fit your data integrity and change control expectations.

Safe Fast-Track

Which AI use cases can go live now, and which need more control?

We sort your portfolio of use cases by risk, for example literature review, drafting support, deviation triage or commercial content. Low-risk cases move with guardrails; GxP-critical ones get the validation they need before they go live.

AI Coverage Gap Review

Do our policies respond when AI touches quality or safety decisions?

We prepare the questions and the AI use picture that your broker needs to review product liability, cyber and professional liability cover. We are not a broker and give no coverage opinions.

Sovereign Path

Where may our data and models live, and who can access them?

For clinical and patient-related data and cross-border transfers, we compare hosting and model options in Switzerland and the EU, and prepare the questions for your legal counsel and data protection officer.

What is settled, and what is not

  • The EMA and FDA principles are guidance, not law, and they are broad. We use them as a reference for good practice, not as a checklist you can be certified against.
  • Annex 22 is, as far as we know, still in draft. We prepare you for its direction (intended use, validation, monitoring, human oversight) and adjust when the final text is published.
  • We do not give legal or regulatory opinions. Your Regulatory Affairs, Quality and legal counsel decide what applies to your products; we prepare the evidence and the questions.

Who we work with in pharma

  • R&D and clinical data owners, who know which data is the crown jewel.
  • Quality, validation and computer system validation teams, who own the evidence.
  • IT, security and the CISO, who own access, logging and vendors.
  • Regulatory Affairs, legal and the board, who need one clear answer.
How We Work

A fixed-scope engagement in four steps

We agree scope and deliverables before we start. Duration and fees depend on the size of your organization and the service you choose, and we set them out in a scoping call.

1

Scope

A short call to agree objectives, sponsors, the systems and business areas in scope, and what your board or auditors will ask for.

2

Assess

We build the inventory with your teams, classify each use by risk and data, and test current controls against the relevant framework.

3

Decide

You receive a ranked plan of gaps and actions. Decisions to fix, accept or transfer each risk are recorded with a named owner.

4

Prove

We assemble the evidence pack and board summary, rehearse the questions an independent reviewer would ask, and can support periodic review as tools and rules change.

Where We Fit

Independent advice, with clear limits

What we do

  • Advise on AI governance, security and adoption for regulated and knowledge-intensive companies, with a Life Sciences and IT delivery background.
  • Work with the identity, security and monitoring tools you already own, and help you judge where a gap needs a new tool and where it needs a process or an owner.
  • Prepare the evidence and questions that make your legal counsel, broker and auditors more effective.

What we do not do

  • We are not a law firm and do not give legal opinions.
  • We are not an insurance broker and do not sell, place or give coverage opinions on insurance.
  • We are not a certification body and cannot certify you against a standard; we get you ready.
  • We do not sell software, host models or take fees from vendors, so our recommendations are not tied to a product.

Start with one conversation

Tell us which question your board, auditor, insurer or customers are asking. We will recommend the service that answers it and set out scope and deliverables.

Request a Scoping Call