Tricycle Advisory · AI Governance Assessment
Identify Where Your AI Systems Create Governance Risk—and What to Fix First
A fixed-scope assessment for regulated organizations deploying or buying AI. Tricycle evaluates priority use cases, data flows, vendor and model controls, decision workflows, human oversight, and audit evidence—then produces a risk register and prioritized action plan.
Govern the system, not the label
The assessment follows how an AI use case actually works—from its purpose and data through its model, decisions, oversight, and evidence—before recommending policy or architecture changes.
- 5Connected control boundaries
- 4Assessment phases
- 4Decision-ready outputs
WHEN THE ASSESSMENT FITS
Use It When AI Is Moving Faster Than Ownership and Evidence
The strongest fit is a consequential AI decision that technology, risk, privacy, legal, and business owners cannot evaluate from the current documentation.
- AI use cases are already in production, but no complete inventory or risk classification exists.
- A vendor review cannot answer how data is retained, used for training, accessed, or deleted.
- An AI-supported decision affects customers, members, employees, patients, or regulated operations.
- Policy exists, but technical controls, human review, monitoring, and evidence do not consistently follow it.
- Leadership needs a prioritized remediation plan before approving deployment or additional investment.
THE GOVERNANCE PROBLEM
Three Questions Expose Most Unresolved AI Risk
The answers depend on the use case, data, provider terms, deployment architecture, and effect of the output—not simply whether a system is described as shared or private.
- 01What data enters the system, and what may the provider do with it?
- Trace collection, prompts, retrieval sources, outputs, retention, training use, subprocessors, access, location, deletion, and contractual restrictions. Architecture and vendor terms must tell the same story.
- 02Who controls the model, configuration, and changes?
- Identify who can select models, change prompts or guardrails, approve updates, grant access, monitor performance, respond to incidents, and end the service. Hosting location alone does not establish accountability.
- 03Can consequential outputs be traced, reviewed, and challenged?
- Determine how outputs affect people or operations, where human review occurs, which records are retained, how errors are escalated, and whether the organization can reconstruct what happened.
THE CONTROL MODEL
Governance Must Follow the Full Decision Path
A policy is useful only when it reaches the controls and evidence surrounding a real AI use case. The assessment follows five connected boundaries and tests what is documented, implemented, and reviewable at each one.
- 01
Use Case
Purpose, users, affected parties, intended outcome, prohibited uses, and accountable owner.
- 02
Data
Sources, sensitivity, permission, retention, location, access, and provider training terms.
- 03
Model and Vendor
Deployment, tenancy, configuration, model changes, subprocessors, security, and exit conditions.
- 04
Decision and Oversight
Output use, materiality, human review, escalation, exception handling, and contestability.
- 05
Evidence and Monitoring
Logs, versions, tests, approvals, performance thresholds, incidents, and periodic review.
Assessment principleGovernance is continuous. The evidence needed before deployment must remain available as the system, provider, data, and use case change.
HOW THE ASSESSMENT WORKS
A Defined Path From Inventory to Prioritized Action
The scope focuses on the systems and decisions that matter most. It does not require every AI experiment in the organization to be assessed at the same depth.
- 01
Inventory and Prioritize
Identify priority systems, owners, users, affected parties, decisions, vendors, and available documentation.
- 02
Trace the System
Map data, model, provider, integration, output, review, monitoring, and evidence boundaries.
- 03
Evaluate Controls
Compare stated policy with implemented technical, contractual, operational, and organizational controls.
- 04
Prioritize Remediation
Assign ownership, dependencies, decision conditions, and next actions according to risk and effort.
WHAT YOU RECEIVE
A Governance Decision Package, Not a Generic Policy Binder
The agreed scope defines the systems, use cases, evidence, stakeholders, timing, deliverables, and fee before the assessment begins.
- 01
Current-State Risk Register
Prioritized findings tied to specific systems, control gaps, affected stakeholders, evidence, assumptions, and owners.
- 02
Governance Control Recommendations
Recommended policy, technical, vendor, human-review, monitoring, and documentation controls calibrated to the assessed use cases.
- 03
Architecture Decision Record
A documented evaluation of viable hosting and operating patterns, their tradeoffs, decision conditions, and recommended path.
