Home/Solutions/AI Governance
Practice · AI Governance

AI governance that survives an audit, not a slide review.

The controls that actually prevent AI incidents — policy, data boundaries, evaluation, and vendor risk — sized for companies without a compliance department.

YOUR BOUNDARYCLASSIFYTHEN ROUTEPRIVATEMODELFRONTIER AFRONTIER BFRONTIER CROUTING BY DATA CLASSREGULATED STAYS IN · REDACTED GOES OUT
Direct answer · What does AI governance actually require?

Practical AI governance answers four concrete questions: what data may reach a model, who approved that, what the system may do without a human confirming, and how you would reconstruct a specific decision six months later. That last one catches most organisations out — without logging the model version, prompt and retrieved context at deployment time, a decision cannot be explained to a regulator, a customer or a court. Corelynx delivers this as a fixed-fee package from $7,500, or an ongoing retainer from $1,500 per month.

Executive summary

Most AI governance documents are written to be shown rather than used. They describe principles, not decisions, and they fail the first time someone asks why a specific output happened. Enterprise firms spend millions on this; mid-market companies — now the fastest-growing group of AI adopters — are barely served at all. Corelynx builds governance sized for a company without a compliance department: four questions answered concretely, logging that makes any decision reconstructable, an evaluation harness that catches drift before a customer does, and vendor risk assessed on what the contract actually says about your data.

$7,500
Typical SMB AI governance package price — versus millions at enterprise scale
80%+
Margin profile of governance work, and among the most underserved SMB segments
40%+
Share of agentic AI projects Gartner projects will be cancelled by 2027
$1.5K–$3K/mo
Market range for an ongoing AI compliance retainer
Market signals · Corelynx 2026 Market Study
Who this is for
  • Mid-market companies deploying AI without a compliance function to govern it
  • Regulated businesses — financial services, healthcare, lending — where explainability is not optional
  • Companies whose customers or insurers are starting to ask AI questions in due diligence
  • Teams that ran a successful pilot and now need it to be defensible in production
When to act — trigger conditions
  • An AI system is making or influencing decisions that affect customers
  • Nobody can say which data reaches which model, or who approved it
  • A pilot is moving to production and the risk conversation has not happened
  • A customer, auditor or insurer has asked how your AI decisions are made
  • Agents are being given permissions nobody classified by consequence
Operational symptoms

What ungoverned AI looks like from the inside.

A governance document written to be shown, not used
No record of which model version and prompt produced a given output
Data reaching models without anyone having approved that it may
Agent permissions granted by default rather than classified by consequence
Vendor contracts nobody has read for data-retention or training clauses
No evaluation harness, so quality drift is discovered by a customer
Why it persists

Why AI governance documents fail when tested.

CAUSE 01

Governance was written for the board, not the system

Principles documents describe intent. They cannot answer what a specific system did on a specific day, which is the question that actually gets asked.

CAUSE 02

Logging was left until after launch

Reconstructing a decision requires the model version, the prompt and the retrieved context recorded at the time. Retrofitting that is expensive; designing it in is cheap.

CAUSE 03

Nobody classified actions by consequence

"Can the agent do this?" is the wrong question. "What happens if it does this wrongly, and would we notice?" is the right one, and it produces different permissions.

CAUSE 04

The vendor contract was never read for data terms

Retention, training rights and sub-processor lists sit in contracts that were signed for price and features. The obligations they create are yours regardless.

Delivery framework

How Corelynx builds AI governance that holds.

AI inventory

Inventory what is actually running

Every AI system, the data reaching it, the decisions it influences, and who owns it — usually more than leadership expects, including tools bought on a card.

  • AI inventory
  • Shadow AI
Data classification

Draw the data boundary

What may reach a model, what must never, and where redaction or a private deployment is genuinely required rather than assumed.

  • Data classification
  • Privacy boundary
Agent permissions

Classify actions by consequence

Every consequential action sorted into autonomous, autonomous-but-logged, or human-confirmed. Unglamorous, and the entire safety model.

  • Agent permissions
  • Human in the loop
Audit trail

Make decisions reconstructable

Model version, prompt, retrieved context and output logged at the point of deployment, so any decision can be explained months later.

  • Audit trail
  • Explainability
Vendor risk

Assess vendor risk on the contract

Retention, training rights, sub-processors and incident obligations read against what you have told customers — the gap is where exposure lives.

  • Vendor risk
  • Contract review
What you receive

What you get from an AI governance engagement.

AI system inventoryEvery system, its data, its decisions and its named owner
Data usage policyWhat may reach a model, what may not, and who approves exceptions
Action classification matrixEvery consequential action sorted by autonomy and review requirement
Audit trail specificationWhat is logged, where, and how a decision is reconstructed
Model evaluation harnessThe tests that catch drift before a customer does
Vendor risk registerContract terms assessed against your customer commitments
Pricing transparency

Engagement tiers & published pricing

Sized for companies without a compliance department. Enterprise governance programmes cost millions; this is the same discipline at mid-market scale.

