The policy was never the problem.
Between what is true and what can be shown.
This practice closes that gap in the direction that matters: it makes the operating model produce evidence as a by-product of running, rather than as a project that runs before each audit.
An operating model that evidences itself.
- 01
Named accountability
Who is accountable at board and executive level, what they are accountable for, and what happens to the accountability when they leave.
- 02
A stated risk appetite
What the organisation has said it will and will not accept, written in terms that can be tested rather than terms that can be agreed with.
- 03
Lifecycle control
Approval, validation, monitoring and retirement for models; attestation and the material service provider test for vendors.
- 04
Agentic AI governance
Inventory, autonomy and consequence tiering, authority, identity, permissions, human approval and decommissioning, for the agents you build, buy or commission. See the specialism ↗
- 05
An evidence cadence
Quarterly, at material change, and on regulatory update, with named owners and a review date on every item.
- 06
A board reporting structure
A standing format for tabling AI risk in your audit and risk committee’s own language, with classification and state on every line.
You attest. We evidence.
- The assurance opinion, in every form it takes
- Acceptance of residual risk
- Management, board, legal, risk and audit accountability
- The attestation, and the signature on it
- The operating model and its control intent
- The evidence expectation at each of fourteen dimensions
- The trace from every board claim to its artefact
- The cadence, the owners and the review dates
Designed here. Kept current there.
Illustrative. Classification tells you which pillar the finding belongs to; the state tells you what exists.
The first call is diagnostic.
Thirty minutes. No pitch. No proposal until it makes sense.