AI Governance Audit

Your organisation is already using AI.
Can you prove it's under control?

A structured audit that maps every AI system in use across your firm, classifies each against EU AI Act and Australian guardrail requirements, and produces a board-ready remediation roadmap — in five defined steps, not an open-ended engagement.

BUILT FOR AU FINANCIAL SERVICES — LENDERS · SUPER FUNDS · INSURERS
The Problem

The gap isn't your AI use. It's what you can prove about it.

Regulators have moved past asking whether firms use AI. They're asking whether firms can document it.

01

Shadow AI accumulates quietly

Tools enter workflows through vendor features and individual adoption — long before procurement or risk teams are aware they exist.

02

"We didn't know" is not a defence

APRA's CPS 230 extends operational risk expectations to AI vendors. Undocumented use is itself a governance failure, regardless of intent.

03

Exposure surfaces at the worst time

Without a register and risk classification in place, the first time gaps appear is usually during an incident, audit, or regulator enquiry.

The Process

Five defined steps. A fixed scope. No open-ended engagement.

01
Discovery
Structured interviews with department heads and IT leadership surface every AI system in active use — including shadow IT and vendor-embedded features never formally procured.
You provideStakeholder access, known vendor list, existing IT asset records.
02
Inventory
Every identified system is documented in a centralised governance register — ownership, vendor, technique, data types accessed, operational status.
You provideSystem documentation, vendor data-processing agreements, ownership confirmation.
03
Risk Classification
Each system is assessed against EU AI Act risk tiers, applicable Australian guardrail requirements, and an internal risk score weighted by data sensitivity and decision impact.
You provideContext on how each system's output is used — automated decision vs. human-reviewed recommendation.
04
Gap Analysis
Current controls — approvals, review cadence, incident logging, documentation — are measured against regulatory requirements and ISO 42001 control objectives.
You provideExisting policies, approval records, any prior incident or complaint logs.
05
Remediation Roadmap
Gaps are prioritised by risk severity and regulatory deadline into a sequenced action plan with clear ownership and target dates.
You provideConfirmation of internal resourcing and timeline constraints.
What You Receive

Five concrete deliverables. Not a slide deck.

AI System Inventory Register

A structured, exportable register of every AI system identified — the foundation of an audit-ready governance position.

Risk Classification Report

Every system mapped to EU AI Act categories and applicable Australian guardrail requirements.

Gap Analysis Report

Control deficiencies identified system by system, benchmarked against ISO 42001 control objectives.

Prioritised Remediation Roadmap

A sequenced action plan with clear ownership and target dates, ordered by risk severity and regulatory deadline.

EU
EU AI Act
Risk-tier classification with extraterritorial reach for firms serving EU clients or counterparties.
AU
APRA CPS 230
Operational risk obligations extended to material service providers, including AI vendors.
AU
ASIC RG 271
Conduct expectations applied to AI-assisted decisions affecting customers.
ISO
ISO/IEC 42001
The international AI management system standard, increasingly referenced by auditors and procurement teams.
Questions

What firms ask before engaging.

How long does the audit take?
Scope and timeline are confirmed during the discovery call, based on the number of systems and departments involved. Most engagements follow the five-step process sequentially rather than running open-ended.
Does this replace our compliance team?
No. The audit gives your existing compliance and risk functions a structured, AI-specific baseline they can own and maintain — it is designed to extend internal capability, not substitute for it.
Is this legal advice?
No. This is an advisory and information service. Findings and recommendations support internal governance decisions but do not constitute legal advice — firms should engage qualified legal counsel to confirm obligations specific to their circumstances.
What happens after the discovery call?
If there's a fit, you receive a scoped proposal covering timeline and investment before any engagement begins. There is no obligation arising from the discovery call itself.

Find out where your AI governance actually stands.

A free 30-minute discovery call — no pitch deck, no obligation. We'll discuss your current AI use and whether an audit is the right next step.

Book a free discovery call