How engagements work
Most AI governance work produces a framework. What an auditor, a regulator or an enterprise customer actually asks for is evidence the system generates about itself: what the model was told, what it did, who approved it, and how you know the answer was sound. Engagements here run in four phases over six working weeks of effort, and each phase ends with a working artifact rather than a report describing one.
- 01Inventory and exposure
- 02Controls, implemented
- 03Evaluation and assurance
- 04Agent authority and handover
01
Inventory and exposure
5 working days
Locating the models, prompts, agents and third-party AI dependencies actually running, including undeclared ones, then classifying each by owner, data classes, deployment surface, vendor terms and exposure. The ranking sequences everything that follows, so the highest-risk systems get the control work.
Evidence artifact
An AI system register, held in your systems and structured to stay current as a byproduct of your normal change process rather than as a quarterly exercise.
02
Controls, implemented
12 working days
Controls go into the running system, in your repositories: provenance on every model interaction, tenant isolation at the data layer, prompt change control with author and approver separated, guardrails and disclosure. Implemented on the highest-risk system the register surfaces, as the reference others follow.
Evidence artifact
A control-to-obligation mapping where every obligation points at the implemented mechanism satisfying it, and at the query that produces the proof on demand.
03
Evaluation and assurance
8 working days
Not what happened, but whether the output was sound. Output scored against a defined rubric by an independent judge, at full coverage rather than on a sample, failures classified into a closed taxonomy, and a compact regression suite run across permission boundaries.
Evidence artifact
An evaluation harness with tagged baselines and a regression-diff report, runnable by your team on demand. Anyone can rerun it and get the same answer, including someone who does not trust you.
04
Agent authority and handover
5 working days
The exposure most organisations have not addressed: the AI agents your own staff and pipelines already run, usually with broad permissions and no logging. For the teams in scope, constrained by allow-list, pinned models, turn limits and credential-read blocking. Then handover.
Evidence artifact
An agent authority policy enforced in code rather than written in a document, and a self-regenerating evidence pack your team assembles with a single command.
What is included
- Discovery of models, prompts, agents and vendor AI dependencies already in use
- Provenance and append-only audit logging, immutability enforced by the database
- Tenant isolation at the data layer, re-verified server-side on every model-facing path
- Prompt version control with segregation of duties and rollback to any prior version
- Guardrails, injection defence with fail-closed behaviour, and transparency disclosure
- Evaluation rubrics, closed failure taxonomies, versioned baselines and regression diffing
- Agent permission scoping for the assistants and pipelines your own teams run
- Handover: runbook, named control owners, and an evidence pack that regenerates itself
- Implementation focused on the highest-risk systems the register surfaces, built as a reference pattern your engineers extend
What is not included, and what is follow-on
- Certification. I am not a certification body and cannot issue or guarantee any conformity marking. I build the controls and the evidence an assessor will want; the assessment is done by an accredited third party you engage separately.
- Legal advice. I implement to the risk classification and obligations your legal function sets. I do not determine them.
- Vendor contract negotiation. I will specify the terms your AI vendors need to meet, including data retention and training-use terms. Signing is yours.
- Automated detection and redaction of personal data. That is a genuine build in its own right, not a configuration flag. Suppression of internal system identifiers before they reach the model is a narrower control and is included.
- Records retention policy as a legal instrument. I can implement whatever retention behaviour your policy specifies. Authoring the policy is a legal position.
- Model development. No training or fine-tuning of foundation models.
- Ongoing operations. No managed service, no on-call, no staff augmentation. The controls are handed to your team to run.
- Rolling the control set across systems beyond the reference implementation. Quoted separately per system after handover, once the pattern exists and the cost per system is known.
- Two-pass prompt-injection defence with an independent judge model. A genuine build of its own.
- Automated synthesis of corrective prompt rules from clustered evaluation failures.
- Wiring register upkeep into your CI so it maintains itself without human action.
- Organisation-wide AI and agent discovery across every business unit, beyond the systems and teams in scope.
Terms
- Shape
- Four phases totalling six working weeks of effort. Fixed fee for each phase, agreed after a scoping call. No time and materials, and no change-request billing for work inside the agreed scope.
- Pace
- Six working weeks is effort, not a delivery date. Full time it runs about six weeks end to end; at two to three days a week, roughly twelve to fifteen weeks. The fee does not change with the calendar.
- Delivery
- Remote, European hours. On site for kickoff and handover where it helps.
- Who does the work
- One person. The person who scopes the engagement is the person who writes the code. No handoff to a bench after signature.
- Ownership
- Everything lands in your repositories under your ownership. No licensing, no runtime dependency on me, nothing that phones home.
- What you provide
- Repository and environment access, a named technical counterpart who can answer questions inside a day, and an accountable owner who can approve a design decision.
- Stopping points
- Each phase ends somewhere usable. The register is worth having on its own, and so are the controls on your highest-risk system, whether or not the next phase runs.
Engagements start with a scoping call. Ninety minutes, no charge, and the place to say if this shape is wrong for you. The four phases are how the work usually decomposes, not a product you have to buy, and the effort can be redistributed across them once there is a ranking to point at.
Angazhimet fillojnë me një telefonatë njohjeje. Ju punoni me personin që e bën punën.