What a governance evidence pack looks like.
This is the kind of anonymised pack I hand over so you can answer a customer security review or a board question with something concrete. The example below is fictional; a real pack is built from your own evidence and you approve every line before it leaves your hands.
Leadership summary
The evidence pack is ready for a customer security review. Two items should be closed first: staff use of consumer AI tools, and an undefined retention limit on AI prompts and outputs.
1. AI and data risk register (extract)
| ID | Risk | Likelihood | Impact | Owner | First mitigation |
|---|---|---|---|---|---|
| GR-01 | Customer personal data sent to a third-party model without a data processing agreement | Medium | High | CTO | DPA in place; minimise personal data before prompts |
| GR-02 | No retention limit on stored AI prompts and outputs | Medium | Medium | Eng lead | Define and enforce a 30-day retention rule |
| GR-03 | Staff use consumer AI tools for client data | High | High | HR / All | AI acceptable use policy plus approved tooling |
| GR-04 | No human review on AI-generated customer messages | Medium | Medium | Support lead | Add a review step before outbound AI content |
| GR-05 | AI subprocessors not mapped | Medium | Medium | Security | Maintain an AI and subprocessor inventory |
2. Security questionnaire response (extract)
Yes. A documented policy covers approved tools, prohibited data and human review. Evidence: AI acceptable use policy v1.2.
Only to contracted providers under a data processing agreement, with personal data minimised before processing.
Not certified yet. Controls are mapped to ISO 27001 Annex A as readiness, and certification is on the roadmap. Stated plainly so the answer is defensible.
Flagged answer: where you cannot yet say yes, I give you defensible wording to validate, not a claim you cannot back.
3. AI acceptable use policy (extract)
- Use approved AI tools for non-sensitive drafting and research.
- Review AI output before it reaches a customer or goes into production.
- Paste customer personal data, secrets or source code into consumer AI tools.
- Present AI output as reviewed work without checking it.
Where this stops
This is technical readiness and evidence support, not legal advice and not certification. Where you need certified sign-off, a DPIA or a penetration test, I tell you who to bring in. Technical readiness support, not a compliance guarantee.
