Why “we have a policy” fails the first review
Procurement and counsel do not want philosophy. They want owners, systems, data categories, and controls you can export. Shadow AI — staff pasting customer data into consumer tools — rarely appears in the official register. Vendor AI features hide inside SaaS renewals. Agent credentials show up in logs without a named human approver.
From an ops lens, treat governance like any other control plane: a living register, named owners, and artifacts you can produce on demand. Policy without evidence fails the first questionnaire.
What “good enough” evidence looks like
Start with a short inventory that catches production and shadow use:
- System or tool name (including unofficial ChatGPT / Copilot use)
- Business owner and technical owner
- Data categories touched (personal, commercial, secrets, none)
- Whether the system makes or assists decisions about people
- Controls: access, logging, retention, human approval gates
- Where evidence lives (ticket, SIEM, eval store, export path)
Then keep an approval trail for high-impact actions — especially anything an agent can trigger. If you cannot tell a human approval from an agent API key in the log, security review will stall the rollout.
Further reading that goes deeper on Australia
For jurisdiction-specific depth, Cipher Projects has been publishing a practical series we regularly hand to operations and risk stakeholders:
Use those pieces for the legal and inventory detail. Use your own register and exports for the operating proof. Bear’s job on engagements is to connect the two so the demo does not outrun the evidence.
A one-week starter plan
Day 1–2: Spreadsheet inventory from SSO apps, expense tools, vendor contracts, and a short staff survey.
Day 3: Flag anything that touches personal data or customer content; assign owners.
Day 4: For each high-impact flow, confirm a human approval gate and an exportable log.
Day 5: Draft the one-pager counsel asks for — systems, owners, decisions, gaps — then schedule the deeper reading above with your risk lead.
Related reading in this series