Tricycle Advisory · AI Governance Assessment

Identify Where Your AI Systems Create Governance Risk—and What to Fix First

A fixed-scope assessment for regulated organizations deploying or buying AI. Tricycle evaluates priority use cases, data flows, vendor and model controls, decision workflows, human oversight, and audit evidence—then produces a risk register and prioritized action plan.

Govern the system, not the label

The assessment follows how an AI use case actually works—from its purpose and data through its model, decisions, oversight, and evidence—before recommending policy or architecture changes.

  • 5Connected control boundaries
  • 4Assessment phases
  • 4Decision-ready outputs

WHEN THE ASSESSMENT FITS

Use It When AI Is Moving Faster Than Ownership and Evidence

The strongest fit is a consequential AI decision that technology, risk, privacy, legal, and business owners cannot evaluate from the current documentation.

  • AI use cases are already in production, but no complete inventory or risk classification exists.
  • A vendor review cannot answer how data is retained, used for training, accessed, or deleted.
  • An AI-supported decision affects customers, members, employees, patients, or regulated operations.
  • Policy exists, but technical controls, human review, monitoring, and evidence do not consistently follow it.
  • Leadership needs a prioritized remediation plan before approving deployment or additional investment.

THE GOVERNANCE PROBLEM

Three Questions Expose Most Unresolved AI Risk

The answers depend on the use case, data, provider terms, deployment architecture, and effect of the output—not simply whether a system is described as shared or private.

01What data enters the system, and what may the provider do with it?
Trace collection, prompts, retrieval sources, outputs, retention, training use, subprocessors, access, location, deletion, and contractual restrictions. Architecture and vendor terms must tell the same story.
02Who controls the model, configuration, and changes?
Identify who can select models, change prompts or guardrails, approve updates, grant access, monitor performance, respond to incidents, and end the service. Hosting location alone does not establish accountability.
03Can consequential outputs be traced, reviewed, and challenged?
Determine how outputs affect people or operations, where human review occurs, which records are retained, how errors are escalated, and whether the organization can reconstruct what happened.

THE CONTROL MODEL

Governance Must Follow the Full Decision Path

A policy is useful only when it reaches the controls and evidence surrounding a real AI use case. The assessment follows five connected boundaries and tests what is documented, implemented, and reviewable at each one.

  1. 01

    Use Case

    Purpose, users, affected parties, intended outcome, prohibited uses, and accountable owner.

  2. 02

    Data

    Sources, sensitivity, permission, retention, location, access, and provider training terms.

  3. 03

    Model and Vendor

    Deployment, tenancy, configuration, model changes, subprocessors, security, and exit conditions.

  4. 04

    Decision and Oversight

    Output use, materiality, human review, escalation, exception handling, and contestability.

  5. 05

    Evidence and Monitoring

    Logs, versions, tests, approvals, performance thresholds, incidents, and periodic review.

Assessment principleGovernance is continuous. The evidence needed before deployment must remain available as the system, provider, data, and use case change.

HOW THE ASSESSMENT WORKS

A Defined Path From Inventory to Prioritized Action

The scope focuses on the systems and decisions that matter most. It does not require every AI experiment in the organization to be assessed at the same depth.

  1. 01

    Inventory and Prioritize

    Identify priority systems, owners, users, affected parties, decisions, vendors, and available documentation.

  2. 02

    Trace the System

    Map data, model, provider, integration, output, review, monitoring, and evidence boundaries.

  3. 03

    Evaluate Controls

    Compare stated policy with implemented technical, contractual, operational, and organizational controls.

  4. 04

    Prioritize Remediation

    Assign ownership, dependencies, decision conditions, and next actions according to risk and effort.

WHAT YOU RECEIVE

A Governance Decision Package, Not a Generic Policy Binder

The agreed scope defines the systems, use cases, evidence, stakeholders, timing, deliverables, and fee before the assessment begins.

  1. 01

    Current-State Risk Register

    Prioritized findings tied to specific systems, control gaps, affected stakeholders, evidence, assumptions, and owners.

  2. 02

    Governance Control Recommendations

    Recommended policy, technical, vendor, human-review, monitoring, and documentation controls calibrated to the assessed use cases.

