Skip to main content

AI Governance & Assurance Readiness

Can you substantiate how your AI system is governed?

A scoped, evidence-based assessment of whether the controls, responsibilities and technical evidence surrounding an AI system are appropriate for the context in which it now operates.

From £7,500 · typically 7 to 10 business days from evidence availability

The commercial position

The situation
An AI capability is entering production, facing enterprise scrutiny or becoming important enough that management needs a defensible position on how it is governed and controlled.
The decision
Can the organisation explain what the AI system does, where responsibility sits, how its behaviour is evaluated and what evidence supports the controls being claimed?
What Lornets does
We establish the operating context, map the AI system and its dependencies, examine governance and technical controls, test the evidence behind material claims and identify what must change before the organisation can responsibly depend on the system or represent its position externally.
What you leave with
  • AI System Context and Use-Case Inventory
  • AI Responsibilities and Control Map
  • AI Claims and Evidence Matrix
  • Material Findings and Assurance Confidence
  • Critical AI Assurance Gates
  • Prioritised 90-day remediation roadmap
What may happen next
Where genuine technical gaps are identified, remediation may continue through Production Hardening & Scale, Forward Deployed AI Engineering or Managed Production Engineering. A conclusion that the existing controls are proportionate is also a valid outcome.
When this is not appropriate
  • The organisation requires formal certification or an audit opinion
  • The primary need is legal interpretation or regulatory advice
  • The organisation wants generic AI policies without examining the operating system
  • The use case is still an experiment with no credible production intention
  • The organisation needs a broad AI strategy or introductory training programme

Governance becomes an engineering question when the system starts carrying consequence.

The system itself may not have changed. What changed is the consequence attached to what it does, and who now expects evidence for it.

  • An enterprise customer is asking how AI is governed, evaluated or monitored
  • An AI feature has moved from prototype into customer or operational use
  • Management needs technical evidence to support EU AI Act readiness alongside appropriate legal advice
  • Sensitive or customer data is being sent to model providers
  • AI components can recommend, initiate or perform consequential actions
  • A new model, provider, dataset or level of autonomy is being introduced
  • Investor, procurement or risk teams are asking for technical evidence
  • Ownership of evaluation, incidents, monitoring and human oversight is unclear

What Lornets examines

Scope follows the system and its operating context. Each area is examined against evidence rather than stated intent.

System purpose and boundaries
What the AI system is intended to do, who is affected, where it operates and which decisions or actions remain outside its authority.
Ownership and responsibility
Accountable owners, operational responsibilities, provider dependencies, escalation routes and ownership across the system lifecycle.
Data and provider dependencies
Data provenance, sensitive information, model-provider exposure, retention, residency, contractual dependencies and third-party failure conditions.
Evaluation and acceptable behaviour
Defined evaluation criteria, test datasets, failure modes, quality thresholds, model and prompt versioning, reproducibility and ongoing evaluation.
Human oversight and permission boundaries
Human intervention, review points, privileged actions, tool permissions, output validation, fallback behaviour and withdrawal mechanisms.
Monitoring, incidents and change
Production monitoring, behavioural drift, incidents, model or provider changes, release controls, records and reassessment triggers.

Standards and regulatory context

Where relevant to the system and operating context, evidence may be mapped against recognised sources including ISO/IEC 42001, ISO/IEC 42005, the NIST AI Risk Management Framework, the NIST Generative AI Profile, UK AI Management Essentials guidance and applicable technical or operational requirements arising from the EU AI Act.

This mapping supports technical and governance readiness. It does not constitute legal advice, regulatory certification or a formal conformity assessment.

What you receive

A written position that can be handed to management, a customer or an engineering team without translation.

The engagement concludes with an AI Assurance Dossier.

  • Executive AI Assurance Position
  • Defined scope and operating context
  • AI system, model, data and provider map
  • Responsibilities and control ownership
  • Claims, evidence and identified gaps
  • Evaluation and monitoring position
  • Human oversight and permission boundaries
  • Critical gates and residual risks
  • Prioritised remediation roadmap
  • Verification criteria for recommended changes

Relationship to other Lornets services

AI Governance & Assurance Readiness

For an AI system that already exists or is approaching consequential production use, where governance, controls and evidence need to be established.

Forward Deployed AI Engineering

For a defined AI opportunity that still needs to be framed, built, deployed, assured and transferred into real operations.

Enterprise Readiness

For a specific enterprise customer or procurement process examining the organisation's wider technical position, including AI where material.

Questions and objections

Can you substantiate how your AI system is governed?

If the AI system already carries consequence, the governance and evidence position is worth establishing before someone else asks for it.