The AI Governance Operating Layer

Your enterprise is adopting AI. Is anyone accountable for it?


AegisPoint is the operating layer your AI governance programme actually runs in — the inventory, the framework, the risk register, the roadmap and the evidence, in one place, assessed by a consultant whose name is on the report.

The coordination is being automated. The judgement never is.

clients.aegispoint.ai / risk-register
The AegisPoint client portal Risk Register — open risks by severity and domain

Your Risk Register, in the client portal. Every finding classified against the framework, severity by domain, owner named.

5
Governance domains
Each anchored to a named regulation
14
Live portal pages
Your programme, not a PDF you file
1
Disclosure gate
No score reaches you before your executive briefing. It fails closed
100%
Judgement calls made by a human
By design, not by current limitation

What an operating layer is

A dashboard reports on the programme. An operating layer is where the programme runs.


Most AI governance tooling gives you a view. A view tells you what you already recorded. An operating layer holds the record itself — and everything that has to happen to it.

The inventory

Every AI system in use — sanctioned, under review and shadow — with an owner, an autonomy level and a risk classification against each one.

The framework

Five domains, scored on evidence rather than assertion, crosswalked to NIST AI RMF and ISO/IEC 42001, and mapped to the obligations each edition answers to.

The gate

No score is disclosed before the executive briefing, and the gate fails closed: an unset briefing date shows the withheld state, never the score. A separate internal review state records who checked what an agent produced — in build, and we will say when it is enforced.

The agents

Five agents are being built into the layer to detect, draft, sequence and chase. None are running today; the roster below says where each one is. None will ever decide.

The gap

AI adoption is outpacing the governance built to manage it.


Security tools protect your perimeter. GRC platforms manage IT risk. Neither was built for the governance demands of enterprise AI.

01

Shadow AI is already in your org

Employees using unapproved tools, with no visibility into what data left the building.

02

The deadlines are real

EU AI Act, ISO 42001 and NIST AI RMF all carry audit expectations, and none of them wait for your roadmap.

03

Manual oversight doesn't scale

A spreadsheet inventory is out of date the week after it's built, and nobody owns keeping it current.

04

A firewall cannot see a configuration change

Your security stack answers "who is touching AI we haven't sanctioned?" It cannot answer "is the AI we did sanction still inside its approved boundary?"

Absence is the finding

A dashboard shows you what exists. Governance is about what's missing.


Your inventory renders records. It cannot tell you that a Critical risk has no item on your roadmap, that an adopted policy has nobody accountable for it, or that a tool touching regulated data has no agreement on file. Those are absences — and absences are computable. We run them as queries against your record set continuously, not quarterly.

⚠ Critical risk, no plan

Four open risks. Zero roadmap items.

Nobody had noticed, because no screen in the organisation shows the join between a risk register and a plan.

⚠ Policy with no owner

The policy exists. The RACI exists. Nothing connects them.

An orphaned policy is not a governance artifact. It is a document that will fail its first audit question.

⚠ Record contradicts itself

"We have no AI policy." Three sit published in the library.

A human reading the portal would never catch this. A join catches it instantly.

Illustrative and anonymised. The patterns above are drawn from real engagements; no client's data, name or findings are ever used in our marketing. Where a finding is not yet measurable, we say so — a query returning results from a field nobody has populated is a correct query and an unusable finding, and goes to your consultant as a data coverage gap, never to you as a finding about your programme.

Why it matters

A consultant cannot produce these by reading. A query notices instantly.

That is the part we automate — and it is the only part. Every classification, every adoption, every closure is still a human decision, made by the consultant whose name is on your report.

Assessed against

Three editions. Every domain anchored to a named regulation.


Framework badges are easy. What matters is whether a finding in your environment maps to a domain, and whether that domain maps to something a regulator recognises. Ours do — and we show the anchor. One framework, three editions: the structure holds, the obligations it answers to change.

General Edition

For mid-market and enterprise organisations adopting AI across the business. The baseline edition, aligned to NIST AI RMF and ISO/IEC 42001.

Crosswalked to NIST AI RMF · ISO/IEC 42001  ·  Anchored to EU AI Act · SOC 2 · COSO ERM

Legal Edition — with a design partner

For law firms and in-house legal departments, where the governing obligations are professional-conduct rules and client confidentiality before they are anything else.

ABA Model Rules 1.1 · 1.6 · 5.1 · 5.3 · state bar AI opinions · privilege and confidentiality

Healthcare Edition — live

For health systems and providers, where PHI, clinical decision support and patient safety carry obligations no general framework covers.

HIPAA §164 · FDA SaMD · ONC HTI-1 · OIG

Worked example — Healthcare Edition v2.0

Five domains, and the regulation each one answers to

D1
Data Privacy & PHI Governance
HIPAA §164.308 · §164.314 · §164.512
D2
Clinical AI Risk & Patient Safety
FDA SaMD · AMA · ONC HTI-1
D3
Vendor & Third-Party AI Risk
HIPAA §164.308(b) · NIST AI RMF
D4
Workforce & Shadow AI Governance
HIPAA §164.308(a)(5) · OIG
D5
Compliance, Auditability & Governance Structure
NIST AI RMF · COSO ERM · HHS

All three editions crosswalk to the same standards — NIST AI RMF 1.0, ISO/IEC 42001, the EU AI Act, SOC 2 and COSO ERM — so a finding is portable and a score means the same thing whichever edition you were assessed under. What changes between editions is the sector obligation each domain is anchored to, and that is what makes a finding actionable rather than academic.

