The four questions governance has to answer
Most AI governance documents describe principles — fairness, transparency, human oversight. Principles are necessary, and they answer nothing when someone asks why a specific output happened on a specific day.
Governance that survives contact with an auditor answers four concrete questions instead: what data may reach a model, who approved that, what the system may do without a human confirming, and how you would reconstruct a given decision six months later.
Why reconstructability is the control people skip
The first three questions can be answered in a document. The fourth cannot — it requires the model version, the prompt, the retrieved context and the output to have been logged at the moment the decision happened.
Instrumenting that at deployment is straightforward. Retrofitting it after a regulator, customer or insurer asks is impossible for decisions already made, which is why it is the control most worth installing before anything reaches production.
AI governance package versus an AI compliance retainer
The one-off package establishes the system. The retainer keeps it true as the estate changes — and in most companies it changes monthly, usually without anyone announcing it.
| Governance Package — $7,500 | One-off, two to three weeks. Inventory, data usage policy, action classification, audit trail specification and vendor risk register. The system, documented. |
|---|---|
| Governance + Evaluation — $15,000–$25,000 | Adds a working model evaluation harness and drift monitoring wired into your deployment, so quality degradation is caught by a test rather than by a customer. |
| AI Compliance Retainer — $1,500–$3,000/month | Ongoing. New systems reviewed as they appear, vendor terms reassessed, policy maintained, and a quarterly evidence pack ready for whoever asks. |
Shadow AI is the largest ungoverned surface
The inventory step almost always finds more AI in use than leadership expected. Some is deliberate; much of it is a SaaS tool that quietly added an AI feature, or a subscription bought on a card by someone solving a real problem quickly.
None of that is misconduct, and all of it creates obligations. If an employee pastes customer data into an external model, a data-governance decision has been made — just not deliberately, and not by anyone accountable for the consequences.
Classifying actions by consequence, not capability
"Can the agent do this?" is the wrong question, because the answer is almost always yes. The right question is what happens if it does this wrongly, and whether anyone would notice.
Every consequential action sorts into one of three buckets: fully autonomous, autonomous but logged for review, or requiring human confirmation. It is unglamorous work and it is the entire safety model. The alternative — deploy and watch — fails in a specific way: the failures are individually small and collectively invisible, so nobody notices until a quarterly number is wrong and there is no audit trail explaining why.
When you do not need this yet
- If no AI system influences a decision affecting a customer or an employee, an inventory and a short data policy is proportionate. Do not buy a programme.
- If you are pre-production on everything, install the audit trail now and defer the rest — it is the one control that cannot be retrofitted.
- If you already have a compliance function, they may need a technical partner rather than a governance vendor. We work either way, and will say which applies.