Our methodology

The Evidence-First Method.

Most AI governance work produces a document that describes good intentions. Ours produces evidence that controls exist and are operating, captured as you go, in a form a regulator or your board can read on any given day.

Continuous assurance, not a point-in-time checkbox. Four phases, each tied to a defined artefact.

Mapped to: NIST AI RMF / ISO/IEC 42001 / APRA CPS 230 / Privacy Act 1988 / EU AI Act
Phase 01

Map

You cannot govern what you have not located.

We inventory every AI system, data flow, and automated decision point, then classify each against the regimes that bind you: EU AI Act risk tiers, APRA and ASIC exposure, Privacy Act obligations, and ISO 42001 scope.

Output

An AI system inventory and risk classification that becomes the baseline the rest of the engagement is measured against.

NIST Map ยท ISO 42001 Plan

Phase 02

Frame

Nothing is governance for its own sake.

We set the governance architecture: policies, roles, accountabilities, risk appetite, and the operating model that holds them together. Every control is mapped to the specific obligation it discharges.

Output

A governance framework, policy stack, accountability map, and a control-to-regulation traceability matrix.

NIST Govern ยท ISO 42001 Plan

Phase 03

Control

Policy that sits in a folder is not a control.

We embed the framework into the workflows that actually carry risk: model lifecycle, approval gates, third-party onboarding, and incident handling. Evidence capture is wired into business as usual, not bolted on at audit time.

Output

Implemented controls, approval gates, model governance procedures, and a standing evidence trail.

NIST Measure + Manage ยท ISO 42001 Do

Phase 04

Assure

A maintained evidence position, not an annual snapshot stale the day after sign-off.

Independent, ongoing verification that the controls are working, reported at board and supervisory grade. This is where continuous assurance lives: an evidence position you can put in front of APRA, the FMA, or your risk committee whenever they ask.

Output

Assurance reports and a regulator-ready evidence pack, refreshed on a defined cycle.

NIST Manage ยท ISO 42001 Check + Act

Why the method ends in continuous assurance.

In its April 2026 letter to industry, APRA warned that most regulated entities rely on point-in-time, sample-based assurance that does not keep pace with the scale and speed of AI adoption. A model that stops at go-live leaves a gap a supervisor will find.

Phase 4 closes that gap. Board reporting and a defined refresh cycle carry the governance forward, so the evidence pack stays current between reviews. That is the operating model the regulator is asking for, and it is the part that holds up when the next obligation lands.

Every service sits inside a phase.

You can engage the whole method end to end, or start at the phase where your gap is. Each service below produces the artefact that phase contributes to the evidence pack.

See full service detail

Start with a map. Leave with an evidence pack.

Run the calculator for a baseline read on your exposure, then we scope the phase that fits where you are and outline the work to close the gap.

Run the free calculator

Get in Touch