The AI Governance Operating Layer
AegisPoint is the operating layer your AI governance programme actually runs in — the inventory,
the framework, the risk register, the roadmap and the evidence, in one place, assessed by a consultant
whose name is on the report.
The coordination is being automated. The judgement never is.
Your Risk Register, in the client portal. Every finding classified against the framework, severity by domain, owner named.
What an operating layer is
Most AI governance tooling gives you a view. A view tells you what you already recorded. An operating layer holds the record itself — and everything that has to happen to it.
Every AI system in use — sanctioned, under review and shadow — with an owner, an autonomy level and a risk classification against each one.
Five domains, scored on evidence rather than assertion, crosswalked to NIST AI RMF and ISO/IEC 42001, and mapped to the obligations each edition answers to.
No score is disclosed before the executive briefing, and the gate fails closed: an unset briefing date shows the withheld state, never the score. A separate internal review state records who checked what an agent produced — in build, and we will say when it is enforced.
Five agents are being built into the layer to detect, draft, sequence and chase. None are running today; the roster below says where each one is. None will ever decide.
The gap
Security tools protect your perimeter. GRC platforms manage IT risk. Neither was built for the governance demands of enterprise AI.
Employees using unapproved tools, with no visibility into what data left the building.
EU AI Act, ISO 42001 and NIST AI RMF all carry audit expectations, and none of them wait for your roadmap.
A spreadsheet inventory is out of date the week after it's built, and nobody owns keeping it current.
Your security stack answers "who is touching AI we haven't sanctioned?" It cannot answer "is the AI we did sanction still inside its approved boundary?"
Absence is the finding
Your inventory renders records. It cannot tell you that a Critical risk has no item on your roadmap, that an adopted policy has nobody accountable for it, or that a tool touching regulated data has no agreement on file. Those are absences — and absences are computable. We run them as queries against your record set continuously, not quarterly.
Nobody had noticed, because no screen in the organisation shows the join between a risk register and a plan.
An orphaned policy is not a governance artifact. It is a document that will fail its first audit question.
A human reading the portal would never catch this. A join catches it instantly.
Illustrative and anonymised. The patterns above are drawn from real engagements; no client's data, name or findings are ever used in our marketing. Where a finding is not yet measurable, we say so — a query returning results from a field nobody has populated is a correct query and an unusable finding, and goes to your consultant as a data coverage gap, never to you as a finding about your programme.
Why it matters
A consultant cannot produce these by reading. A query notices instantly.
That is the part we automate — and it is the only part. Every classification, every adoption, every closure is still a human decision, made by the consultant whose name is on your report.
Assessed against
Framework badges are easy. What matters is whether a finding in your environment maps to a domain, and whether that domain maps to something a regulator recognises. Ours do — and we show the anchor. One framework, three editions: the structure holds, the obligations it answers to change.
For mid-market and enterprise organisations adopting AI across the business. The baseline edition, aligned to NIST AI RMF and ISO/IEC 42001.
For law firms and in-house legal departments, where the governing obligations are professional-conduct rules and client confidentiality before they are anything else.
For health systems and providers, where PHI, clinical decision support and patient safety carry obligations no general framework covers.
Five domains, and the regulation each one answers to
All three editions crosswalk to the same standards — NIST AI RMF 1.0, ISO/IEC 42001, the EU AI Act, SOC 2 and COSO ERM — so a finding is portable and a score means the same thing whichever edition you were assessed under. What changes between editions is the sector obligation each domain is anchored to, and that is what makes a finding actionable rather than academic.
AegisPoint is not a law firm, and nothing on this site is legal advice. We assess governance maturity and map findings to recognised frameworks; whether any obligation applies to your organisation is a determination for your own counsel. Framework and standard names are used for identification only — trademarks are the property of their respective owners, and no affiliation or endorsement is implied.
The agent layer
Most AI governance products give you more dashboards to check. We give you one place to ask. Your Client Success Manager will be an AI agent, and it will say so every session. It will answer only from records your advisor has released, and it will never make a judgement call. Behind it, four headless agents will keep those records current. In build. No release date is published.
