Service · Governance

AI governance for financial and professional services.

Before an AI workflow runs on real work, someone has to write down what it may touch, what it may do, when a person signs off and what gets recorded. Airclerk does that writing for each workflow it builds, then turns it into controls the workflow enforces rather than a policy filed beside it.

01 / At a glance
Who it's for
Risk, compliance and operations leaders at regulated firms who have been handed the brief "make AI safe enough to say yes to", and the executive who owns the workflow the AI is going into.
What improves
The workflow stops being a black box. It has written boundaries, named approvers, a logging and evidence design and a running cost it is allowed to reach. A reviewer can read the rules and check they operated.
What you get
A governance and controls model for the workflow: the eleven questions below answered in writing, an approval matrix, the logging and evidence design, cost limits with alerting, and an incident path. Built into the workflow, handed over with it.
What you bring
The person who owns the workflow day to day, someone from risk or compliance who can say what your obligations require, and the policies you already have. The model is written against those, not a generic template.
Timing and cost
The fixed fee and the timeline are quoted in writing after a free introductory conversation; governance is part of every first-workflow engagement and its fee. Governance for AI you already run is scoped the same way. Platform licences and usage are separate, paid by you to the provider.
Afterwards
The controls model is handed over with the workflow, written for your firm, and post-go-live support is written into the scope. Keeping the model current as the workflow, the model or the regulation changes is part of ongoing operations, a separate agreement rather than something included by default.
02 / The framework

Eleven questions every AI workflow must answer.

These are the questions a risk committee, an auditor or a regulator will ask sooner or later. We answer them in writing before the workflow runs on real work.

G-01
What can the AI access?
G-02
What can it recommend?
G-03
What must it never do?
G-04
When is human approval required, and from whom?
G-05
What gets logged, and where?
G-06
How is evidence captured?
G-07
How are outputs reviewed?
G-08
How are incidents handled?
G-09
How is the workflow evaluated before and after go-live?
G-10
How is AI usage monitored over time?
G-11
What does each workflow cost to run, and how is spend controlled?
03 / What you receive

One controls model in five parts, and the controls that enforce it.

Each is written for one workflow. A firm with three workflows has three of each, because the right answers differ.

01

The controls document.

The eleven questions answered for this workflow, in plain language, agreed by the workflow owner and your risk lead in the detailed design, before the build starts.

02

The approval matrix.

Which steps hold for a named person, which continue with someone notified to review alongside, and which are recorded only. Set per step, to the risk of that step rather than one rule for the whole workflow.

03

The logging and evidence design.

What is recorded about each run, where it lives, who can read it and how long it is kept. Outputs cite the documents they relied on and the recorded steps that produced them.

04

Cost controls.

A budget per workflow and usage alerting, with token, tool-call and model-tier limits where the chosen platform can enforce them. Finance sees what the workflow is costing before the invoice arrives.

05

The incident path.

What happens when an output is wrong, a gate is bypassed or the model behaves unexpectedly: who is told, what is paused, and how the fix is recorded.

04 / Principles

What the answers have in common.

P-01

Human-in-the-loop by design

Critical decisions are reviewed by people. The model proposes, a person disposes, and the system records both.

P-02

Permission-aware access

The AI inherits the user's permissions. It never bypasses the access model you already have.

P-03

A record as it works

What was asked, the tools and systems used, the evidence referenced and the output produced, captured while the work happens rather than reconstructed later.

P-04

Evidence, cited

Outputs point at their source documents and the recorded steps that produced them, so a reviewer can check rather than trust.

P-05

Clear system boundaries

What the AI can read, write and trigger is defined per workflow, not per organisation.

P-06

No black-box production decisions

If we cannot explain why a workflow produced an output, it does not ship to production.

P-07

Predictable cost

Per-workflow budgets and limits, with alerting. Nobody finds out what the AI cost from the invoice.

05 / How this fits

Governance writes the rules. Assurance shows they ran.

i.

With implementation.

Governance is not a separate project you buy after the build. Every first-workflow engagement produces the controls model for the workflow it builds, and the approval gates and logging are part of what gets built. You can also ask us to write one for AI your people are already using.

ii.

With optional AI Process Assurance.

Governance is the document and the design: what should happen. AI Process Assurance is optional software, on subscription, and the retained record: what did happen, compared against what should have, with the gaps flagged. Governance without the record is a policy nobody can test. The record without governance has nothing to compare against.

iii.

With your procurement and security review.

Our own security posture is on the security page. To request the security and governance pack for vendor onboarding, talk to us.

Start with one workflow

Discuss the controls for your first workflow.

A free introductory conversation about the work, who owns it and what your obligations require. If it is a fit, a written scope with a fixed fee follows.

Talk to us →
06 / Common questions

Common questions.

01What does Airclerk's AI governance work cover?

Airclerk designs the controls, approvals, audit trails, cost controls and operating model required to run AI workflows in production. The work answers eleven questions for each workflow: what the AI can access, recommend and must never do, when human approval is required, what gets logged, how evidence is captured, how outputs are reviewed, how incidents are handled, how the workflow is evaluated, how usage is monitored over time and what it costs to run.

02Which regulatory regimes does the governance model map to?

Airclerk designs governance for firms operating under FSLAA / FAP, CoFI and FMA conduct expectations in New Zealand, and ASIC RG 271, APRA CPS 230 and CPS 234 in Australia, alongside the Privacy Act and the Contracts of Insurance Act 2024. Airclerk helps you evidence these obligations; meeting them remains the firm's responsibility, and Airclerk does not provide legal advice.

03How does AI governance relate to Airclerk's AI Process Assurance?

Governance is the written design: the controls, approvals and boundaries a workflow must operate within. AI Process Assurance is the software and the retained record that shows whether those controls operated on each run, comparing what happened against what the design said should happen and flagging the difference. Governance is part of every workflow engagement. Assurance is optional software, on subscription, that keeps the record and compares it against the design.

04How do firms keep AI spend predictable under this model?

Each workflow gets its own budget and usage alerting, with token, tool-call and model-tier limits where the chosen platform can enforce them, so finance can see what AI is costing before the invoice arrives. Cost is treated as a governance question in its own right: every workflow must answer what it costs to run and how that spend is controlled.

05How do firms get started with AI governance?

With a free introductory conversation about the workflow, who owns it and what your obligations require. The engagement that follows includes the full governance and controls model for the workflow it builds, under one fixed fee quoted in writing. Firms that want to review our security posture first can request the security and governance pack through the contact form.