Loading…
Loading…Loading…
Loading…AI Governance and Security · Assessment
Know every AI tool touching your data, what it can reach, and who let it in.
A read-only assessment that inventories every AI tool and AI-connected application in use across your organisation, maps the data each one can reach and under whose authority it was granted, and hands you a keep, restrict or revoke decision for each. One to two weeks, a couple of hours of your time.
Discuss this engagementWho this is for
Your people are already using AI. In most organisations it arrived one person at a time: a drafting assistant here, a meeting summariser there, a plug-in that offered to read the inbox and was allowed to. Each choice was reasonable. Together they add up to a set of standing permissions over your email, your files and your customer data that nobody has listed, let alone approved.
The exposure is rarely where leadership expects it. The browser tab someone types into is visible and usually harmless. The application that was granted permission to read every message and file in the organisation, by an employee who left last year, is neither. When a customer, an insurer or a regulator asks what AI touches their data, the honest answer today is usually that nobody knows.
At the end of the engagement you hold an inventory you can defend. Every AI tool and AI-connected application in use, which parts of the business use it, exactly what data and permissions it holds, and who granted them. Each item carries a risk ranking and a recommended decision, so the conversation with leadership is about choices rather than discovery.
You also learn something the inventory alone does not show: which business needs are driving unsanctioned use. That list usually points to two or three tools you should be providing properly, which is the difference between a governance exercise that restricts and one that enables.
The goal is not to catch anyone. It is to replace a guess with a record.
A scoping call to agree the platforms in scope, typically your collaboration suite and identity provider, and to provision read-only access
We inventory connected applications, permission grants and AI features from the platforms' own audit and administration data, which records activity regardless of whose device produced it
We map each tool to the data it can reach and rank it by vendor data handling, permission scope and sensitivity
A two-hour findings session with your nominated data owner to test the ranking against how the business actually works
A written report and a decision list, delivered with a short note on what to do first
Nothing is changed by us during the assessment. Where a revocation or restriction is recommended, your administrators make the change with our guidance, which keeps you in control of your own environment.
A complete inventory of AI tools and AI-connected applications, and the parts of the business using each. The exact data and permission scope each one holds, and under whose authority it was granted. A risk ranking and a keep, restrict or revoke recommendation per item. A short approval process for future connections, so the list does not simply regrow. And a view of the unmet needs behind unsanctioned use, which is often the most useful page in the report.
Keep the approval process running and the inventory stays current; where you want new AI connections flagged as they appear, we can monitor for them as part of the controls build.
The engagement

From Email Migration to Full-Spectrum Business Partnership

Strategic Growth Partnership

A private professional network for trusted member discovery, workspace coordination, relationship context, and internal admin workflows.
Anything that sends your data to a model: consumer assistants used through the browser, AI features switched on inside the software you already pay for, and third-party applications granted standing permission to read your email, files or calendars. The last group is where most of the exposure sits, and it is the group nobody has usually reviewed.
No. The assessment runs on read-only access and log data. Nobody is asked to stop using anything while it runs, and no setting is changed by us. The findings session is the only time we need from your people beyond the initial scoping call.
A written inventory of every tool and connected application, the data and permission scope each holds, a risk ranking based on the vendor, the scope and the sensitivity of what is reachable, and a recommended keep, restrict or revoke decision for each item. It is written so a general counsel or a board can read it without a technical translator.
Yes, and it is designed to. Governance advisors decide what AI should and should not do in your business. This assessment gives that work its facts. We deliver the findings in a form their assessment can rely on and stay available to them for questions.
A conversation first, then a written scope.
Discuss this engagement