Each date is a commitment, not an estimate
| Agent | What it does | Talks to you | Build state |
|---|---|---|---|
| Client Success Manager | Your programme manager. Answers from your records, sends the weekly digest, escalates to your consultant. | Yes — and it says so | ◑ In build · no date published |
| Program | Turns validated findings into a sequenced roadmap, and re-sequences it when an action slips. | No | ◑ In build · no date published |
| Monitoring | Watches for shadow AI, sanctioned-AI drift, and regulatory change relevant to your inventory. | No | ◑ In build · no date published |
| Policy Enforcement | Evaluates whether your adopted policies cover what is actually happening, and drafts what is missing. | No | ◑ In build · no date published |
| Documentation | Pre-screens submitted documents and maintains the evidence crosswalk behind your assessment. | No | ◑ In build · Q4 2026 |
Build state above is current and accurate. The operating layer is live today and your programme runs in it now; the agents are being built into it in the order shown. We publish where they are, because a client who advertised a control that wasn't operating would get a finding from us.
What no agent of ours may do: finalise a framework classification, adopt a policy, close a finding, or move a date you have already been shown. Two tiers of accountability sit behind that: your principal consultant is accountable for everything the agents produce on your engagement, and our Chief Product Officer is accountable for the agents as systems — action lists, autonomy levels, model versions, prompts, guardrails and logging. We can produce both on request.
Advisory
Every stage runs in the same operating layer. The assessment does not produce a PDF you file and forget — it populates the record that stages two and three then work against.
Stage 01 · Assess
A structured 2–3 week engagement that maps your AI usage, scores you against the five domains on evidence rather than self-report, and delivers a board-ready baseline with a sequenced remediation roadmap.
Stage 02 · Advise
We execute the roadmap alongside your team — adopting governance policies, naming accountable owners, aligning initiatives across business units, and enabling safe deployment of your priority use cases.
Stage 03 · Manage
A standing governance programme — monitoring, policy coverage evaluation, risk scoring and executive reporting — reviewed on a set cadence with your consultant. The automated monitoring and policy-coverage agents that will run it continuously are in build, with no release date published; the programme runs on the consultant's cadence until they land.
Every engagement is scoped before it is priced. The assessment is fixed-scope, so we can give you the number on the discovery call — before you commit to anything. Scope is driven by the size of your AI estate, the number of business units in scope, and how many people we need to interview.
Who you'll be working with
Jason Pender — Founder & CEO, AegisPoint AI.
Thirty years building security businesses through partners. Jason led carrier and service-provider channels at Fortinet, Palo Alto Networks, Cisco and Netskope, and most recently ran global service-provider and systems-integrator partnerships at Cato Networks. He started at IBM Global Network in London in 1991.
He founded AegisPoint because the pattern was familiar — a new technology arriving inside enterprises faster than the controls around it, and no partner channel equipped to govern it. That is why this is built channel-first: through the advisors clients already trust, not around them.
Jason is also the accountable owner for every AegisPoint agent — their action lists, autonomy levels, models, prompts and guardrails. When we say judgement stays human, this is the human.
Straight answers
Not by us. These are the claims most likely to reach you from somewhere else in this market, and both fall apart under a question your auditor will ask.
We hold governance metadata only — never prompts, responses or document content. Holding it would make us a custodian of your regulated data and a data vendor, not an independent advisor. That boundary is architectural, not a policy we could quietly relax.
Agents will detect, draft, sequence and chase. A human decides, approves and signs. If the software made the call, you could not defend the outcome — and defensibility is the whole point.
Channel
AegisPoint is introduced by MSSPs, trusted advisors and technology partners — giving their clients enterprise-grade AI governance without building the capability in-house. You make the introduction; we scope, price, deliver and sign, and you shadow the engagement.
Get started
Start with a complimentary 30-minute discovery call. We'll map where your AI risk sits, name the gaps that matter first, and tell you plainly whether a structured assessment is the right next step — or whether it isn't.
Assessment: 2–3 weeks · fixed scope · board-ready report. Delivered by AegisPoint or through a certified partner.
The Daily AI Risk Brief covers regulatory developments, AI litigation and liability trends, and emerging security vulnerabilities. No cost, no pitch.
We reply within one business day
We use what you send here to reply to your enquiry and nothing else. No list, no sequence.