Model and use-case inventory
What exists, who owns it, what data it touches, what decision it affects and when it was last reviewed.
AI Capabilities & Services
Policies, lineage, and controls that keep your data and AI trustworthy and compliant.
AI arrives in an organisation faster than the controls around it. Within a year there are models in production nobody has inventoried, staff pasting confidential material into consumer tools because the approved path is slower, and no answer to the question a regulator or a customer will eventually ask: on what basis was this decision made, and who is accountable for it. Policy alone does not fix this — a rule that bans the only practical way to do the work gets routed around.
What exists, who owns it, what data it touches, what decision it affects and when it was last reviewed.
Proportionate control: a drafting assistant and a credit decision should not carry the same process.
What may go where, with an approved route for the work people are already doing another way.
Being able to reconstruct a decision — inputs, model version, approver and date — after it has been challenged.
Models, tools, assistants and spreadsheets doing model-like work — including the ones nobody registered.
By what the output affects, not by how sophisticated the technology is. A simple model deciding eligibility outranks a complex one drafting text.
Approval, testing, human review, logging and review frequency, scaled to the tier rather than applied uniformly.
The approved tool, the approved data route, and the approval that takes days rather than quarters. Controls people can follow are the only ones that work.
Scheduled review by tier, drift monitoring on live models, and a route for reporting a wrong output.
Current state against the regulations that apply to you, with the gaps ranked by exposure rather than by count.
Who approves what, at which tier, and how quickly — designed so the sanctioned path is the path of least resistance.
The register, the control set, the templates and the evidence trail, populated with what you actually have.
Training the people who build and the people who approve, because a framework nobody was taught is a document.
Discovery and risk tiering come first and move quickly, because the value is in finding what nobody had listed. The operating model takes as long as your approval culture takes to agree — and embedding it is continuous, not a phase. A framework delivered and not used is the most common outcome in this field, so the engagement is designed to end with people trained rather than a document delivered.
This is not legal advice, and it does not certify you as compliant with anything — that determination belongs to your counsel and your regulator. It also cannot succeed as a policy alone: unless the sanctioned path is genuinely faster than the workaround, staff will keep using the workaround, and no amount of framework changes that.
Tiering exists precisely to stop that. Most use cases are low-consequence and should pass through a light, fast route; the heavy process is reserved for the few decisions that warrant it.
Give them an approved alternative that does the job, then enforce. Enforcement without an alternative moves the behaviour out of sight rather than stopping it.
This page describes capability and method. It does not publish accuracy figures, throughput numbers or delivery dates, because those depend on your data, your systems and your scope — and a number published here would be wrong for most readers. You get them, in writing and against your own data, at scoping.
A first call is a technical conversation, not a pitch: what you have, what you need, and whether this is the right approach at all.
Every InsAI product runs on the same four-stage backbone.
ERP · IoT · BIM · CRM
Forecasting, detection, optimization
Acting on predictions, end to end
From the floor to the boardroom
Policies, lineage, and controls that keep your data and AI trustworthy and compliant.
Security Features
Verification successful
Secure · Private · Verified