Engagement tiers & published pricing
Offering Investment Model What it covers
Fixed feeGovernance Package $7,500 See where yours lands 2–3 weeks Inventory, data usage policy, action classification, audit trail specification and vendor risk register.
Fixed feeGovernance + Evaluation $15,000–$25,000 See where yours lands 4–6 weeks Adds a working model evaluation harness and drift monitoring wired into your deployment.
MonthlyAI Compliance Retainer $1,500–$3,000/mo See where yours lands Ongoing Policy maintenance, new-system review, vendor reassessment and quarterly evidence packs.
How these fit the Corelynx engagement model

The four questions governance has to answer

Most AI governance documents describe principles — fairness, transparency, human oversight. Principles are necessary, and they answer nothing when someone asks why a specific output happened on a specific day.

Governance that survives contact with an auditor answers four concrete questions instead: what data may reach a model, who approved that, what the system may do without a human confirming, and how you would reconstruct a given decision six months later.

Why reconstructability is the control people skip

The first three questions can be answered in a document. The fourth cannot — it requires the model version, the prompt, the retrieved context and the output to have been logged at the moment the decision happened.

Instrumenting that at deployment is straightforward. Retrofitting it after a regulator, customer or insurer asks is impossible for decisions already made, which is why it is the control most worth installing before anything reaches production.

AI governance package versus an AI compliance retainer

The one-off package establishes the system. The retainer keeps it true as the estate changes — and in most companies it changes monthly, usually without anyone announcing it.

Governance Package — $7,500One-off, two to three weeks. Inventory, data usage policy, action classification, audit trail specification and vendor risk register. The system, documented.
Governance + Evaluation — $15,000–$25,000Adds a working model evaluation harness and drift monitoring wired into your deployment, so quality degradation is caught by a test rather than by a customer.
AI Compliance Retainer — $1,500–$3,000/monthOngoing. New systems reviewed as they appear, vendor terms reassessed, policy maintained, and a quarterly evidence pack ready for whoever asks.
See where yours lands

Shadow AI is the largest ungoverned surface

The inventory step almost always finds more AI in use than leadership expected. Some is deliberate; much of it is a SaaS tool that quietly added an AI feature, or a subscription bought on a card by someone solving a real problem quickly.

None of that is misconduct, and all of it creates obligations. If an employee pastes customer data into an external model, a data-governance decision has been made — just not deliberately, and not by anyone accountable for the consequences.

Classifying actions by consequence, not capability

"Can the agent do this?" is the wrong question, because the answer is almost always yes. The right question is what happens if it does this wrongly, and whether anyone would notice.

Every consequential action sorts into one of three buckets: fully autonomous, autonomous but logged for review, or requiring human confirmation. It is unglamorous work and it is the entire safety model. The alternative — deploy and watch — fails in a specific way: the failures are individually small and collectively invisible, so nobody notices until a quarterly number is wrong and there is no audit trail explaining why.

When you do not need this yet

  • If no AI system influences a decision affecting a customer or an employee, an inventory and a short data policy is proportionate. Do not buy a programme.
  • If you are pre-production on everything, install the audit trail now and defer the rest — it is the one control that cannot be retrofitted.
  • If you already have a compliance function, they may need a technical partner rather than a governance vendor. We work either way, and will say which applies.
Outcome model

What changes when AI decisions become defensible.

OUTCOME 01

Any AI decision can be reconstructed and explained months later

OUTCOME 02

Data reaching models is deliberate and approved rather than incidental

OUTCOME 03

Agent permissions match consequence rather than convenience

OUTCOME 04

Quality drift is caught by an evaluation harness, not by a customer complaint

OUTCOME 05

Diligence and audit questions about AI have documented answers

Frequently asked

AI governance questions, answered straight.

Four concrete answers: what data may reach a model, who approved that, what the system may do without a human confirming, and how you would reconstruct a specific decision six months later. Governance documents that describe principles rather than answering those four questions fail the first time they are tested.

Corelynx publishes its ranges: a fixed-fee governance package is $7,500 over two to three weeks, governance plus a working evaluation harness runs $15,000–$25,000, and an ongoing compliance retainer is $1,500–$3,000 per month. Enterprise governance programmes cost millions; this is the same discipline sized for a mid-market company.

See where yours lands

If employees paste customer data into any external model, you have already made a data-governance decision — just not deliberately. The inventory step usually finds more AI in use than leadership expects, most of it bought on a card and none of it reviewed.

Governance is the internal system: who decides what, what is logged, which actions need a human. Compliance is demonstrating that system to an outside party — a regulator, an auditor, a customer's security review. Governance done properly makes compliance a reporting exercise rather than a project.

Yes, and most of it will be. Third-party AI inside SaaS tools is the largest ungoverned surface in most mid-market companies. The vendor risk workstream reads what those contracts actually say about retention, training rights and sub-processors, then compares it to what you have told your own customers.

Browse the full FAQ hub
Keep exploring

Related practices

Talk this through with a practitioner.

Bring your assessment result. The first conversation is about context and fit — nothing more.

Book a Strategy Session

Or request a tailored roadmap.

Tell us the situation; we'll outline how we'd sequence the diagnostic and what it would examine. Or see the engagement model first.

Request a Tailored Roadmap
Book a Strategy Session