Our AI governance method

Evidence before
assurance.

AI governance becomes useful when it changes a decision, a control or an operating practice. We start with the use case and its consequences, open only the questions that matter, and separate what has been reported from what has been proven.

Rules first. AI where justified. Controls outside the model. Evidence over assurances.

Deterministic by design

The same answers produce the same result.

The scan does not ask an AI model to interpret, score or rewrite a response. Its question routing, findings, combined patterns and priorities are fixed in the published rule pack used by the browser.

  1. 01

    Define the use

    Describe one implementation: who it affects, what it can access or change, where people intervene and whether it supports a critical operation.

  2. 02

    Open relevant controls

    Context determines which groups apply, including accuracy, fairness, model change, security, authority, oversight, fallback and third parties.

  3. 03

    Combine weaknesses

    Fixed patterns identify when separate answers create a more consequential problem together and state the first practical move.

  4. 04

    Test the evidence

    The report lists evidence prompts for every applicable answer. A deeper review examines whether documents, tests and operating records support the claim.

How sources are used

Different sources carry different weight.

The scan maps questions and findings to their basis. It does not present contextual guidance as an APRA requirement.

Prudential requirement

APRA standards

Direct obligations are treated as requirements only where the cited standard applies. CPS 230 informs questions about critical operations, service providers, resilience and continuity.

Regulatory direction

APRA and APRA/ASIC publications

Letters and roundtable material indicate supervisory focus and emerging expectations. They are not converted into new legal obligations.

Governance context

AICD and Actuaries Institute

Director and actuarial publications broaden the practical control set, especially around accountability, fairness, model risk and the questions boards should ask.

Technical context

ASD cyber security guidance

Agentic-AI guidance informs practical controls for privileges, identities, tools, untrusted inputs, monitoring, stop mechanisms and unintended objectives.

What the scan does not do

A useful screen, not an assurance opinion.

It does not calculate residual risk.

Potential impact is separated from the self-reported control position. Control effectiveness cannot be established without evidence and testing.

It does not determine compliance.

Applicability depends on the organisation, system and facts. The scan is not legal advice, audit, certification or a substitute for current source material.

It does not inspect the system.

Avowal does not receive answers through the tool. No documents, logs, model behaviour, fallback arrangements or supplier claims are independently verified.

What an evidence review adds

Move from reported controls to tested controls.

A focused review can trace the most consequential claims to current evidence: decision rights, test results, exception records, change approvals, access controls, logs, incident playbooks, fallback exercises and supplier commitments.

The objective is not a longer governance document. It is a short list of material weaknesses, evidence that supports or contradicts the reported position, and practical actions with owners.

Discuss a deeper review