Thistlewood Assurance builds and maintains AI management systems for fintech and HR-technology companies that already hold, or are pursuing, ISO 27001 or SOC 2. The London team of around thirty splits its time between client sites in the City and remote delivery, and most engagements begin when a bank, insurer or enterprise customer adds ISO/IEC 42001 to a vendor due-diligence pack. A gap analysis takes three to four weeks and produces a control-by-control mapping against the client's existing ISMS, a risk register for in-scope AI systems and a costed remediation plan. Implementation projects run four to six months and are quoted as a fixed fee, with a monthly retainer available afterwards for internal audit support, supplier reviews and management-review preparation. Thistlewood drafts the policy set rather than handing over templates, and expects the client to nominate an owner for each control. It does not issue certificates, act as a certification body, or give legal opinions on the EU AI Act; where those are needed it introduces accredited bodies and law firms it has worked alongside. Pricing bands are shared on request and do not change with company size.