Make every AI governance claim traceable.
Four things a board can act on.
What AI exists
A register of every system, with an owner and a risk rating against each one.
What evidences it
The artefact behind each control, or the named gap where none exists.
Who approved it
A named human against every evidence item, with the date they reviewed it.
A record you can table
A dated, versioned pack for the board or the auditor, produced from the same entries.
Boards are signing AI attestations they cannot defend. Risk produces slide decks; audit asks for trace. Document stores hold policies without proving a human reviewed each control on each cycle.
Four phases. One traceable record.
Live AI register
Every AI system registered, owned and risk-rated.
Controls mapped
Mapped to the standards and guidance that apply to your organisation.
Human-approved
Requested from named owners, reviewed by a named human, traceable.
Auditor-followable pack
Version-stamped, delivered to your private portal, with an audit row written.
What the platform produces.
Live AI register
Every system, owner, lifecycle stage and data sensitivity.
Risk rating
Per-system rating with documented rationale, refreshed each cycle.
Control mapping
Each system mapped to the fourteen dimensions and to the standards that apply to you.
Evidence requests
Plain-English asks issued to named owners. Tracked, reminded, logged.
Human approval gate
Every evidence item approved by a named human reviewer. Appended, never overwritable.
State scorecard
Per pillar, per system, per cycle, stated as evidence states rather than a traffic light.
Evidence pack
A versioned PDF an auditor can follow end to end, with an attestation page for the sponsor to sign.
Gaps register
Named remediation owner and due date for every absent or partial dimension.
Client portal
Passwordless access to your packs, isolated from every other client, with every view logged.
You attest. We evidence.
- The assurance opinion, in every form it takes
- Whether the organisation is compliant, certified or assured
- Management, board, legal, risk, audit and regulatory accountability
- The decision to accept, remediate or tolerate every finding
- The attestation itself, and the signature on it
- The record of what human-reviewed evidence demonstrates
- A classification and a state for every dimension, on every cycle
- The trace from each board-level claim to its underlying artefact
- The named owner, the date and the review interval for each item
- The published pack, versioned, and the audit row that records it
We hold no interest in any tool we recommend.
No assessment of work we would be engaged to remediate.
No recommendation of ours creates a downstream interest for us.
The rule runs both ways, for twelve months either side of a Health Check.
The record is yours. Every register, assessment and evidence pack is delivered in a form you can keep current without Mycelium and without the platform.
The boundary is in the product.
Client isolation
Isolated by construction, not by policy.
Private evidence
Private storage, reached only through short-lived, single-use links.
Append-only audit
Every publication and view written to a record that cannot be altered.
Versioned packs
“What did we hold in March?” has a file as its answer.
Fail-closed drafting
Malformed output is rejected, never published.
Data residency
Australian by default. Source artefacts stay in your tenant.
Human review is mandatory on every evidence item, the gate is enforced, not advisory. Full architecture, control detail and penetration-test position are provided under NDA during procurement.
The AI Governance Evidence Pilot.
The questions buyers ask first.
- 01
Does the platform certify compliance?
No. The platform produces an evidence trail; assurance opinions remain with management, the board and the relevant assurance providers.
- 02
Where does the data live?
Source artefacts stay in your own tenant; Mycelium holds references and metadata only. Published evidence packs sit in private storage in an Australian region. The website, forms, scheduling and analytics we use process offshore, and the privacy policy sets out which is which.
- 03
Who can see another client’s data?
No-one. Any cross-client access attempt fails closed and is written to the audit record.
- 04
Does the AI decide anything?
No. Nothing publishes without a named human reviewer approving it, and drafted narrative is validated before publication.
- 05
Can I see a published evidence pack?
Yes. An anonymised sample is available from the reference library, built to the same structure as a live cycle. All entity names, identifiers and email addresses in it are illustrative.
- 06
Can the platform integrate with our GRC?
Yes, via documented export. Custom integrations are a paid extension after pilot.
- 07
Is the platform IRAP- or SOC 2-certified?
No. It is engineered to the relevant baselines, and certification will be pursued when a contracted client requires it. A Security and Trust Summary is available on request.
If your board is being asked to attest to AI governance, or your auditor is.
The Evidence Platform is the system that makes that attestation defensible.