EU AI Act consultancy services
- EU AI Act consultancy covers six workstreams: inventory, classification, gap assessment, documentation, control build, and ongoing monitoring.
- Classification carries the most value per hour, because it decides every obligation that follows.
- The Annex IV technical file is the heaviest single deliverable for any high-risk system.
- Fees commonly run £15,000 to £50,000 for a first programme, driven by system count rather than headcount.
- Ask what happens after the build. The Act requires post-market monitoring for the life of the system.
What the services cover
EU AI Act consultancy services cover the work of getting an organisation from "we use AI somewhere" to a documented, defensible position on every system it provides or deploys. That work divides into six workstreams, and understanding what each delivers is the practical way to compare proposals.
Unlike SOC 2 or ISO certification, there is no external body issuing you a result for most systems. You self-assess and hold the file. That makes the quality of the documentation the whole product.
The six workstreams
Inventory. Finding every AI system the organisation provides or uses, including AI features inside purchased software, and recording owner, purpose, data, markets and decision impact for each. The systems most often missed are bought rather than built.
Classification. Determining your legal role for each system, provider or deployer, and the risk tier that applies. This carries the most value per hour in the entire engagement, because every later obligation follows from it, and because both over-classification and under-classification are expensive.
Gap assessment. Comparing each system against the duties its classification attaches and stating what is met, what is not, and what closes each gap. This is our readiness and gap assessment, delivered as a fixed fee with a delivery call.
Documentation. The Annex IV technical file for each high-risk system, the fundamental rights impact assessment where a deployer requires one, instructions for deployers, and the classification record itself. This is the heaviest workstream by volume.
Control build. Risk management process, data governance, logging that retains what the Act requires, human oversight designed so a named person can actually perform it, accuracy and robustness measures, and the Article 50 disclosures where they apply. Covered by our implementation service.
Ongoing monitoring. Post-market monitoring, serious incident reporting, and keeping the technical file current as the system changes. The Act does not have an end point, and a consultancy engagement that stops at the documentation leaves this to you.
What consultancy services cannot do
They cannot give you a compliance certificate, because for most systems none exists. Where third-party conformity assessment is required, that comes from a notified body, and a consultancy that prepared you cannot be that body.
They cannot make a prohibited system compliant. If a use falls in the prohibited category there is no compliant version, and a firm that suggests otherwise is not helping you.
They cannot operate your human oversight. The Act requires a competent person with the authority and the time to intervene. That person works for you.
Typical fees
| Service | Typical fee |
|---|---|
| Inventory and classification, small estate | £5,000 to £15,000 |
| Gap assessment | £5,000 to £20,000 |
| Full readiness and build programme | £15,000 to £50,000 |
| Annex IV technical file, per high-risk system | £8,000 to £25,000 |
| Fundamental rights impact assessment | £4,000 to £12,000 |
| Independent practitioner day rate | £700 to £1,600 |
| Ongoing monitoring | Retainer, scope dependent |
Fees are driven by system count and how many are high risk. Ask for the fee to be itemised per system rather than as a single programme number, because that is how the work actually scales and it makes proposals comparable.
How this differs from a SOC 2 or ISO engagement
Three differences worth knowing when you compare providers.
There is no auditor to prepare for in most cases, so the discipline that normally comes from an external examination has to come from somewhere else. Good practitioners impose it themselves by writing the file to the standard a supervisor would read.
The obligations attach per system rather than per organisation. One company can hold three different classifications across three products, with three different sets of duties and dates.
The work does not end. Post-market monitoring and incident reporting continue for the life of the system, which is why the ongoing arrangement matters more here than in a certification engagement.
Choosing between advisory and delivery
An advisory engagement gives you guidance while your team writes the documentation. This works when you have people who can write to a regulatory standard and need direction on what it should contain.
A delivery engagement means the firm writes the technical files, builds the classification record and stands behind the reasoning. This costs more and is the usual fit where nobody internal has written for a supervisor before.
The question that separates them in a proposal is who writes the Annex IV file. Ask it directly.
What to do next
Start with the inventory, because the scope of everything else depends on it and because it is the one part you can begin without a supplier.
Our free AI impact assessment gives an immediate first view, and the EU AI Act service page sets out how we run each workstream.
References
FAQ
What do EU AI Act consultancy services include?
Inventory, classification, gap assessment, documentation including Annex IV technical files, control build, and ongoing monitoring.
How much do EU AI Act consultancy services cost?
Commonly £15,000 to £50,000 for a first programme, with individual technical files at £8,000 to £25,000 each. Cost scales with system count, not headcount.
Can a consultancy certify us under the AI Act?
No. Most systems are self-assessed. Where third-party conformity assessment applies, it comes from a notified body, not from your adviser.
Which workstream matters most?
Classification. Every obligation, date and cost in the programme follows from it.
Does the engagement end when the documentation is written?
It should not. Post-market monitoring and incident reporting continue for the life of the system, so ask what happens after the build.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance. We do the work, hold the deadline and stand behind the evidence, across the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001. We are not a certification body and we take no commission from certification bodies or platform vendors. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised payment and e-money firms on authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.