Back to 1AYM

About

About 1AYM.

1AYM is an enterprise AI and platform consultancy and an OpenAI Select Partner, founded by Tayyeb Mahmud. We work with clients across the UK, the US and the Gulf, with people in the US and the UK and associates around the world. We take organisations from AI ambition to governed production systems their people use every day: executive discovery, architecture, hands-on engineering, governance, rollout and measurement. Every engineer here is either certified on the platforms we build on, or has shipped inside a top-tier engineering organisation, and we scale the team to the contract.

What separates us from an advisory firm is that the people who write the strategy write the code. A plan a board can fund and an engineer can start on Monday needs both halves written by the same firm, and the second half is where most AI programmes stop. Client environments depend on our work every working day.

Delivery in each place has a receipt: one client environment runs on Postgres in Google Cloud’s Doha region to meet Gulf data-residency requirements, and another reached 91% adoption in North America, a figure published in the Anthropic customer case study.

How we work

Five stages, in this order.

The three stages on the homepage, opened out into the steps a programme actually passes through. Each one ends with something written down and handed over, so a programme can stop after any of them and still own what it paid for.

  1. Discovery

    Sessions with the executive sponsor and the people who do the job today. What the outcome is worth, what stands in the way of it, and how it will be judged.

    You leave with the outcome written down, what it is worth, and the measure it will be judged against.
  2. Opportunity and feasibility

    What data exists and who may see it, which systems have to be touched, which models and tools fit, and what security, governance and adoption risk each candidate carries. Scored, so the sequence is defensible.

    You leave with a scored shortlist, with the data, security and adoption risk set against each candidate.
  3. Architecture and operating model

    Target architecture, context strategy, access control, human review, evaluation, observability, and who owns each part of it once we are gone.

    You leave with the target architecture and the operating model, with an owner named against each part.
  4. A working slice, then a controlled pilot

    One real workflow, end to end, in your systems and against your data. Then deterministic checks, thresholds and human approval sized to the risk, tested on representative data before anyone depends on it.

    You leave with working software in your environment, and evidence of what it does.
  5. Production, enablement and measurement

    Identity, monitoring, release control and incident handling, then documentation, training and handover to your own team. Adoption, cycle time and cost are measured, so the change is reported rather than asserted.

    You leave with a running system, a team that can maintain it, and numbers for the board.

How it is bought

Three commercial shapes. A fixed-scope statement of work with defined outputs, a defined price and acceptance criteria written into it. A retained implementation engagement covering architecture, build and enablement, typically two to three days a week. Or engineers embedded in your own programme on a contract from three months, where the constraint is capacity rather than a scoped deliverable. Where you already have a scoped job, 1AYM can also resource it on contract from the collective of associates who work with the firm, held to the same standard as the rest of 1AYM.

In every case it is one supplier and one contract. Where a programme needs more engineers we scale the team to the contract, and every one of them is held to the same standard.

Public-sector buyers can work with 1AYM through G-Cloud via our partner BAPRO. BAPRO is the delivery partner and 1AYM is the AI partner, across everything 1AYM offers.

The five named engagementsBuying through G-Cloud

Governance and data

Governance is risk-based and built as controls rather than written as a policy: use-case approval, data-sensitivity classification, least-privilege and default-deny access, audit logging that records refusals as well as answers, deterministic validation and human approval sized to the risk, and staged rollout with monitoring behind it. A governance platform can hold the register and the evidence these controls produce. It cannot enforce them inside systems it is not connected to, and our guide to what AI governance software does sets out where that line falls.

We work to UK GDPR and the Data Protection Act 2018, plus whatever your sector adds, and we architect for data residency where a region is a requirement. We hold no ISO or SOC certification, and we do not imply one. If your policy makes one a hard requirement, we are the wrong supplier. If it allows other evidence, our guide to vetting an AI supplier without a SOC report sets out what to ask for instead.

Who you'll meet

The engineers on your work.

Every engineer here is either certified on the platforms we build on, or has shipped inside a top-tier engineering organisation: Meta, Spotify, UBS, Starling Bank, S&P Global, Sky. We scale the team to the contract.

The senior engineers you will meet first

Tayyeb Mahmud

Founder and Principal Architect

10+ years

AI adoption, agent systems, and Claude and OpenAI platform architecture. Sits with the sponsor, sets the standard, and still writes the code.

Certification

Holds both Anthropic Claude certifications, Architect – Professional and Associate – Foundations, verifiable on Credly.

In production

A large international marketing agency · a government-accredited EdTech

LinkedIn profile of Tayyeb Mahmud

Principal Engineer

14 years · London

Data platform work, and the context and memory architecture that decides what an AI system is allowed to see, keep and recall.

Shipped inside

Meta · Spotify · Viasat/Inmarsat

Principal Data Engineer

17 years · London

Pipeline orchestration, CI/CD and data infrastructure: the layer most AI programmes are actually blocked on once the model choice is settled.

Shipped inside

Starling Bank · UBS · S&P Global · Sky · Société Générale

We name colleagues only with their permission. We name a client only where it has published the work with us. 1AYM delivers the work, and the role, the years and the organisations on each card are the standard being met. You meet the engineers before you sign anything.

The credential record

Status and certification

What we claim, in its exact wording.

One company status and two personal certifications. They are different kinds of thing, and the difference is worth stating plainly.

  • OpenAI Select Partner
    OpenAI Select Partner
  • Claude Certified Architect – Professional
    Claude Certified Architect – Professional · Held by Tayyeb Mahmud, founder · Verify on Credly
  • Claude Certified Associate – Foundations
    Claude Certified Associate – Foundations · Held by Tayyeb Mahmud, founder · Verify on Credly

OpenAI Select Partner is a company status, held by 1AYM and awarded after a partner agreement, a compliance review and a technical assessment. It belongs to the firm rather than to any individual, and it is written that way everywhere on this site.

The two Claude certifications, Architect – Professional and Associate – Foundations, were issued by Anthropic in July 2026 on passing a proctored exam. They are personal credentials held by our founder, and each one verifies on Credly in under a minute.

Two things to be precise about, because they are the two most often blurred. A partner status is not a certification, so we never fold the two into one phrase. When both are stated, they are two sentences: “1AYM is an OpenAI Select Partner.” and “Our founder and principal architect holds Anthropic’s Claude Certified Architect credential.” And Anthropic issued the two credentials above to an individual.

Our OpenAI Select Partner statusThe credential record, verbatim from Credly

Company details

Our official website is 1aym.com. The impersonation notice names the domains and the app that use our company identity without permission.

Registered company informationImpersonation noticePrivacy notice

Bring one workflow.

Half an hour is enough to tell you whether we can help, what it would take, and roughly what it would cost. We will say plainly when the answer is that you do not need us.

Last reviewed · 1AYM