AegisPoint is not a law firm, and nothing on this site is legal advice. We assess governance maturity and map findings to recognised frameworks; whether any obligation applies to your organisation is a determination for your own counsel. Framework and standard names are used for identification only — trademarks are the property of their respective owners, and no affiliation or endorsement is implied.

The agent layer

One voice, many hands. Five agents; one of them talks to you.


Most AI governance products give you more dashboards to check. We give you one place to ask. Your Client Success Manager will be an AI agent, and it will say so every session. It will answer only from records your advisor has released, and it will never make a judgement call. Behind it, four headless agents will keep those records current. In build. No release date is published.

Agent roster

Each date is a commitment, not an estimate

AgentWhat it doesTalks to youBuild state
Client Success Manager Your programme manager. Answers from your records, sends the weekly digest, escalates to your consultant. Yes — and it says so ◑ In build · no date published
Program Turns validated findings into a sequenced roadmap, and re-sequences it when an action slips. No◑ In build · no date published
Monitoring Watches for shadow AI, sanctioned-AI drift, and regulatory change relevant to your inventory. No◑ In build · no date published
Policy Enforcement Evaluates whether your adopted policies cover what is actually happening, and drafts what is missing. No◑ In build · no date published
Documentation Pre-screens submitted documents and maintains the evidence crosswalk behind your assessment. No◑ In build · Q4 2026

Build state above is current and accurate. The operating layer is live today and your programme runs in it now; the agents are being built into it in the order shown. We publish where they are, because a client who advertised a control that wasn't operating would get a finding from us.

What no agent of ours may do: finalise a framework classification, adopt a policy, close a finding, or move a date you have already been shown. Two tiers of accountability sit behind that: your principal consultant is accountable for everything the agents produce on your engagement, and our Chief Product Officer is accountable for the agents as systems — action lists, autonomy levels, model versions, prompts, guardrails and logging. We can produce both on request.

Advisory

Three stages. One programme. Assess, advise, manage.


Every stage runs in the same operating layer. The assessment does not produce a PDF you file and forget — it populates the record that stages two and three then work against.

Stage 01 · Assess

AI Governance Assessment

A structured 2–3 week engagement that maps your AI usage, scores you against the five domains on evidence rather than self-report, and delivers a board-ready baseline with a sequenced remediation roadmap.

Fixed scope · 2–3 weeks · pricing on request

Stage 02 · Advise

Implementation & Advisory

We execute the roadmap alongside your team — adopting governance policies, naming accountable owners, aligning initiatives across business units, and enabling safe deployment of your priority use cases.

Scoped per engagement · pricing on request

Stage 03 · Manage

Managed Governance Programme

A standing governance programme — monitoring, policy coverage evaluation, risk scoring and executive reporting — reviewed on a set cadence with your consultant. The automated monitoring and policy-coverage agents that will run it continuously are in build, with no release date published; the programme runs on the consultant's cadence until they land.

Monthly retainer · pricing on request

Every engagement is scoped before it is priced. The assessment is fixed-scope, so we can give you the number on the discovery call — before you commit to anything. Scope is driven by the size of your AI estate, the number of business units in scope, and how many people we need to interview.

Jason Pender

Who you'll be working with

Governance is a judgement call. Someone has to make it.


Jason Pender — Founder & CEO, AegisPoint AI.

Thirty years building security businesses through partners. Jason led carrier and service-provider channels at Fortinet, Palo Alto Networks, Cisco and Netskope, and most recently ran global service-provider and systems-integrator partnerships at Cato Networks. He started at IBM Global Network in London in 1991.

He founded AegisPoint because the pattern was familiar — a new technology arriving inside enterprises faster than the controls around it, and no partner channel equipped to govern it. That is why this is built channel-first: through the advisors clients already trust, not around them.

Jason is also the accountable owner for every AegisPoint agent — their action lists, autonomy levels, models, prompts and guardrails. When we say judgement stays human, this is the human.

FortinetPalo Alto NetworksCisco NetskopeCato NetworksIBM LinkedIn →

Straight answers

Two things you'll be told that aren't true.


Not by us. These are the claims most likely to reach you from somewhere else in this market, and both fall apart under a question your auditor will ask.

"We monitor everything your AI does"

We hold governance metadata only — never prompts, responses or document content. Holding it would make us a custodian of your regulated data and a data vendor, not an independent advisor. That boundary is architectural, not a policy we could quietly relax.

"Our AI closes the loop automatically"

Agents will detect, draft, sequence and chase. A human decides, approves and signs. If the software made the call, you could not defend the outcome — and defensibility is the whole point.

Channel

Built to deliver through the partners clients trust.


AegisPoint is introduced by MSSPs, trusted advisors and technology partners — giving their clients enterprise-grade AI governance without building the capability in-house. You make the introduction; we scope, price, deliver and sign, and you shadow the engagement.

1
Introduction to get started
No onboarding programme, no certification, no commitment
0
Capability to build in-house
No framework, scoring model or platform to write
4
Deliverables per client
Assessment through board reporting
1
Vendor for your client
AegisPoint. You made the introduction

Get started

You have an AI governance gap. The only question is how big.


Start with a complimentary 30-minute discovery call. We'll map where your AI risk sits, name the gaps that matter first, and tell you plainly whether a structured assessment is the right next step — or whether it isn't.

Assessment: 2–3 weeks · fixed scope · board-ready report. Delivered by AegisPoint or through a certified partner.

The Daily AI Risk Brief covers regulatory developments, AI litigation and liability trends, and emerging security vulnerabilities. No cost, no pitch.

Book a discovery call

We reply within one business day

We use what you send here to reply to your enquiry and nothing else. No list, no sequence.