AI governance your clients will actually use
Most AI governance ends at a policy nobody reads. This module runs the whole programme — readiness through to the AI Register — and meets staff inside Microsoft Teams, where the questions are already being asked.
From practice to client
See every client running an AI programme from the practice view, then open an individual programme to work through its tier, coverage, and next steps.
The five-phase programme model
Readiness
Assess where the organisation actually stands before any policy is written.
Policies
A full policy stack with version control, acknowledgements, and branded PDF generation.
Intake and approval
Staff request tools; automated manager pre-approval emails route the decision.
Risk and privacy
Vendor assessments and privacy impact assessments attached to each approved tool.
AI Register
Every AI system in use, tracked with its risk and privacy posture.
Teams-native, not another portal
A Microsoft Teams Q&A bot answers staff AI questions with citations back to the client's own policy stack, and escalates to the client owner and the vCISO when the answer needs a human.
- Answers cite the client's approved policies, not generic guidance.
- Escalation path to the client owner and the fractional security leader.
- Tool requests raised in Teams flow into the same intake and approval queue.
Shadow AI Discovery
Scan the client's Microsoft 365 environment for unmanaged AI use. The result is a report you deliver — not a dashboard the client ignores.
Sector overlays
Legal, accounting, healthcare, not-for-profit, and First Nations overlays layer onto the core acceptable-use policy instead of forking it.
Policy library
- Version control across every policy in the stack.
- Acknowledgement tracking per staff member.
- Branded PDF generation and per-policy download.
- Delivered policies automatically close the matching action-plan task.
Role-scoped client access
- AI Program Manager and Staff each see only their own surfaces.
- First-login guided walkthrough for every role.
- Row-level security scopes every read to the single client.
- Registry and approvals visible to the people accountable for them.
Three tiers, one engine
For SMB clients
AI Governance Essentials
Acceptable use policy, staff notices, tool-request intake, and a right-sized AI Register.
For growing organizations
AI Governance Professional
Adds vendor AI assessments, privacy impact assessments, and the Teams bot for staff questions.
For larger clients
AI Governance Enterprise
Full policy suites, framework coverage mapping, Shadow AI Discovery, and sector overlays.
