Home / AI & Agentic Readiness
Technology
Independent readiness, operating-model design and assurance for AI and agentic systems. We design how the work runs, set what an agent is permitted to do, and produce the record that shows it performed as designed.
We advise and assure only. That scope is what makes the opinion independent.
The Australian picture
The failure pattern is consistent: ownership sits nowhere, authority stays undefined, the baseline was never measured, and the record of what the system did runs thin.
of Australian firms have rolled back or shut down a customer-facing AI agent over governance failures — ten points above the global average.
name lack of auditability as the cause. It ranks second behind privacy, and it is the one most organisations are least equipped to answer.
of Australian organisations report a mature agentic AI governance model. The rest are deploying ahead of their controls.
Sources: Sinch survey of 2,527 senior decision-makers including 264 Australian respondents at organisations of 1,000+ employees, June 2026; Deloitte State of AI in the Enterprise, February 2026.
Most AI governance work produces the policy an organisation needs. The value turns on the layer beneath it — how the system behaves inside real work, on a real day.
We work at that layer. We design how the agent operates inside the business: the process it runs in, the actions it may take, the person who answers for the outcome, the point at which a human decides, and the way it is stopped. Then we produce the record that shows it followed the design, and whether the value arrived.
One thread runs through all of it: business architecture, runtime evidence, value realisation.
Most firms hold these three separately. The assurance opinion depends on holding them together.
How we engage
The constant that governs every VCG engagement, applied to AI. Start small, prove the value, scale with confidence.
Up to three AI or agentic use cases, examined in three weeks for a fixed fee. Where each one sits in the process, how much autonomy it holds, who owns the decision rights, and whether to proceed, redesign, constrain or stop.
The Agent-Ready X-ray →The control design an agent needs ahead of go-live: accountable owner, permitted actions, data boundaries, approval thresholds, escalation paths — and a shutdown that works.
AI & Agent Operating Model →The artefact your regulator, board or auditor will ask for: use-case register, impact assessments, conformance against the designed process, benefits realised. Delivered as an evidence pack.
Value Assurance →Retained afterwards through the Value Realisation Office — the standing function that tracks whether the benefit was banked, including from AI.
Australia regulates AI through existing law, sector regulators, critical-infrastructure rules and procurement. Each route carries a date.
Current as at August 2026. We keep this current because our clients are asked about it.
We work from the primary sources — the DTA policy and its agentic AI addendum, the NSW AI Assessment Framework, the CIRMP Rules, ISO/IEC 42001 and the NIST AI Risk Management Framework. Several widely circulated commercial summaries carry incorrect dates.
Independence
We define the evidence your systems must produce, and we read it back.
Agent telemetry, model registries and audit logs already live in the platforms you own — the hyperscaler control planes, your observability stack, your GRC tooling. That layer is commoditising fast, and it belongs with your vendors.
The judgement is where the value sits: mapping that telemetry to control assertions a board, a regulator or an underwriter will accept, in the context of your processes and your sector. That is the work we sell.
Certification to ISO/IEC 42001 is issued by accredited bodies. We handle readiness, gap closure and evidence design, and we say so plainly.
You are entitled to ask this before you ask us to assure anyone else. Our answer is published.
Every number in a VCG deliverable — a cycle time, a conformance rate, a dollar figure — is computed deterministically from your data. A language model helps structure and draft the explanation. Every finding originates with a person.
Public and method work, client-confidential work, and security-classified work each run under a separate standard. Classified and SOCI-regulated work runs inside your boundary, with external model access closed.
Every AI-assisted deliverable carries a named senior signature. Our product is judgement. The tooling gives judgement more evidence per hour.
Australian-based delivery, led by an NV2-cleared principal. Defence, Commonwealth and SOCI-regulated engagements run onshore, in your environment, with data held inside your boundary.
In your environment by default. Alternatively a minimised, de-identified extract under NDA, held in Australia, processed onshore, destroyed on completion.
Read-only access, isolated from live and OT systems. Every system stays as we found it, and agents remain untouched throughout a diagnostic.
AI performs to the standard of the data beneath it. Quality, governance and AI-ready data products — the substrate everything above rests on.
Data to Intelligence →The process twin gives an agent the operational context it acts within, and the baseline its behaviour is measured against.
Process Intelligence & BPM →Panels, clearance, independence and evidence. What the DTA policy, the NSW framework and Commonwealth procurement require of an agency — and of its suppliers.
Government →Thirty minutes with your leadership team: the AI already running in your operation, what it is permitted to do, who signed off, and which of the dates above applies to you first. No cost, no obligation.