Where does your AI risk actually sit?
Two outputs. One clear picture.
Executive Scorecard
One page. Fourteen dimensions, each classified into a pillar and carrying an evidence state. The artefact your Chair can read in three minutes and your risk committee can table the same day.
- One page, PDF
- Classification and state on every line
- Exceptions named for the quarter
Detailed Findings Report
Ten to fifteen pages. Evidence reviewed, findings, prioritised remediation roadmap, control owners and standards mapping. The artefact your auditor and CISO will work from.
- Ten to fifteen pages, PDF and DOCX
- Every finding traced to an artefact
- Named owner and due date per gap
Fourteen dimensions. Four pillars.
- D01 · Strategy & alignment
- D02 · Accountability, ownership & transparency
- D03 · Risk appetite & tolerance
- D04 · Model governance
- D05 · Vendor & third-party governance
- D06 · Data governance, quality & protection
- D07 · Model security & integrity
- D08 · Identity & access management
- D09 · Supply chain & tooling security
- D10 · Monitoring & observability
- D11 · Incident response & recovery
- D12 · Change & release management
- D13 · Capability & skills
- D14 · Culture & awareness
* Data is classified into Protect, and is a dependency of all four pillars.
* Agentic AI is not a fifteenth dimension. A single agent typically touches seven of the fourteen at once.
Four weeks. Four phases.
Scope
Executive interviews, scope confirmation, evidence-request schedule. Stakeholder map agreed.
Evidence
Document review, control walkthroughs, system inventory, frontline input. Artefacts collected.
Score
Every dimension classified and stated against its threshold. Findings drafted, exceptions identified.
Report
Executive Scorecard finalised. Detailed Findings Report delivered. Board read-out optional.
Sector-tuned where it matters.
Banking & Finance
Tuned to APRA CPS 230, CPS 234, CPS 220 and AFSL obligations. Heavy emphasis on vendor AI risk and customer-facing decisioning.
Energy & Utilities
Tuned to the SOCI Act, CIRMP, AEMO and the AESCSF. Heavy emphasis on operational technology AI, grid events and control-system safety.
Master
Cross-sector edition for organisations spanning regulated industries, and for every sector without an edition of its own.
Board-ready. Auditor-defensible. Regulator-ready.
- 01
An Executive Scorecard your Chair can table at the next risk committee.
One page, fourteen lines, every one classified and stated.
- 02
A Detailed Findings Report your CISO and internal audit can work from immediately.
Every finding traced to the artefact that evidences it, or to the gap where none exists.
- 03
A defensible position before the auditor walks in or the regulator asks.
Dated, versioned, and re-evidenced on a cadence rather than rebuilt from scratch each cycle.
The first call is diagnostic.
Thirty minutes. No pitch. No proposal until it makes sense.