askew.systems

Practice 01

AI governance that survives
contact with an auditor

Every organisation is being told to adopt AI. Almost none can answer the questions that follow: who is accountable, what the model touched, and whether the policy is being followed. We build the operating model that answers them.

What we deliver

AI strategy, grounded

Where AI genuinely pays in your organisation and where it does not. Sequenced by risk, cost and readiness, tied to outcomes your board already cares about. No innovation theatre.

Policy that operates

Usage policy, data handling rules and escalation paths that are enforced by the platform, not filed in a drawer. Mapped to ISM, the Essential Eight and the Privacy Act where they apply.

Risk you can register

A live register of AI use in your estate: what runs, whose data it touches, what it can decide, and who owns it. The artefact your risk committee keeps asking for.

Person in the loop

Escalation designed in from the start: the system raises the concern with evidence attached, a named person decides, and the record survives. Automation advises; it never closes the loop.

How an engagement runs

  1. 1

    See it. Inventory the AI already in use, sanctioned or not. You cannot govern what you have not found.

  2. 2

    Name it. Strategy and policy, written against your obligations, your risk appetite and your actual workforce.

  3. 3

    Wire it. Controls, telemetry and escalation built into the platforms where the work happens: Azure, ServiceNow, your own systems.

  4. 4

    Prove it. Audit trail, risk register and reporting an auditor can read without a translator.

Start the governance conversation

Tell us what AI is already doing in your organisation. We will tell you plainly what it would take to govern it.

[email protected]