04 Account · AI Governance Assurance

Test whether governance operates.

An independent assessment of whether AI ownership, approval authority, oversight, change control, incident handling and leadership reporting function in practice. Documentation is evidence of intent. We look for evidence of operation.

Assessment sequence

  1. 01Establish stated governance and accountability
  2. 02Trace real decisions and approvals
  3. 03Test change and incident handling
  4. 04Assess oversight against observed practice
  5. 05Report gaps between policy and operation

Who this is for

Organisations that will be asked who authorised the AI and on what basis.

  • Boards and executives carrying accountability for AI-assisted outcomes
  • Risk and compliance functions preparing for regulatory or client scrutiny
  • Organisations with AI policy in place but limited assurance over practice
  • Groups where AI adoption has outpaced approval and oversight
  • Firms responding to insurer, client or regulator questions

Outcomes

What changes for the organisation

Accountability made explicit

A clear statement of who owns each system, who approves change and where that is currently ambiguous.

Governance tested against practice

Findings drawn from real approvals, exceptions, changes and incidents rather than from policy text.

A defensible reporting line

What leadership should receive, how often, and what evidence supports it.

What Alacrix does

We trace decisions, not documents.

The assessment follows real AI systems through approval, change, exception and incident handling to see where accountability holds and where it dissolves.

  • Review stated policy, standards, registers and committee remits
  • Interview accountable owners, approvers, reviewers and operational users
  • Trace sample approvals, exceptions, changes and incidents end to end
  • Assess whether oversight roles have authority, information and time
  • Assess regulatory alignment relevant to the sector and use cases
  • Report the gap between governance as written and governance as operated

Assessment domains

What we examine

Six governance domains tested against operation.

Ownership

Who is accountable for each AI system, and whether that person has the authority and information to act on it.

Approval authority

Who may approve deployment, expansion or increased autonomy, and on what evidence that approval rests.

Oversight in operation

Whether review, exception handling and escalation happen as described once the system is live.

Change control

How model, prompt, data, vendor and permission changes are assessed before they take effect.

Incident governance

How AI-related failures are detected, escalated, recorded, remediated and disclosed where required.

Reporting

What leadership actually receives about AI use, exposure, incidents and control performance.

Deliverables

What you leave with

Independent AI governance assessment report
Ownership and approval authority map
Oversight and exception handling findings
Change and incident governance findings
Leadership reporting recommendations
Prioritised remediation with accountable owners

Independent, not self-assured

An independent view of accountability.

We do not write your policies and then assess them. Where an organisation needs governance built, we say so and remain the party that tests the result.

  • Findings are evidenced by traced decisions and records
  • Unclear accountability is reported as a material finding
  • Residual governance risk is stated and assigned
  • This is an independent assurance opinion, not a certification or regulatory approval

Engagement process

How the work runs

  1. 01

    Establish

    Capture stated governance, ownership, approval routes and reporting expectations.

  2. 02

    Trace

    Follow real approvals, changes, exceptions and incidents to observed practice.

  3. 03

    Report

    State where accountability holds, where it fails and what must change.

Next step

Could you show who approved the AI, and why?

An independent governance assessment establishes whether ownership, approval, oversight and incident handling would withstand external scrutiny.