Capability 03
Controls that survive an audit, not just a checklist.
The approval limits, logging and evidence trails regulators and boards now ask for. Built against the EU AI Act, state-level US rules and SOC 2, and tested by someone trying to break them.
Best fit: an audit or a board question
The problem
what goes wrongGovernance written to pass a questionnaire fails the moment someone asks for evidence. The policy exists. Nobody can show which model made a decision, who approved the spend, or what data left the building.
The gap widens once systems act on their own. A control designed for a person clicking a button doesn't cover a process running unattended at 3 a.m. A policy document is not a control an agent can read.
What we do
four piecesControl mapping
Each obligation mapped to a specific control someone can try to break. Gaps named, not smoothed over.
Approval and spend limits
Who can authorise what, enforced in the system rather than written in a policy.
Evidence and logging
Logs that answer "which system did this, on whose authority" without a manual reconstruction.
Board-ready reporting
Exposure and posture in terms a non-technical director can question, with a number to track.
Tools & resources
how this service uses themDownloads for this service are above. All free tools run in your browser and need no email.
What good looks like
6 of 6 coveredWhat buyers are increasingly measured against here, taken from the frameworks doing the measuring. Each line names the engagement that covers it. Where nothing does yet, the row says so.
| Capability | What done properly looks like | Covered by |
|---|---|---|
| An inventory of AI systems in useEU AI Act · Art. 9 | Every system is listed and classified by risk, including the ones nobody sanctioned. | 3.1 AI Governance Gap Check |
| Controls that are testable, not narrativeSOC 2 · Common Criteria | Each obligation maps to a specific control someone can attempt to break. | 3.2 Control Set & Evidence Pack |
| Approval and spend limits enforced in the systemNIST AI RMF · Manage | The limit is technical, not a line in a policy document that an agent cannot read. | 3.2 Control Set & Evidence Pack |
| Evidence produced without reconstructionSOC 2 · Monitoring | Logging answers "which system did this, on whose authority" without a manual archaeology exercise. | 3.2 Control Set & Evidence Pack |
| A published acceptable-use positionISO/IEC 42001 · Operation | Staff know what is allowed before they reach for an unsanctioned tool, and the incident path is written down. | 3.3 AI Use Policy Template |
| Someone accountable when a regulator callsISO/IEC 42001 · Leadership | Named ownership and rehearsed responses, rather than assembling a team after the letter arrives. | 3.4 Audit Standby |
Sample report: 808 Control Heatmap
808 demo datasetFictional demo company · sample data, not a client
Lakeshore Example Co.
A fictional 1,200-person distributor we use to show what our reports look like. Every number below is invented for the demo.
- 5 obligations checked across 5 systems: 25 cells
- 9 controls tested, 10 partial, 6 missing
- Agents column: 4 of 5 controls missing
- Fix order: spend limits, then evidence trail
Engagements & products
status shownThe deliverables behind this capability. We publish what is live and what is still being built rather than implying a bench we don't have.
-
3.1 Entry Planned
AI Governance Gap Check
Free diagnostic
A short diagnostic against the obligations that actually apply to you: EU AI Act exposure, state-level US rules, SOC 2. It returns the gaps most likely to fail a real audit, not a questionnaire.
Shadow Scanner Unsanctioned inventory and egress findings turn a self-assessment into evidence.
-
3.2 Anchor engagement Planned
Control Set & Evidence Pack
Fixed-fee engagement · 4–6 weeks
Your obligations turned into specific, testable controls. Approval and spend limits enforced in the system, not described in a document. Evidence trails that answer an auditor without a manual reconstruction.
Shadow Scanner Egress vectors, missing SSO enforcement and access that outlived the employee: the findings an auditor asks for and most teams cannot produce.
-
3.3 Anchor engagement Planned
AI Use Policy Template
Productised template + half-day tailoring
A policy pack you adopt and adapt: acceptable use, approval thresholds, data handling, agent boundaries and the incident path. Sold with a working session, because templates on their own get filed and forgotten.
Shadow Scanner Scan findings tell you which clauses your organisation actually needs first.
-
3.4 Continuing Planned
Audit Standby
Retainer
On-call support through an audit or a regulator enquiry: evidence assembly, questionnaire responses, and someone in the room who knows how the controls were built.
Shadow Scanner A current scan on file means evidence gathering starts from something, not from nothing.
Status is kept in one place and shown as it stands. See the full catalogue across all six capabilities.
Further reading
frameworks · research · our work, on this topic- LawRegulation (EU) 2024/1689 — the AI Act, full textThe law itself, for anyone selling AI into the EU or using it on EU customers.EUR-Lex ↗
- StandardISO/IEC 42001:2023 — AI management systemsThe certifiable standard for running AI under a management system.ISO ↗
- LawOntario Bill 194: Strengthening Cyber Security and Building Trust in the Public Sector Act, 2024Ontario rules for AI use in the public sector, relevant to its suppliers.Government of Ontario ↗
- PolicyDirective on Automated Decision-MakingCanada’s federal rules for automated decisions, with an impact assessment.Treasury Board of Canada Secretariat ↗
How Shadow Scanner helps
platform intelligence & risk telemetryAn audit asks two questions: what is running, and who can reach it. Shadow Scanner answers both from telemetry, not a self-reported survey. That is usually where the gap between policy and practice shows.
What you walk away with
the outcomeA control set that holds up when someone tests it, and documentation of what is actually running — not what was intended a year ago.
The trade-off. Enforced limits create friction. Some requests that used to go through on a credit card will now wait for an approval. That friction is the control working.
Tell us what you're running.
A person replies within one business day.