September 2026

Capability 03

Controls that survive an audit, not just a checklist.

The approval limits, logging and evidence trails regulators and boards now ask for. Built against the EU AI Act, state-level US rules and SOC 2, and tested by someone trying to break them.

Best fit: an audit or a board question

One-page service sheet preview

Downloads

take it to the meeting

Service sheets follow one standard across all six capabilities. Engagement status on each sheet is taken from the live catalogue.

The problem

what goes wrong

Governance written to pass a questionnaire fails the moment someone asks for evidence. The policy exists. Nobody can show which model made a decision, who approved the spend, or what data left the building.

The gap widens once systems act on their own. A control designed for a person clicking a button doesn't cover a process running unattended at 3 a.m. A policy document is not a control an agent can read.

What we do

four pieces
01

Control mapping

Each obligation mapped to a specific control someone can try to break. Gaps named, not smoothed over.

02

Approval and spend limits

Who can authorise what, enforced in the system rather than written in a policy.

03

Evidence and logging

Logs that answer "which system did this, on whose authority" without a manual reconstruction.

04

Board-ready reporting

Exposure and posture in terms a non-technical director can question, with a number to track.

What good looks like

6 of 6 covered

What buyers are increasingly measured against here, taken from the frameworks doing the measuring. Each line names the engagement that covers it. Where nothing does yet, the row says so.

CapabilityWhat done properly looks likeCovered by
An inventory of AI systems in useEU AI Act · Art. 9 Every system is listed and classified by risk, including the ones nobody sanctioned. 3.1 AI Governance Gap Check
Controls that are testable, not narrativeSOC 2 · Common Criteria Each obligation maps to a specific control someone can attempt to break. 3.2 Control Set & Evidence Pack
Approval and spend limits enforced in the systemNIST AI RMF · Manage The limit is technical, not a line in a policy document that an agent cannot read. 3.2 Control Set & Evidence Pack
Evidence produced without reconstructionSOC 2 · Monitoring Logging answers "which system did this, on whose authority" without a manual archaeology exercise. 3.2 Control Set & Evidence Pack
A published acceptable-use positionISO/IEC 42001 · Operation Staff know what is allowed before they reach for an unsanctioned tool, and the incident path is written down. 3.3 AI Use Policy Template
Someone accountable when a regulator callsISO/IEC 42001 · Leadership Named ownership and rehearsed responses, rather than assembling a team after the letter arrives. 3.4 Audit Standby

Sample report: 808 Control Heatmap

808 demo dataset
CRMSUPPORTDEVHRAGENTSInventoryTestable controlsSpend limitsEvidence trailUse policyTESTEDPARTIALMISSING
Lakeshore Example Co. · Fictional demo company · sample data, not a client

Fictional demo company · sample data, not a client

Lakeshore Example Co.

A fictional 1,200-person distributor we use to show what our reports look like. Every number below is invented for the demo.

  • 5 obligations checked across 5 systems: 25 cells
  • 9 controls tested, 10 partial, 6 missing
  • Agents column: 4 of 5 controls missing
  • Fix order: spend limits, then evidence trail

Engagements & products

status shown

The deliverables behind this capability. We publish what is live and what is still being built rather than implying a bench we don't have.

  • 3.1 Entry Planned

    AI Governance Gap Check

    Free diagnostic

    A short diagnostic against the obligations that actually apply to you: EU AI Act exposure, state-level US rules, SOC 2. It returns the gaps most likely to fail a real audit, not a questionnaire.

    Shadow Scanner Unsanctioned inventory and egress findings turn a self-assessment into evidence.

  • 3.2 Anchor engagement Planned

    Control Set & Evidence Pack

    Fixed-fee engagement · 4–6 weeks

    Your obligations turned into specific, testable controls. Approval and spend limits enforced in the system, not described in a document. Evidence trails that answer an auditor without a manual reconstruction.

    Shadow Scanner Egress vectors, missing SSO enforcement and access that outlived the employee: the findings an auditor asks for and most teams cannot produce.

  • 3.3 Anchor engagement Planned

    AI Use Policy Template

    Productised template + half-day tailoring

    A policy pack you adopt and adapt: acceptable use, approval thresholds, data handling, agent boundaries and the incident path. Sold with a working session, because templates on their own get filed and forgotten.

    Shadow Scanner Scan findings tell you which clauses your organisation actually needs first.

  • 3.4 Continuing Planned

    Audit Standby

    Retainer

    On-call support through an audit or a regulator enquiry: evidence assembly, questionnaire responses, and someone in the room who knows how the controls were built.

    Shadow Scanner A current scan on file means evidence gathering starts from something, not from nothing.

Status is kept in one place and shown as it stands. See the full catalogue across all six capabilities.

How Shadow Scanner helps

platform intelligence & risk telemetry

An audit asks two questions: what is running, and who can reach it. Shadow Scanner answers both from telemetry, not a self-reported survey. That is usually where the gap between policy and practice shows.

More about Shadow Scanner

What you walk away with

the outcome

A control set that holds up when someone tests it, and documentation of what is actually running — not what was intended a year ago.

The trade-off. Enforced limits create friction. Some requests that used to go through on a credit card will now wait for an approval. That friction is the control working.

The five stages

Tell us what you're running.

A person replies within one business day.

Talk to us