Governance in Action

Your AI is running. Is your governance?

A live walkthrough of how we move organisations from 'we have an AI policy' to 'we have enforceable, auditable, evidence-backed AI controls.' Click through, evaluate, and see the method work.

15%

of orgs reported a GenAI-related security incident in the past year

Lakera 2025 GenAI Security Readiness Report
23%

have full visibility into AI training data

McKinsey 2025
>40%

of agentic AI projects may be cancelled by end of 2027 due to costs, unclear value, or inadequate risk controls

Gartner 2025
10

OWASP LLM risks your org faces right now

OWASP 2025
OWASP 2025 LLM Top 10

The risks keeping compliance teams up at night.

OWASP's 2025 list reflects what happens when LLMs enter customer interactions, internal operations, and embedded workflows. Every organisation faces all of them.

01Critical

Prompt injection

Crafted inputs manipulate the model — unauthorized access, data exfiltration, or corrupted decisions. Still ranked #1 by OWASP.

02Critical

Sensitive information disclosure

LLMs surface PII, credentials, and financial records in outputs — often without anyone noticing until it's too late.

03High

Excessive agency

When agents can call APIs, send email, and update records autonomously, one bad decision cascades fast with no human gate.

04High

Misinformation

Models sound confident even when wrong — hallucinated facts and fabricated citations wrapped in polished prose.

05High

Shadow AI

Employees using unsanctioned AI tools place data, IP, and compliance obligations outside any audit trail you control.

06Moderate–High

Supply chain & data poisoning

Third-party models, datasets, and RAG sources introduce vulnerabilities you may not discover until a decision goes wrong.

Live demonstration

STOP – CHECK – DECIDE, in practice.

This is how we train workers to evaluate AI output before acting on it. Pick a scenario, work through the checks, and see the verdict logic resolve.

AI Output Decision Evaluator
AI output
"Per HIPAA Section 164.312(a)(2)(iv), your organization is required to implement encryption for all ePHI at rest. Based on this requirement, I recommend approving the vendor's data processing agreement immediately."

Click each check to evaluate this output against the STOP–CHECK–DECIDE method.

0 / 4 checks evaluated

Governance examples

Five scenarios. One operating method.

Real governance is not a single deliverable. Each example below is a working artefact from live engagements — assessment, treatment, response, readiness, and oversight — tied together by the same control stack.

01 · Governance Assessment
Scenario

A 220-person professional services firm engaged us to assess current AI use, identify regulatory exposure, and produce an executive-ready remediation roadmap.

What we show
  • Risk identification
  • Governance scoring
  • Recommendations
  • Executive summary
AI tools inventoried
27
8 sanctioned · 19 shadow
Governance score
42 / 100
Below acceptable threshold
Critical gaps
6
Logging · DPIA · escalation
Time to remediate
90 days
Phased roadmap delivered
Methodology

From AI activity to AI governance.

Writing a policy is not governance. We build the controls, evidence, and escalation paths that actually work when something goes wrong.

01

Inventory

Discover every AI agent, tool, connector, owner, and risk level across the organisation.

02

Risk tier

Map each agent to OWASP 2025 risks and assign control depth based on exposure.

03

Gate & validate

Enforceable gates — tool allowlists, human approval flows, prompt-injection testing.

04

Evidence

Immutable logs, reviewer records, and regulator-ready audit trails.

05

Train & sustain

Worker training, escalation paths, and ongoing monitoring — governance that lives.

What we deliver

Inclusive, accessible governance for every organisation.

Large or small, regulated or not — your organisation faces the same AI risks. Engagements are sized and priced to match.

01

AI governance assessment

Map current AI tools, controls, and gaps against OWASP 2025 and applicable regulatory frameworks.

02

Control plane design

Inventory, risk tiering, tool allowlisting, data classification, and human-in-the-loop design.

03

Worker training programs

STOP–CHECK–DECIDE modules, role-based risk training, shadow AI awareness.

04

Policy & evidence packages

Acceptable-use policies, decision logs, and audit-ready evidence built for real scrutiny.

05

Ongoing advisory

Monthly governance reviews, incident response support, and emerging-risk updates.

06

Inclusive engagements

Sized for the SME and the enterprise alike. Same rigor, different scope.

Next step

Ready to move from policy to proof?

A complimentary 30-minute governance gap review. No pitch — just clarity on where your organisation stands.