AI Governance Assessment
Assess current AI usage, systems, agents, risks, ownership, policies, data access and human oversight against a defined control set.
Agents that can act inside your systems are a new class of privileged identity. They need to be governed like one.
Copilots were bought by departments. Agents were built by a project team. Staff paste company data into consumer tools. Each is defensible alone; together they are an ungoverned surface with no inventory, no owner and no audit trail.
The moment an AI system can read your data and call your tools, it becomes part of your attack surface and your compliance perimeter. We help organizations establish the inventory, policy, permissions, guardrails, monitoring and audit trail that make scaling AI a controlled decision rather than an accepted risk.
Controls that live in the prompt can be talked around. These do not.
Engagements draw on a subset of these, scoped to the outcome you are buying.
Assess current AI usage, systems, agents, risks, ownership, policies, data access and human oversight against a defined control set.
A single register of what exists, who owns it, what it does, what data it reads, what tools it can call and what risk tier it sits in.
Practical policy covering acceptable use, sensitive data, model usage, agent autonomy, human approval thresholds, employee AI use and internal development standards.
Autonomy tiers agreed with the business: categorizing an email is not drafting an external reply, and neither is authorizing a payment.
Identify and classify operational, data, model, business, security and compliance risk, with owners and mitigations attached to each.
Continuous evaluation of accuracy, reliability, hallucination, policy compliance, task performance and safety — with results that survive an audit.
Identify vulnerabilities across models, agents, integrations, data pipelines, prompts, tools, APIs and permission models.
Prompt injection, data leakage, unauthorized tool use, excessive agent permissions, malicious documents, compromised integrations and insecure agent-to-agent interaction.
Who may invoke an agent, what it may access, which tools it may call, and which actions it may perform — enforced, not documented.
Every agent scoped to the minimum permission its task requires, with elevation as an explicit, logged and time-bound event.
Technical controls on what an AI system can access, say, call and do — enforced outside the prompt, where they cannot be talked around.
Behaviour, tool usage, data access, failures, anomalies, cost and performance monitored in production — with a durable record of what happened, to what data, and who approved it.
Adversarial testing against prompt injection, unsafe behaviour, information leakage and unexpected workflow paths, before someone else finds them.
These are illustrative constructions, not client case studies. We do not publish customer names, savings figures or results we have not verified.
The problem
AI systems have been introduced by several teams. Risk and IT cannot produce a list of what is running, what it can reach, or who signed it off.
What we would build
An agent registry capturing every AI system with its owner, data scope, tool permissions and risk tier, alongside an agreed autonomy model defining which actions require human approval.
How it works
Potential business impact
Leadership gets a single answer to “what AI is running here”, and every future deployment enters through a defined door.
The problem
An agent reads supplier documents and can call internal tools. The documents come from outside the organization and are treated as trusted input.
What we would build
A structured red team exercise attempting to steer the agent through crafted document content, followed by remediation of the tool and permission model rather than the prompt alone.
How it works
Potential business impact
Untrusted content is treated as untrusted, the tool surface is narrowed to what the task needs, and the failures become permanent regression tests.
Where we set out the reasoning, in more detail than a capability list allows.