// secureos · govern

AI governance: know what your business is allowed to do with AI — and prove it’s under control

Your people are already using it. Your product probably depends on it. Your customers and your insurer have started asking about it. AI governance is working out which obligations actually bind you, writing down the rules, and checking every month that they’re being kept — measured against ISO/IEC 42001, the standard the questionnaires will quote at you next.

ISO/IEC 42001 readiness assessment  ·  three weeks  ·  $12,500 ex GST, fixed  ·  every finding signed by a named practitioner

// sound familiar?

AI arrived through the side door. The obligations came in with it.

Boards are being asked two questions at once — are we allowed to use this? and what happens when it goes wrong? — and most businesses have answered neither.

// 01

Nobody owns it

A browser tab, a vendor feature flag, a developer’s API key. There is no register of what runs where, on whose data, under whose approval.

// 02

The questionnaire has changed

Enterprise customers, insurers and tenders now ask how you govern AI in the same breath as ISO 27001 and Essential Eight. ‘We have a policy’ is no longer an answer.

// 03

A policy is not governance

A two-page acceptable-use policy nobody can enforce is where most businesses stop. Governance is the policy plus the inventory, the risk register, the approval gate and the monthly check that it’s still true.

// 04

The obligations are already binding

The Privacy Act applies to what you put into a model. Your customer contracts apply to what you build with one. Sector rules apply regardless of the tool. None of that waits for a standard.

// what we deliver

Four ways in. One loop underneath.

Start with the assessment if you need the number. Start with the framework if you already know the gaps. Put it inside the monthly close if you want it kept true. Brief the board if that’s where the question is coming from.

// one · fixed price

ISO/IEC 42001 readiness assessment

A scored baseline against 42001, with the obligations mapped from your contracts, the Privacy Act and your sector. We build the AI inventory with you and hand back a prioritised, costed roadmap. Three sessions, under three weeks.

$12,500 ex GST, fixed.

// two · scoped

AI governance framework and policy suite

Acceptable-use policy, AI risk register, model and vendor inventory, approval gates, and incident handling for when a model does something it shouldn’t. Written to be operated by your people, not filed.

Scoped on the call.

// three · monthly

AI governance inside the Monthly Security Close

AI risk, inventory changes and policy exceptions become standing items in the monthly close report and the executive session — the same ten things, same order, every month.

Part of the Sheep Dog vCISO retainer.

// four · one session

Board AI briefing

One session with the board or the executive: which AI obligations bind this business, what you actually have to decide, and what ‘under control’ looks like in twelve months.

Scoped on the call.

// how the work runs

Baseline. Prioritise. Embed. Re-measure. Show the board.

Same loop as everything else Securitribe runs. The assessment gives the first score. The framework is the embedding. The monthly close re-measures it and puts the number in front of the board. Nothing here is a report that sits in a drawer.

// 1

Baseline, scored

Where you stand against ISO/IEC 42001, weighted by which clauses your obligations actually invoke. A number, not an opinion.

// 2

Prioritise, dated

The high-risk gaps first, each with a cost and a date. The roadmap is the report.

// 3

Embed

Policy, inventory, register and approval gates, operated by your people. Configured, not just bought.

// 4

Re-measure

Same standard, new score. Monthly inside the close, or at the end of the framework engagement.

// 5

Board visibility

One page the board can read: the score, what moved, what they have to decide.

// who it fits

Who this is for — and who it isn’t

It fits if

  • You’re one Australian legal entity, roughly 20 to 200 people
  • AI is already in use in operations, or shipping in a product — or both
  • A customer, insurer, tender or board is asking the question, or you want the answer before someone does
  • You’d rather have a score and a plan than a policy PDF

It’s quoted instead if

  • You’re several entities, or 200-plus people — same method, scoped on the call
  • The AI is itself regulated product — medical device software, credit decisioning — and needs its own scope
  • You need a certification body — we get you ready, we don’t certify

And one we’ll tell you for free: if AI governance isn’t actually required in your situation, we’ll say so in writing — even though we sell it.

Who does the work. Team-delivered; nothing leaves without Ashley reading it. His name is on the report, so the judgement in it is his — twenty years across mining, banking and Defence, ISO 27001 delivery, and a practitioner who builds AI platforms rather than reads about them.

// next step

Start with the free Obligations Check.

Thirty minutes, no prep. We’ll work out which obligations — AI and otherwise — actually bind your business, and whether the 42001 assessment is the right next step or not. If it isn’t, we’ll say so.

// questions

Straight answers

Do we need ISO 42001 certification?

Almost never yet. Readiness against ISO/IEC 42001 is what customers, insurers and tenders are starting to ask for; certification is a later, separate decision that needs a certification body. We get you ready and tell you honestly whether certifying is worth it for you.
The ISO/IEC 42001 clauses and Annex A controls, weighted by which of them your obligations actually invoke — your contracts, the Privacy Act, your sector’s rules. You get a score, the gaps ranked by risk, and a costed roadmap. Three sessions, under three weeks, $12,500 ex GST fixed.
No — it sits on top of it. Most of the management-system scaffolding is shared, so if you already run an ISMS we build on it rather than making you build it twice.
Then the assessment is shorter and the answer is mostly policy, inventory and training. The price is still fixed; you’ll get change from three weeks.
$12,500 ex GST for a single Australian entity of roughly 20 to 200 people with one product or operating environment in scope. Outside that, we scope and quote the same method on the call rather than squeeze you into a price that doesn’t fit.
Team-delivered; nothing leaves without Ashley reading it. His name is on the report, so the judgement in it is his.