Before an AI workflow runs on real work, someone has to write down what it may touch, what it may do, when a person signs off and what gets recorded. Airclerk does that writing for each workflow it builds, then turns it into controls the workflow enforces rather than a policy filed beside it.
These are the questions a risk committee, an auditor or a regulator will ask sooner or later. We answer them in writing before the workflow runs on real work.
Each is written for one workflow. A firm with three workflows has three of each, because the right answers differ.
The eleven questions answered for this workflow, in plain language, agreed by the workflow owner and your risk lead in the detailed design, before the build starts.
Which steps hold for a named person, which continue with someone notified to review alongside, and which are recorded only. Set per step, to the risk of that step rather than one rule for the whole workflow.
What is recorded about each run, where it lives, who can read it and how long it is kept. Outputs cite the documents they relied on and the recorded steps that produced them.
A budget per workflow and usage alerting, with token, tool-call and model-tier limits where the chosen platform can enforce them. Finance sees what the workflow is costing before the invoice arrives.
What happens when an output is wrong, a gate is bypassed or the model behaves unexpectedly: who is told, what is paused, and how the fix is recorded.
Critical decisions are reviewed by people. The model proposes, a person disposes, and the system records both.
The AI inherits the user's permissions. It never bypasses the access model you already have.
What was asked, the tools and systems used, the evidence referenced and the output produced, captured while the work happens rather than reconstructed later.
Outputs point at their source documents and the recorded steps that produced them, so a reviewer can check rather than trust.
What the AI can read, write and trigger is defined per workflow, not per organisation.
If we cannot explain why a workflow produced an output, it does not ship to production.
Per-workflow budgets and limits, with alerting. Nobody finds out what the AI cost from the invoice.
Governance is not a separate project you buy after the build. Every first-workflow engagement produces the controls model for the workflow it builds, and the approval gates and logging are part of what gets built. You can also ask us to write one for AI your people are already using.
Governance is the document and the design: what should happen. AI Process Assurance is optional software, on subscription, and the retained record: what did happen, compared against what should have, with the gaps flagged. Governance without the record is a policy nobody can test. The record without governance has nothing to compare against.
Our own security posture is on the security page. To request the security and governance pack for vendor onboarding, talk to us.
A free introductory conversation about the work, who owns it and what your obligations require. If it is a fit, a written scope with a fixed fee follows.
Airclerk designs the controls, approvals, audit trails, cost controls and operating model required to run AI workflows in production. The work answers eleven questions for each workflow: what the AI can access, recommend and must never do, when human approval is required, what gets logged, how evidence is captured, how outputs are reviewed, how incidents are handled, how the workflow is evaluated, how usage is monitored over time and what it costs to run.
Airclerk designs governance for firms operating under FSLAA / FAP, CoFI and FMA conduct expectations in New Zealand, and ASIC RG 271, APRA CPS 230 and CPS 234 in Australia, alongside the Privacy Act and the Contracts of Insurance Act 2024. Airclerk helps you evidence these obligations; meeting them remains the firm's responsibility, and Airclerk does not provide legal advice.
Governance is the written design: the controls, approvals and boundaries a workflow must operate within. AI Process Assurance is the software and the retained record that shows whether those controls operated on each run, comparing what happened against what the design said should happen and flagging the difference. Governance is part of every workflow engagement. Assurance is optional software, on subscription, that keeps the record and compares it against the design.
Each workflow gets its own budget and usage alerting, with token, tool-call and model-tier limits where the chosen platform can enforce them, so finance can see what AI is costing before the invoice arrives. Cost is treated as a governance question in its own right: every workflow must answer what it costs to run and how that spend is controlled.
With a free introductory conversation about the workflow, who owns it and what your obligations require. The engagement that follows includes the full governance and controls model for the workflow it builds, under one fixed fee quoted in writing. Firms that want to review our security posture first can request the security and governance pack through the contact form.