AI Governance
Policy, controls and audit readiness for AI systems, including the agentic gap that none of the established frameworks was written to cover.
Most organisations do not need a new AI policy. They need to know which of their existing controls apply to AI, which do not, and what is now uncontrolled.
This engagement answers that, and produces the evidence that a customer, an auditor or a regulator will actually ask for.
The framework position, stated plainly#
Checked 9 August 2026. Most enterprises run three frameworks together, each doing a different job:
| Layer | Framework | What it is for |
|---|---|---|
| Values | OECD AI Principles | What the organisation says it stands for |
| Internal risk model | NIST AI RMF | Flexible, risk-based, not certifiable |
| External proof | ISO/IEC 42001 | The certifiable management system procurement asks about |
None of the three was designed for autonomous agents. Anyone deploying agents has to extend them by hand to cover cascading failures, scope creep and attribution gaps. Singapore's Model AI Governance Framework for Agentic AI, published January 2026, is the first written for them, and its central principle is that an agent cannot be a principal: the organisation stays responsible, a human stays accountable, and delegation must be explicit and bounded.
That gap is the part of this work with the least off-the-shelf help available, and it is the part we spend the most time on.
What happens#
- Obligation mapping. What applies to you, from regulation, contracts and customer commitments. Anything unmapped is a gap, recorded today rather than at the next audit.
- Control mapping. Which existing control satisfies each obligation. The subtler failure is a mapping table that looks complete and is not.
- The agentic extension. Where your agents act, what they can reach, and who answers when one is wrong.
- Evidence design. How each control will be evidenced as work happens, rather than reconstructed before an audit.
- The gap register, with owners and dates.
What you receive#
- The obligation-to-control map, with the gaps named
- Control records stating how each is evidenced and who owns it
- A gap register with dates, not intentions
- An attestation process that separates monitoring from asserting, because a system that both watches a control and declares it passing has no independent element in it
The distinction we insist on#
A control is operating, failing, or unevidenced. Three states, never two.
"No failure detected" is not a pass, and folding unevidenced into operating is how a control quietly stops working for eight months while every report stays green.
What we will not do#
- Write a policy nobody will follow so a questionnaire can be answered.
- Certify anything. We prepare you for an audit; we do not conduct it, and a supplier who offers both should worry you.
- Tell you a regulation does not apply without writing down why. A no with no reasoning gets reopened every quarter.
How we work, in public#
Our own governance and security functions are published, including what we refuse to automate and why the human approval gate between a risk score and a response is not a maturity stage to be outgrown.
Get in touch with the obligation you are least confident about.