AI Risk & Governance Assessment
Know what AI you are permitted to use, who must approve it, and how to evidence that to an auditor — before December. A comprehensive 2–3 week AI impact assessment aligned to DTA Policy v2.0, establishing your agency's AI risk boundaries, human-in-the-loop controls, data privacy architecture, and PSPF/ISM/Essential Eight alignment — so you can deploy agentic AI with confidence, not exposure.
Why an AI Assurance Assessment?
Agentic AI systems act autonomously — calling tools, accessing data, executing workflows, and making decisions at machine speed. Without explicit risk boundaries, human oversight triggers, and data access controls embedded before deployment, agencies face governance exposure, data leakage risk, and operational liability that can only worsen after go-live.
This sprint produces the governance architecture your AI needs to operate safely — and the documented evidence your accountable authority, audit committee, and DTA reporting will require. It is the sprint that makes the agentic AI PoC sprint deployable rather than just demonstrable.
Any agentic AI deployment
Recommended before
2–3 weeks fixed scope
Duration
4 governance frameworks
Output
What We Assess
AI Risk Classification & Boundary Definition
Systematic classification of your planned AI use cases by risk tier — from low-risk summarisation workloads to high-risk autonomous decision-making agents. Defines exposure boundaries and escalation thresholds before build begins.
Human-in-the-Loop (HITL) Design
Design of human checkpoint triggers, approval workflow architecture, and override controls for agentic AI workflows — ensuring human oversight is embedded by design, not bolted on after deployment.
Data Privacy & Access Control Review
Assessment of RBAC/ABAC policy design, PII handling procedures, consent management maturity, and data access patterns for LLM and agentic AI workloads — identifying privacy leakage vectors before they reach production.
Token FinOps & Model Routing Strategy
Design of token budget governance, model tier routing policies (frontier vs. cost-efficient models by task), and FinOps guardrails to ensure AI cost scales predictably with value rather than unbounded with usage.
Agentic Safety & Containment Architecture
Review of agent tool call permissions, blast radius containment design, sandbox boundary architecture, prompt injection defence patterns, and data leakage prevention for multi-agent systems.
Compliance Alignment Review
Structured assessment of your AI governance posture against the PSPF, the ISM, the Essential Eight, and the DTA Policy for the Responsible Use of AI in Government v2.0 — producing a gap register and remediation priority stack.
What You Receive
AI Impact Assessment (DTA Policy v2.0 Aligned)
Tiered risk classification of your AI use cases with defined exposure boundaries, compliance gaps against the PSPF, ISM, Essential Eight, and DTA Policy v2.0, and a prioritised remediation register — structured for direct entry into your AI use-case register.
Human-in-the-Loop (HITL) Trigger & Override Matrix
Structured matrix mapping each AI workflow to its required human checkpoint, approval authority, override control, and escalation path — ready for engineering implementation.
Token FinOps & Model Routing Cost Strategy
Model routing policy design, token budget governance framework, and a three-scenario cost model projecting AI operating costs at your target usage volumes.
Agentic Safety & Data Leakage Audit Framework
Documented safety architecture requirements for agentic AI deployments — tool call permission model, containment boundaries, sandbox design, and prompt injection defence patterns.
Sprint Timeline
Discovery & Risk Scoping
- Stakeholder alignment: CTO, CISO, risk/compliance, internal audit
- AI use case inventory and risk pre-classification workshop
- Review of existing AI policies, privacy impact assessments, and data access controls
- Current-state model inventory and deployment architecture documentation
Deep Assessment
- Risk boundary definition and tier classification for each use case
- HITL workflow design for high-risk agentic workloads
- Data privacy and RBAC/ABAC access pattern review
- Token FinOps modelling and model routing policy design
- Compliance gap analysis against the PSPF, ISM, Essential Eight, and DTA Policy v2.0
Framework & Deliverables
- Agentic safety architecture design: blast radius, sandboxing, tool permissions
- HITL trigger and override matrix completion
- Compliance gap register and remediation priority stack
- Final report and framework documentation preparation
Presentation & Handover
- Executive findings presentation to risk, compliance, and technology leadership
- Full deliverables handover: risk report, HITL matrix, FinOps strategy, safety framework
- Optional: 30-day follow-up check-in included
Who This Is For
- CISOs and Risk Officers evaluating AI governance gaps
- CTOs preparing for an agentic AI deployment
- Compliance teams facing PSPF, ISM, and DTA Policy v2.0 obligations
- Internal audit preparing an AI controls review
- Accountable authorities requiring AI risk reporting and assurance
Common Triggers
- Accountable authority or audit committee requesting AI risk assessment
- PSPF, ISM, and DTA Policy v2.0 obligations driving AI governance review
- Agentic AI build sprint planned but governance undefined
- Data privacy team raising concerns over LLM data access
- AI model costs exceeding budget without clear oversight
- Ahead of the 15 December 2026 AI impact assessment deadline
Related Advisory
GOVERNStrategy, Risk & AI Readiness
Full advisory pillar →
Ready to govern your AI before it governs you?
Fixed-scope. Senior-led. Delivered in 2–3 weeks with four governance frameworks ready for immediate implementation.
Book AI Assurance SprintDownload Capability Statement