Staff are using AI with no rules
People found the tools themselves, and the useful ones spread by word of mouth. Nobody wrote down what is allowed.
Output quality varies by whoever produced it.Responsible AI governance setup
Your staff know what they may and may not do with AI, and you can prove it to an auditor. You receive the policy, the risk tiers, the approval paths, the data boundaries, the review rules and the incident process, written for the people who have to follow them.
Where the exposure comes from
By the time governance is raised at leadership level, AI is usually in daily use in three or four teams. Six patterns show up in the gap between the two.
People found the tools themselves, and the useful ones spread by word of mouth. Nobody wrote down what is allowed.
Output quality varies by whoever produced it.The fastest way to get a good answer is to paste the real document in, so that is what happens.
Data leaves your control, and you cannot say where it went.No one has said which AI-assisted decisions need a person to sign off and which do not.
Work ships that nobody agreed to.Different teams pay for different assistants, on different terms, holding different data.
No accountability for what runs where.When AI produces something wrong in front of a client, the response is improvised by whoever notices.
Problems get found late and fixed twice.The controls may exist in practice, and none of them are written down in a form anyone outside the team can read.
A due-diligence questionnaire stalls the deal.What you receive
These are working documents, not a policy binder. Your staff read them to know what to do, and you hand them to a client or a regulator who asks how AI is controlled here.
Price and duration
Where you land follows the number of teams using AI, how sensitive the data is, and whether anything client-facing is already live.
Conformance audit
$2,500 to $5,000
About 3 weeks
A review of AI use already happening in your business, against a defined control set. Take this when you need to know your exposure before deciding what to fix.
Guardrails retrofit
$5,000 to $15,000
4 to 8 weeks
The full governance baseline, built and handed over. Take this when AI is already in use across teams and the rules have to exist before it spreads further.
Governance is also built into every AI-enabled or agentic system we deliver, so the risk classification and guardrails that a FusionBuild engagement needs are already inside its price. Buy this separately when AI is running in your business ahead of anything we built.
Proof
One regulated firm, one live sales territory. In both, the rules and the review points were agreed before anything was built, which is the order that leaves you something to show a client or a regulator.
A regulated firm rolled AI out across research, compliance and client engagement. Governance and regulatory requirements specific to financial services shaped the rollout rather than following it.
Three agents went into a live sales territory. The review points where a person has to check the output were designed before the agents were built.
Understand it first
Financial services deadlines already in force, what Deloitte's governance report means for operators, and how AI work gets measured once it is live.
Fit
Governance is worth buying once AI is already in the building. If nothing is running yet, the right column points at the engagement that comes before this one.
After the baseline
Rules on their own change little. What follows depends on whether the constraint turns out to be the system, the people, or the scope of what you are trying to run.
Questions
They cover whether a small company needs this, what gets prohibited, how registers and approval rules work, and what happens when something goes wrong.
Once staff use AI on client, personal or regulated data, or anything AI-assisted goes in front of clients, yes. Headcount does not change the exposure. The Conformance audit exists for organizations that need to know what is already running before they decide what to fix.
That is written into the Acceptable Use Policy for your organization, against the data you hold and the work you do. Common prohibitions include putting client or regulated data into consumer tools, using AI output as advice without review, and letting agents write to systems without an approval gate. The policy names the allowed tools and the banned ones.
Yes, if you cannot name every place AI is already in use. The register lists each use case, the data it touches, the risk tier, the owner and whether it is approved. Governance without that inventory sits on top of invisible work.
A record of every model and vendor in use: which tool, which model version, what data it sees, who approved it, and when it was last reviewed. It is the inventory an auditor or a client asks for when they want to know what is running on your data.
Each risk tier names which actions a person must approve before they happen, and who that person is. Low-risk drafting may pass with a spot check. Writes to a CRM, payments, or client-facing output sit behind a named reviewer. The rules are written into the Agent Permission Matrix when agents are in scope.
Yes. Agents with read or write access get a permission matrix, boundary assessment where they can change records, and the same incident process as every other AI use. The Guardrails retrofit tier includes those artifacts when agents are already live or about to be.
The Incident Response Process names who is told, who decides, what gets recorded, and when the system is paused. Near misses are logged the same way as harm, so the next review has evidence rather than memory.
Bring what your teams are already doing with AI. We will tell you which parts need a rule this quarter and which can wait.