AI governance foundations
Build a risk map from the use cases you actually run rather than from a generic framework.
— Operations & Process
Classifies and scores the risks carried by your actual AI use cases and maps each to practical controls and owners.
2–3 weeks → ~40 minutes
For a full population, not a sample
No coding required
— USE CASES
Build a risk map from the use cases you actually run rather than from a generic framework.
Score a proposed AI use case and attach the controls needed before it goes live.
Show, per use case, which risks are identified and which controls address them.
— HOW IT BEHAVES
The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.
Items are sorted into your categories using the same rules each time, which makes volume readable.
Assessment happens against criteria you control and weight, so the same standard applies on every run.
Results are placed into defined bands, so thresholds decide the outcome instead of individual interpretation.
Content is pulled into the same field structure every time, so records from different sources stay comparable.
Analysis runs against your actual structure and reporting lines rather than an assumed org shape.
Current external sources are researched during the run rather than recalled from training data, and the sources travel with the output.
AI governance stalls when the risk register is written in the abstract. AI governance foundations is the typical trigger — build a risk map from the use cases you actually run rather than from a generic framework. Get it right and the conclusion holds up in the room; get it rushed and it gets picked apart. Either way it costs roughly 2–3 weeks of experienced attention.
As a Skill, the work is already sequenced. You bring the evidence, and the run produces use-case-level risk classification and scores plus practical controls mapped to each risk. What sits between input and output is the codified method: thresholds, sequencing and the points where a human confirms a call — all of it visible and editable in the Skill. Net effect: 2–3 weeks down to ~40 minutes, no drift between runs, and every conclusion traceable back to the evidence behind it.
AI risk map exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.
Automation opportunity map
Maps team or function activities to automation potential, computing addressable effort and bucketing opportunities into a prioritised roadmap.
Control failure → incident RCA pattern engine
Joins control test results to incident logs by process to show where control failures are actually producing incidents, grouped by systemic weakness with residual risk quantified.
Process diagnostic
Inventories every process step with its owner, system, effort and wait time, tests each against bottleneck, duplication, handoff and control-gap lenses, and returns a prioritised 30/60/90 improvement backlog.