GOVERNANCE EVIDENCE OS™ · ExampleAI B.V. · SAMPLE
Governance Evidence OS™ · sample

What a governance evidence pack looks like.

This is the kind of anonymised pack I hand over so you can answer a customer security review or a board question with something concrete. The example below is fictional; a real pack is built from your own evidence and you approve every line before it leaves your hands.

Fictional sample

ExampleAI B.V. is not a real client. This pack is a fabricated illustration, no real customer data, systems or documents are described.

Leadership summary

The evidence pack is ready for a customer security review. Two items should be closed first: staff use of consumer AI tools, and an undefined retention limit on AI prompts and outputs.

1. AI and data risk register (extract)

IDRiskLikelihoodImpactOwnerFirst mitigation
GR-01Customer personal data sent to a third-party model without a data processing agreementMediumHighCTODPA in place; minimise personal data before prompts
GR-02No retention limit on stored AI prompts and outputsMediumMediumEng leadDefine and enforce a 30-day retention rule
GR-03Staff use consumer AI tools for client dataHighHighHR / AllAI acceptable use policy plus approved tooling
GR-04No human review on AI-generated customer messagesMediumMediumSupport leadAdd a review step before outbound AI content
GR-05AI subprocessors not mappedMediumMediumSecurityMaintain an AI and subprocessor inventory

2. Security questionnaire response (extract)

Do you have an AI acceptable use policy?

Yes. A documented policy covers approved tools, prohibited data and human review. Evidence: AI acceptable use policy v1.2.

Is customer data sent to third-party AI models?

Only to contracted providers under a data processing agreement, with personal data minimised before processing.

Do you hold ISO 27001 certification?flag

Not certified yet. Controls are mapped to ISO 27001 Annex A as readiness, and certification is on the roadmap. Stated plainly so the answer is defensible.

Flagged answer: where you cannot yet say yes, I give you defensible wording to validate, not a claim you cannot back.

3. AI acceptable use policy (extract)

Do
  • Use approved AI tools for non-sensitive drafting and research.
  • Review AI output before it reaches a customer or goes into production.
Do not
  • Paste customer personal data, secrets or source code into consumer AI tools.
  • Present AI output as reviewed work without checking it.

Where this stops

This is technical readiness and evidence support, not legal advice and not certification. Where you need certified sign-off, a DPIA or a penetration test, I tell you who to bring in. Technical readiness support, not a compliance guarantee.

See Governance Evidence OS™ →

Contact

Book a call

Tell me what you are working on. I will tell you plainly whether I can help, and how.

Calendar not loading? Email contact@sirrapa.com