Your people are already using it. Your product probably depends on it. Your customers and your insurer have started asking about it. AI governance is working out which obligations actually bind you, writing down the rules, and checking every month that they’re being kept — measured against ISO/IEC 42001, the standard the questionnaires will quote at you next.
ISO/IEC 42001 readiness assessment · three weeks · $12,500 ex GST, fixed · every finding signed by a named practitioner
Boards are being asked two questions at once — are we allowed to use this? and what happens when it goes wrong? — and most businesses have answered neither.
A browser tab, a vendor feature flag, a developer’s API key. There is no register of what runs where, on whose data, under whose approval.
Enterprise customers, insurers and tenders now ask how you govern AI in the same breath as ISO 27001 and Essential Eight. ‘We have a policy’ is no longer an answer.
A two-page acceptable-use policy nobody can enforce is where most businesses stop. Governance is the policy plus the inventory, the risk register, the approval gate and the monthly check that it’s still true.
The Privacy Act applies to what you put into a model. Your customer contracts apply to what you build with one. Sector rules apply regardless of the tool. None of that waits for a standard.
Start with the assessment if you need the number. Start with the framework if you already know the gaps. Put it inside the monthly close if you want it kept true. Brief the board if that’s where the question is coming from.
A scored baseline against 42001, with the obligations mapped from your contracts, the Privacy Act and your sector. We build the AI inventory with you and hand back a prioritised, costed roadmap. Three sessions, under three weeks.
$12,500 ex GST, fixed.
Acceptable-use policy, AI risk register, model and vendor inventory, approval gates, and incident handling for when a model does something it shouldn’t. Written to be operated by your people, not filed.
Scoped on the call.
AI risk, inventory changes and policy exceptions become standing items in the monthly close report and the executive session — the same ten things, same order, every month.
Part of the Sheep Dog vCISO retainer.
One session with the board or the executive: which AI obligations bind this business, what you actually have to decide, and what ‘under control’ looks like in twelve months.
Scoped on the call.
Same loop as everything else Securitribe runs. The assessment gives the first score. The framework is the embedding. The monthly close re-measures it and puts the number in front of the board. Nothing here is a report that sits in a drawer.
Where you stand against ISO/IEC 42001, weighted by which clauses your obligations actually invoke. A number, not an opinion.
The high-risk gaps first, each with a cost and a date. The roadmap is the report.
Policy, inventory, register and approval gates, operated by your people. Configured, not just bought.
Same standard, new score. Monthly inside the close, or at the end of the framework engagement.
One page the board can read: the score, what moved, what they have to decide.
And one we’ll tell you for free: if AI governance isn’t actually required in your situation, we’ll say so in writing — even though we sell it.
Who does the work. Team-delivered; nothing leaves without Ashley reading it. His name is on the report, so the judgement in it is his — twenty years across mining, banking and Defence, ISO 27001 delivery, and a practitioner who builds AI platforms rather than reads about them.
Thirty minutes, no prep. We’ll work out which obligations — AI and otherwise — actually bind your business, and whether the 42001 assessment is the right next step or not. If it isn’t, we’ll say so.