04 Account · AI Governance Assurance
Test whether governance operates.
An independent assessment of whether AI ownership, approval authority, oversight, change control, incident handling and leadership reporting function in practice. Documentation is evidence of intent. We look for evidence of operation.
Assessment sequence
- 01Establish stated governance and accountability
- 02Trace real decisions and approvals
- 03Test change and incident handling
- 04Assess oversight against observed practice
- 05Report gaps between policy and operation
Who this is for
Organisations that will be asked who authorised the AI and on what basis.
- Boards and executives carrying accountability for AI-assisted outcomes
- Risk and compliance functions preparing for regulatory or client scrutiny
- Organisations with AI policy in place but limited assurance over practice
- Groups where AI adoption has outpaced approval and oversight
- Firms responding to insurer, client or regulator questions
Outcomes
What changes for the organisation
Accountability made explicit
A clear statement of who owns each system, who approves change and where that is currently ambiguous.
Governance tested against practice
Findings drawn from real approvals, exceptions, changes and incidents rather than from policy text.
A defensible reporting line
What leadership should receive, how often, and what evidence supports it.
What Alacrix does
We trace decisions, not documents.
The assessment follows real AI systems through approval, change, exception and incident handling to see where accountability holds and where it dissolves.
- Review stated policy, standards, registers and committee remits
- Interview accountable owners, approvers, reviewers and operational users
- Trace sample approvals, exceptions, changes and incidents end to end
- Assess whether oversight roles have authority, information and time
- Assess regulatory alignment relevant to the sector and use cases
- Report the gap between governance as written and governance as operated
Assessment domains
What we examine
Six governance domains tested against operation.
Ownership
Who is accountable for each AI system, and whether that person has the authority and information to act on it.
Approval authority
Who may approve deployment, expansion or increased autonomy, and on what evidence that approval rests.
Oversight in operation
Whether review, exception handling and escalation happen as described once the system is live.
Change control
How model, prompt, data, vendor and permission changes are assessed before they take effect.
Incident governance
How AI-related failures are detected, escalated, recorded, remediated and disclosed where required.
Reporting
What leadership actually receives about AI use, exposure, incidents and control performance.
Deliverables
What you leave with
Independent, not self-assured
An independent view of accountability.
We do not write your policies and then assess them. Where an organisation needs governance built, we say so and remain the party that tests the result.
- Findings are evidenced by traced decisions and records
- Unclear accountability is reported as a material finding
- Residual governance risk is stated and assigned
- This is an independent assurance opinion, not a certification or regulatory approval
Engagement process
How the work runs
- 01
Establish
Capture stated governance, ownership, approval routes and reporting expectations.
- 02
Trace
Follow real approvals, changes, exceptions and incidents to observed practice.
- 03
Report
State where accountability holds, where it fails and what must change.
Next step
Could you show who approved the AI, and why?
An independent governance assessment establishes whether ownership, approval, oversight and incident handling would withstand external scrutiny.