AI governance foundations
Build a risk map from the use cases you actually run rather than from a generic framework.
— Operations & Process
Classifies and scores the risks carried by your actual AI use cases and maps each to practical controls and owners.
2–3 weeks → ~40 minutes
For a full population, not a sample
No coding required
— USE CASES
Build a risk map from the use cases you actually run rather than from a generic framework.
Score a proposed AI use case and attach the controls needed before it goes live.
Show, per use case, which risks are identified and which controls address them.
— HOW IT BEHAVES
The mechanics behind this specific template — what it reads, what it calculates, and where a human stays in the loop.
Risks are sorted into your categories using the same rules each time, which is what makes a large volume of risk registers, controls and policy documents readable.
Each risk is assessed against criteria you control and weight, so the same standard applies to every risk in the risk universe in scope.
Every risk lands in a defined band, so thresholds you set decide the outcome instead of whoever is interpreting it that day.
Every risk is captured in the same field structure, so records drawn from different documents and sources stay comparable.
Your strategy, standards and prior work are loaded first, so conclusions about the risk universe in scope are anchored to your situation.
Analysis runs against your real reporting lines and risks rather than an assumed org shape.
AI governance stalls when the risk register is written in the abstract. AI governance foundations is the typical trigger — build a risk map from the use cases you actually run rather than from a generic framework. Get it right and the conclusion holds up in the room; get it rushed and it gets picked apart. Either way it costs roughly 2–3 weeks of experienced attention.
As a Skill, the work is already sequenced. You bring the evidence, and the run produces use-case-level risk classification and scores plus practical controls mapped to each risk. What sits between input and output is the codified method: thresholds, sequencing and the points where a human confirms a call — all of it visible and editable in the Skill. Net effect: 2–3 weeks down to ~40 minutes, no drift between runs, and every conclusion traceable back to the evidence behind it.
AI risk map exports as a structured SKILL.md file and is MCP-ready, so the same method runs in ChatGPT, Claude, Copilot or your own AI products. Adapt it to your methodology, and the intelligence stays yours — not locked to one vendor.
Identifies where adoption of a new system, process or way of working stalls after go-live, with an evidence-backed report on barriers, workarounds and differences between functions.
Assesses AI readiness through anonymous staff evidence, identifying where AI can improve day-to-day work and the practical barriers that could prevent those gains.
Maps how an organisation actually operates using anonymous accounts from its people, producing an evidence-backed diagnostic of responsibilities, decisions, handoffs and duplicated effort.
Reads a set of weekly status notes for progress, blockers and RAG, charts the trend, and writes an executive digest focused on trajectory.
Reviews a proposed change against your change policy and returns a governed advisory decision — approve, approve with conditions, defer to the change board or reject — weighing risk, blast radius and rollback, with a change manager sign-off required before anything reaches production.
Assesses a refund or compensation request against the contract terms and refund policy that govern it, then returns a decision on approving it in full, in part, offering a goodwill gesture or declining, with every element of the remedy traced to the clause that allows it and anything beyond an agent's authority routed for review.