Southbridge Consulting Services Ltd

Audit-grade AI for organisations that can't afford to be wrong.

We build permission-aware retrieval systems for UK financial services, the NHS and the public sector — with the documented evidence that supervisors and inspectors expect.

Cyber Essentials DSPT aligned SS1/23 methodology DCB0129/0160 ready UK incorporated

Six reasons most enterprise AI deployments
fail compliance review.

01

Heterogeneous documents

Policies, procedures and circulars scattered across SharePoint and shared drives. The system answers from contradictory sources.

02

Naïve chunking

Fixed windows that separate a decision criterion from its supporting analysis. The retrieved fragment looks plausible but lacks the context to be defensible.

03

Vector-only search

Semantic search misses exact strings: counterparty names, ISIN codes, regulatory rule numbers, ICD-10 codes. The content users most often search for.

04

No reranking

Top-five retrieval misses the truly relevant chunk. The model reasons confidently from the wrong evidence.

05

No evaluation set

Without curated real-user questions with scored answers, every change is a guess. Quality drift goes unmeasured until incidents reveal it.

06

No permission enforcement

Identity and access treated as a deployment-time concern. In a regulated workflow, an information barrier breach with regulatory consequences.

The first five sink the pilot. The sixth sinks the firm.

AI deployments in regulated industries succeed or fail on their evidence, not their engineering. Our methodology is structured so that every artefact a supervisor or inspector might ask for is produced as a delivery output — not reconstructed after the fact.

Permission-aware retrieval,
integrated at the data layer.

Southbridge builds retrieval-augmented AI systems that ground language models in your organisation's own documents while respecting the access controls already in place at the source.

The index itself respects the user's permissions through your existing identity provider — Microsoft Entra ID, AWS IAM Identity Center, or NHS Care Identity Service. Information barriers are enforced at the retrieval layer, not at the presentation layer. They are not bypassable by clever prompting.

Every answer cites the documents it drew from. Every retrieval is logged. Every change to the system is measured against a curated evaluation set. The audit trail is the deliverable.

  • Permission-aware

    Integrated with Entra ID and equivalent providers at the data layer. Information barriers respected by architecture, not by policy.

  • Audit-traceable

    Every retrieval logged. Every answer cited. Evidence produced as a delivery output, not a reconstruction.

  • Productised

    Discovery, Pilot, Production and Retained stages with defined outputs and defined timelines. No scope creep.

Built for two of the UK's
most regulated markets.

Vertical 01

Financial Services

UK banks, insurers, fintechs, wealth and asset managers, central banks and supervisors. Aligned to PRA SS1/23 Model Risk Management Principles, FCA Consumer Duty, Operational Resilience and the BoE/PRA AI Innovation framework. Bi-jurisdictional coverage including Nigerian financial services institutions under CBN and NDPA.

  • SS1/23
  • Consumer Duty
  • Op Resilience
  • CBN AI/AML
  • NDPA

Vertical 02

Healthcare & Social Care

NHS Trusts (acute, mental health, community), Integrated Care Boards, local authority adult social care and CQC-regulated private providers. Aligned to the NHS SBS Healthcare AI Solutions Framework, with clinical safety case work under DCB0129/0160 and Data Security and Protection Toolkit alignment.

  • DSPT
  • DCB0129/0160
  • DTAC 2.0
  • Caldicott
  • CE+

A structured pathway.
Built for how regulated buyers procure.

Engagements stack into a structured pathway. Each stage produces a defined output and a defensible internal decision point before committing to the next. No obligation to proceed beyond any given stage.

Stage 01

Discovery Sprint

Timeline: 1 week

A written diagnostic of your document estate, retrieval baseline against 20 real questions, prioritised remediation roadmap, and a draft DPIA template. Owned by you. No commitment to continue.

Stage 02

Pilot

Timeline: 6–8 weeks

Production-equivalent system for one named use case. Full model risk file. Evaluation harness with 100+ named questions. Limited release to a defined user cohort with measured outcomes.

Stage 03

Production

Timeline: 3–6 months

Wider rollout to the eligible population. Full SS1/23 or DCB0160 model record. Monitoring, alerting and incident response. Staff training, change management and handover.

Stage 04

Retained Optimisation

Timeline: Ongoing

Continuous evaluation. Model upgrades with re-validation before promotion. Quarterly business reviews. Ongoing model record maintenance as part of your inventory.

A deliberate position
between the categories.

We combine the engineering depth of a boutique, the regulatory fluency of a Big Four, the fixed-fee discipline of a SaaS vendor, and an identity-engineering moat rare in AI consultancies.

Permission-aware engineering depth

Microsoft Entra ID, AWS IAM Identity Center and NHS Care Identity Service integrations at the data layer. The sixth failure mode, solved by architecture.

Productised methodology

Structured Discovery Sprints make us procurable without lengthy commercial cycles. The pathway is designed for public-sector and regulated-industry procurement processes.

Sector regulatory fluency

SS1/23, Consumer Duty, Operational Resilience, Caldicott, DSPT, DCB0129/0160, DTAC, NDPA and CBN frameworks as native vocabulary.

UK incorporated, founder-led

Registered in England and Wales. UK-resident founders with bi-jurisdictional reach into the Nigerian financial services market.

Written-first culture

Every engagement begins and ends with a written artefact you own. No verbal hand-waving on what was delivered or what comes next.

Aligned to the frameworks
your organisation already runs on.

PRA SS1/23Model Risk Management Principles
FCA Consumer DutyPRIN 12
Operational ResilienceSS1/21 · PS21/3
DCB0129 / DCB0160Clinical Safety
DSPTData Security & Protection Toolkit
DTAC 2.0NHS Digital Assessment Criteria
Caldicott Principles2020 refresh
Cyber EssentialsPlus in progress
UK GDPRData Protection Act 2018
CBN FrameworkAI/AML · Cybersecurity
NDPANigeria Data Protection Act 2023
ISO 27001Readiness in progress

Start with a Discovery Sprint.

One week. A written diagnostic owned by you. No obligation to continue.

Get in touch

hello@southbridgeconsulting.services