- 04
Prioritized Implementation Roadmap
Sequenced actions, owners, dependencies, and review points for closing the highest-priority gaps.
Architecture follows the evidence
The recommendation may support vendor-hosted, client-hosted, self-managed, hybrid, or I/O Sovereign AI™ architecture. The appropriate pattern depends on the use case, data sensitivity, provider controls, operating requirements, and organizational risk tolerance.
THE REGULATORY LENS
Requirements Are Mapped After the System Context Is Clear
Applicability depends on jurisdiction, organizational role, data, use case, affected parties, and the effect of the output. The assessment organizes evidence for review; it does not replace legal advice or certify compliance.
| Governance lens | Context that may trigger review | Evidence the assessment organizes |
|---|---|---|
| Privacy and Sensitive Data | Personal information, protected health information, behavioral data, prompts, retrieval sources, or cross-border processing. | Data flows, purpose, permission, minimization, access, retention, location, deletion, safeguards, and vendor terms. |
| Automated Decisions and Profiling | AI outputs materially influence eligibility, access, treatment, offers, employment, or another consequential outcome. | Decision role, notices, human review, rationale, records, appeal or contest process, testing, and monitoring. |
| AI-Specific Requirements | The organization provides, deploys, imports, or distributes an AI system in a jurisdiction with role- and risk-based obligations. | System classification, intended use, prohibited uses, technical documentation, oversight, transparency, performance, and incident processes. |
| Credit and Fair Lending | AI affects credit marketing, eligibility, underwriting, pricing, line management, or adverse-action decisions. | Decision factors, testing, protected-class risk review, reason codes, adverse-action support, monitoring, and escalation. |
| Internal and Contractual Controls | Enterprise policy, client commitments, vendor agreements, security requirements, or risk thresholds exceed the legal baseline. | Ownership, approvals, contracts, service levels, access controls, model changes, audit rights, portability, and termination procedures. |
BEFORE YOU ENGAGE
Questions to Resolve Before an AI Governance Assessment
The first conversation should clarify the blocked decision, priority systems, available evidence, stakeholders, and scope boundaries.
What kinds of AI systems can be assessed?
The scope can include predictive models, recommendation and personalization systems, generative AI, retrieval-augmented applications, automated decision support, and AI capabilities embedded in third-party platforms. Priority is based on use and impact, not the marketing label applied to the technology.
Do we need a complete AI inventory before starting?
No. Existing inventories help, but discovery can identify and prioritize the systems relevant to the decision. A broad inventory may be recommended as a later governance action rather than a prerequisite for focused assessment.
Does the assessment provide legal advice or certify compliance?
No. Tricycle evaluates architecture, data, vendor, workflow, oversight, monitoring, and documentation controls and organizes evidence for stakeholder review. The client’s legal and compliance advisors determine which laws apply and make legal conclusions.
How are third-party AI vendors evaluated?
The assessment reviews available contracts, data and training terms, security documentation, subprocessors, deployment model, access, model-change practices, logging, audit support, retention, deletion, portability, and termination conditions against the use case’s requirements.
Is Sovereign AI always the recommended architecture?
No. Vendor-hosted, client-hosted, self-managed, hybrid, and sovereign patterns can each be appropriate. The recommendation follows the use case, data sensitivity, contractual and technical controls, operating needs, evidence, and risk tolerance. See the deeper shared-model and sovereign AI architecture comparison.
Who should participate from our organization?
Participation commonly includes the accountable business or product owner plus technology, data, security, privacy, risk, legal or compliance, procurement, and operational stakeholders. The systems and decision determine the working team.
What information is required, and how are timing and fees established?
Useful inputs commonly include system inventories, use-case descriptions, architecture and data-flow documentation, vendor agreements, policies, risk reviews, testing, approval records, logs, and incident procedures. Before work begins, both teams agree to the systems, evidence, working team, deliverables, timeline, and fee.
START WITH THE DECISION
Bring Us the AI Governance Question Your Current Evidence Cannot Answer
Share the system or deployment being considered, the stakeholders involved, and the unresolved concern. We will determine whether a focused AI Governance Assessment is the right next step.