Responsible AI governance setup

AI governance that lets you scale AI with rules

Your staff know what they may and may not do with AI, and you can prove it to an auditor. You receive the policy, the risk tiers, the approval paths, the data boundaries, the review rules and the incident process, written for the people who have to follow them.

  • From $2,500
  • 3 to 8 weeks
  • The FusionGuard pack
  • Built for regulated work

AI risk grows with adoption, and adoption is already happening

By the time governance is raised at leadership level, AI is usually in daily use in three or four teams. Six patterns show up in the gap between the two.

Staff are using AI with no rules

People found the tools themselves, and the useful ones spread by word of mouth. Nobody wrote down what is allowed.

Output quality varies by whoever produced it.

Client data is going into prompts

The fastest way to get a good answer is to paste the real document in, so that is what happens.

Data leaves your control, and you cannot say where it went.

Approval authority is undefined

No one has said which AI-assisted decisions need a person to sign off and which do not.

Work ships that nobody agreed to.

Tools and models have multiplied

Different teams pay for different assistants, on different terms, holding different data.

No accountability for what runs where.

There is no incident path

When AI produces something wrong in front of a client, the response is improvised by whoever notices.

Problems get found late and fixed twice.

You cannot prove any of this to an auditor

The controls may exist in practice, and none of them are written down in a form anyone outside the team can read.

A due-diligence questionnaire stalls the deal.

Documents your team runs on and your auditor accepts

These are working documents, not a policy binder. Your staff read them to know what to do, and you hand them to a client or a regulator who asks how AI is controlled here.

AI Acceptable Use Policy
What your staff may and may not do with AI, written so the people it applies to can follow it without a training session.
Company Alpha Register
An inventory of the proprietary knowledge that creates your advantage: what it is, where it lives, who owns it, and how AI may access it.
Agent Permission Matrix
What each AI agent may read, retrieve, and do, with a classification ceiling and named approval paths. Required when agents are in use.
Agent Control & Boundary Assessment
Optional. Identity, effective permissions, memory audience, communication paths, stopping, and revocation. A FusionGuard pack artifact, not a separate offer.
AI Use-Case Register
Every approved and proposed AI use in the organization, in one list, with an owner against each.
Risk Classification Matrix
Tiered risk with the controls that match each tier, so a low-risk use is not held to the same gate as a client-facing one.
Vendor and Model Register
Which tools and models are approved, what data each may see, and what you agreed to when you signed up.
Human Review Rules
The points where a person has to approve or correct output before it goes anywhere, named by role.
AI Security Checklist
The baseline technical and operational controls, in a form your IT function can action.
Incident Response Process
What happens when AI causes harm or a near miss: who is told, who decides, what gets recorded.
Governance Maturity Baseline
Where you stand today, measured, so the next review has something to compare against.
Executive Governance Report
A leadership view of posture and gaps, in the format you would put in front of a board or a client asking hard questions.

Two ways in, depending on how much AI is already running

Where you land follows the number of teams using AI, how sensitive the data is, and whether anything client-facing is already live.

Conformance audit

$2,500 to $5,000

About 3 weeks

A review of AI use already happening in your business, against a defined control set. Take this when you need to know your exposure before deciding what to fix.

  • Company Alpha Register
  • AI Use-Case Register
  • Risk Classification Matrix
  • Governance Maturity Baseline
  • Executive Governance Report

Guardrails retrofit

$5,000 to $15,000

4 to 8 weeks

The full governance baseline, built and handed over. Take this when AI is already in use across teams and the rules have to exist before it spreads further.

  • Everything in the audit
  • AI Acceptable Use Policy
  • Agent Permission Matrix (when agents are in use)
  • Agent Control & Boundary Assessment (optional, when agents have write access)
  • Vendor and Model Register
  • Human Review Rules and incident process

Governance is also built into every AI-enabled or agentic system we deliver, so the risk classification and guardrails that a FusionBuild engagement needs are already inside its price. Buy this separately when AI is running in your business ahead of anything we built.

AI governance in practice

Financial services deadlines already in force, what Deloitte's governance report means for operators, and how AI work gets measured once it is live.

AI governance for financial services under Canadian deadlines already in force

AI governance in financial services

What Deloitte's governance report means for how you build and manage AI

Deloitte NL report breakdown

The EU AI Act broken into what an operator actually has to do

EU AI Act breakdown

How we measure AI work so the claim and the outcome stay attached

How we measure AI work

Whether governance is your next spend

Governance is worth buying once AI is already in the building. If nothing is running yet, the right column points at the engagement that comes before this one.

Start here if

  • Your teams are already using AI and you want rules before it spreads further
  • You handle client, personal or regulated data and AI is touching it
  • Something AI-assisted is going in front of clients
  • A client or insurer has started asking how you control AI
  • You need a defensible position before signing off build investment

Start somewhere else if

  • Nobody is using AI yet and the question is where it would help. Go to FusionMap.
  • We are building the system, in which case the controls come with it. See FusionBuild.
  • Your people understand the rules and cannot apply them to real work. Go to AI Systems Mastery.
  • You want a free read on where you stand first. Take the systems readiness assessment.

Where governance work usually leads

Rules on their own change little. What follows depends on whether the constraint turns out to be the system, the people, or the scope of what you are trying to run.

Rules are defined and one workflow is ready to build

FusionBuild

Your team needs the judgment to apply the rules

AI Systems Mastery

A whole function is going to run on this

AI Operating System

You need to know where AI should start at all

FusionMap

The seven we get asked before every governance engagement

They cover whether a small company needs this, what gets prohibited, how registers and approval rules work, and what happens when something goes wrong.

Does a small company need AI governance?

Once staff use AI on client, personal or regulated data, or anything AI-assisted goes in front of clients, yes. Headcount does not change the exposure. The Conformance audit exists for organizations that need to know what is already running before they decide what to fix.

What AI use should be prohibited?

That is written into the Acceptable Use Policy for your organization, against the data you hold and the work you do. Common prohibitions include putting client or regulated data into consumer tools, using AI output as advice without review, and letting agents write to systems without an approval gate. The policy names the allowed tools and the banned ones.

Do we need an AI use-case register?

Yes, if you cannot name every place AI is already in use. The register lists each use case, the data it touches, the risk tier, the owner and whether it is approved. Governance without that inventory sits on top of invisible work.

What is an AI model register?

A record of every model and vendor in use: which tool, which model version, what data it sees, who approved it, and when it was last reviewed. It is the inventory an auditor or a client asks for when they want to know what is running on your data.

How do human approval rules work?

Each risk tier names which actions a person must approve before they happen, and who that person is. Low-risk drafting may pass with a spot check. Writes to a CRM, payments, or client-facing output sit behind a named reviewer. The rules are written into the Agent Permission Matrix when agents are in scope.

Does AI governance include AI agents?

Yes. Agents with read or write access get a permission matrix, boundary assessment where they can change records, and the same incident process as every other AI use. The Guardrails retrofit tier includes those artifacts when agents are already live or about to be.

What should happen after an AI incident?

The Incident Response Process names who is told, who decides, what gets recorded, and when the system is paused. Near misses are logged the same way as harm, so the next review has evidence rather than memory.

Scale AI without scaling the risk

Bring what your teams are already doing with AI. We will tell you which parts need a rule this quarter and which can wait.