Ten domains, assessed in one sitting
Ten domains, one focused session
Each domain is tested against how the work actually happens, not against what the policy says should happen. These are the questions the session works through.
AI ownership and accountability
Who is the named owner of each system, and whether that ownership still holds once the system starts making decisions without a person in the loop.
AI and agent inventory
A single register of every model, assistant, agent and embedded AI feature in use — including the ones that arrived through a vendor update rather than a project.
Data and system access
What each tool can actually reach — documents, customer records, internal systems — measured against what it needs to do its job.
Human approval and escalation
Where a person signs off, what triggers an escalation, and whether those gates hold when the work is urgent.
Agent autonomy and decision boundaries
The limits on what an agent may do unsupervised: transaction sizes, irreversible actions, external communication and onward tool use.
Risk classification
Whether AI use cases are rated consistently, and whether that rating actually changes the controls applied to them.
Security and privacy controls
Prompt and output handling, retention, personal data flows, tenancy, and what your contracts say about model training.
Monitoring and audit trails
What is logged when an AI system acts, how long it is kept, and whether it would answer an auditor’s question six months later.
Policies and acceptable AI use
Whether written policy matches observed behaviour, and whether staff can tell what is permitted without having to ask.
Third-party AI and vendor risk
AI features arriving inside software you already bought, and whether any of it went through a review.
Every tool, agent and integration in one inventory
We map what is deployed, who uses it, what data it reaches and how much autonomy it holds — including the AI nobody formally approved.
- Microsoft CopilotOwned
- Support triage agentNo owner
- Finance forecasting modelOwned
- Vendor chat assistantUnreviewed
Control path
Where the controls hold, and where they quietly don’t
Approval gates, escalation routes, retention of audit trails, autonomy limits and third-party reach are each tested against how the work actually happens.
Who it’s for
Organisations already running AI in the business, not planning to.
- Using ChatGPT, Copilot or other GenAI tools across the business
- Piloting or deploying AI agents
- Moving AI from experimentation into production
- Preparing for ISO/IEC 42001 or enterprise AI governance requirements
- Fielding questions from the board, customers, risk teams or auditors
See where you actually stand
Thirty minutes, no preparation, and a ranked action plan at the end.