  3. 03

    Architecture Decision Record

    A documented evaluation of viable hosting and operating patterns, their tradeoffs, decision conditions, and recommended path.

  4. 04

    Prioritized Implementation Roadmap

    Sequenced actions, owners, dependencies, and review points for closing the highest-priority gaps.

Architecture follows the evidence

The recommendation may support vendor-hosted, client-hosted, self-managed, hybrid, or I/O Sovereign AI™ architecture. The appropriate pattern depends on the use case, data sensitivity, provider controls, operating requirements, and organizational risk tolerance.

THE REGULATORY LENS

Requirements Are Mapped After the System Context Is Clear

Applicability depends on jurisdiction, organizational role, data, use case, affected parties, and the effect of the output. The assessment organizes evidence for review; it does not replace legal advice or certify compliance.

Governance lensContext that may trigger reviewEvidence the assessment organizes
Privacy and Sensitive DataPersonal information, protected health information, behavioral data, prompts, retrieval sources, or cross-border processing.Data flows, purpose, permission, minimization, access, retention, location, deletion, safeguards, and vendor terms.
Automated Decisions and ProfilingAI outputs materially influence eligibility, access, treatment, offers, employment, or another consequential outcome.Decision role, notices, human review, rationale, records, appeal or contest process, testing, and monitoring.
AI-Specific RequirementsThe organization provides, deploys, imports, or distributes an AI system in a jurisdiction with role- and risk-based obligations.System classification, intended use, prohibited uses, technical documentation, oversight, transparency, performance, and incident processes.
Credit and Fair LendingAI affects credit marketing, eligibility, underwriting, pricing, line management, or adverse-action decisions.Decision factors, testing, protected-class risk review, reason codes, adverse-action support, monitoring, and escalation.
Internal and Contractual ControlsEnterprise policy, client commitments, vendor agreements, security requirements, or risk thresholds exceed the legal baseline.Ownership, approvals, contracts, service levels, access controls, model changes, audit rights, portability, and termination procedures.

BEFORE YOU ENGAGE

Questions to Resolve Before an AI Governance Assessment

The first conversation should clarify the blocked decision, priority systems, available evidence, stakeholders, and scope boundaries.

What kinds of AI systems can be assessed?

The scope can include predictive models, recommendation and personalization systems, generative AI, retrieval-augmented applications, automated decision support, and AI capabilities embedded in third-party platforms. Priority is based on use and impact, not the marketing label applied to the technology.

Do we need a complete AI inventory before starting?

No. Existing inventories help, but discovery can identify and prioritize the systems relevant to the decision. A broad inventory may be recommended as a later governance action rather than a prerequisite for focused assessment.

Does the assessment provide legal advice or certify compliance?

No. Tricycle evaluates architecture, data, vendor, workflow, oversight, monitoring, and documentation controls and organizes evidence for stakeholder review. The client’s legal and compliance advisors determine which laws apply and make legal conclusions.

How are third-party AI vendors evaluated?

The assessment reviews available contracts, data and training terms, security documentation, subprocessors, deployment model, access, model-change practices, logging, audit support, retention, deletion, portability, and termination conditions against the use case’s requirements.

Is Sovereign AI always the recommended architecture?

No. Vendor-hosted, client-hosted, self-managed, hybrid, and sovereign patterns can each be appropriate. The recommendation follows the use case, data sensitivity, contractual and technical controls, operating needs, evidence, and risk tolerance. See the deeper shared-model and sovereign AI architecture comparison.

Who should participate from our organization?

Participation commonly includes the accountable business or product owner plus technology, data, security, privacy, risk, legal or compliance, procurement, and operational stakeholders. The systems and decision determine the working team.

What information is required, and how are timing and fees established?

Useful inputs commonly include system inventories, use-case descriptions, architecture and data-flow documentation, vendor agreements, policies, risk reviews, testing, approval records, logs, and incident procedures. Before work begins, both teams agree to the systems, evidence, working team, deliverables, timeline, and fee.

START WITH THE DECISION

Bring Us the AI Governance Question Your Current Evidence Cannot Answer

Share the system or deployment being considered, the stakeholders involved, and the unresolved concern. We will determine whether a focused AI Governance Assessment is the right next step.

Discuss Your Governance Question