Home / AI & Agentic Readiness

Technology

AI that earns its place — with the evidence to prove it.

Independent readiness, operating-model design and assurance for AI and agentic systems. We design how the work runs, set what an agent is permitted to do, and produce the record that shows it performed as designed.

We advise and assure only. That scope is what makes the opinion independent.

  • Independent
  • Vendor-neutral
  • Evidence-led
  • Delivered in Australia

The Australian picture

Australian organisations are deploying agents faster than they are governing them.

The failure pattern is consistent: ownership sits nowhere, authority stays undefined, the baseline was never measured, and the record of what the system did runs thin.

84%

of Australian firms have rolled back or shut down a customer-facing AI agent over governance failures — ten points above the global average.

22%

name lack of auditability as the cause. It ranks second behind privacy, and it is the one most organisations are least equipped to answer.

22%

of Australian organisations report a mature agentic AI governance model. The rest are deploying ahead of their controls.

Sources: Sinch survey of 2,527 senior decision-makers including 264 Australian respondents at organisations of 1,000+ employees, June 2026; Deloitte State of AI in the Enterprise, February 2026.

Policy sets the intent. Design decides what happens.

Most AI governance work produces the policy an organisation needs. The value turns on the layer beneath it — how the system behaves inside real work, on a real day.

We work at that layer. We design how the agent operates inside the business: the process it runs in, the actions it may take, the person who answers for the outcome, the point at which a human decides, and the way it is stopped. Then we produce the record that shows it followed the design, and whether the value arrived.

One thread runs through all of it: business architecture, runtime evidence, value realisation.

Business architecture The process the agent runs in, the decision rights, the accountable owner. DESIGNED Runtime evidence What the agent actually did, measured against what it was designed to do. OBSERVED Value realisation Whether the benefit arrived, in dollars, against the measured baseline. BANKED

Most firms hold these three separately. The assurance opinion depends on holding them together.

How we engage

Decide, then design, then assure.

The constant that governs every VCG engagement, applied to AI. Start small, prove the value, scale with confidence.

01 · Decide

The Agent-Ready X-ray

Up to three AI or agentic use cases, examined in three weeks for a fixed fee. Where each one sits in the process, how much autonomy it holds, who owns the decision rights, and whether to proceed, redesign, constrain or stop.

The Agent-Ready X-ray →

02 · Design

AI & Agent Operating Model

The control design an agent needs ahead of go-live: accountable owner, permitted actions, data boundaries, approval thresholds, escalation paths — and a shutdown that works.

AI & Agent Operating Model →

03 · Assure

Evidence & attestation

The artefact your regulator, board or auditor will ask for: use-case register, impact assessments, conformance against the designed process, benefits realised. Delivered as an evidence pack.

Value Assurance →

Retained afterwards through the Value Realisation Office — the standing function that tracks whether the benefit was banked, including from AI.

What you will be asked for, and when

Australia regulates AI through existing law, sector regulators, critical-infrastructure rules and procurement. Each route carries a date.

TODAY DEC 2026 Privacy ADM · DTA register APR 2027 Legacy AI back-capture JUN 2027 SOCI core cyber, incl. AI OCT 2027 NSW signed attestation DEC 2027 EU AI Act high-risk

The compliance clock

Current as at August 2026. We keep this current because our clients are asked about it.

10 Dec 2026
Privacy Act — automated decision-making transparency. Every APP entity must disclose the personal information used, and the decisions made or substantially assisted by a computer program. The "substantially and directly related" test reaches decision-support systems as well as fully automated ones — which is where most enterprise AI sits.
15 Dec 2026
Commonwealth entities — DTA AI policy. An internal AI use-case register, an accountable owner named for every use case, and an AI impact assessment completed before deployment.
30 Apr 2027
Commonwealth entities — back-capture. Every pre-existing AI use case still unassessed must have a completed impact assessment. A bounded sweep across the whole legacy estate, and the deadline most agencies are least prepared for.
~10 Jun 2027
Critical infrastructure — SOCI Enhanced CIRMP Rules. Core cyber risks now expressly include "the deployment or hostile use of advanced, novel or emerging technology (including AI)". Both halves count: AI you deploy, and AI used against you. Water, electricity, gas and freight are all in scope.
31 Oct 2027
NSW agencies — Circular DCS-2026-02. An Accountable Official, every AI use case registered, high and critical risk referred for review — and a signed annual attestation, first due on this date.
2 Dec 2027
EU AI Act — high-risk obligations. Deferred from August 2026 by the AI Omnibus and still binding on Australian organisations whose outputs are used in the EU. Transparency and marking obligations already apply.
In force now
APRA-regulated entities. APRA's April 2026 letter to industry sets expectations for board AI literacy, an AI inventory, third- and fourth-party supply-chain visibility, and continuous monitoring — and states that assurance practices are falling behind.
In force now
Government suppliers. Commonwealth model AI clauses and Victorian procurement terms require you to disclose AI use, obtain approval before using it in delivery, keep records, and show evidence of your own AI governance.

We work from the primary sources — the DTA policy and its agentic AI addendum, the NSW AI Assessment Framework, the CIRMP Rules, ISO/IEC 42001 and the NIST AI Risk Management Framework. Several widely circulated commercial summaries carry incorrect dates.

Independence

Our scope

We define the evidence your systems must produce, and we read it back.

Agent telemetry, model registries and audit logs already live in the platforms you own — the hyperscaler control planes, your observability stack, your GRC tooling. That layer is commoditising fast, and it belongs with your vendors.

The judgement is where the value sits: mapping that telemetry to control assertions a board, a regulator or an underwriter will accept, in the context of your processes and your sector. That is the work we sell.

Certification to ISO/IEC 42001 is issued by accredited bodies. We handle readiness, gap closure and evidence design, and we say so plainly.

How we use AI in our own delivery

You are entitled to ask this before you ask us to assure anyone else. Our answer is published.

Code computes. AI narrates.

Every number in a VCG deliverable — a cycle time, a conformance rate, a dollar figure — is computed deterministically from your data. A language model helps structure and draft the explanation. Every finding originates with a person.

Tiered data handling

Public and method work, client-confidential work, and security-classified work each run under a separate standard. Classified and SOCI-regulated work runs inside your boundary, with external model access closed.

Named human sign-off

Every AI-assisted deliverable carries a named senior signature. Our product is judgement. The tooling gives judgement more evidence per hour.

Where the work is done

Australian-based delivery, led by an NV2-cleared principal. Defence, Commonwealth and SOCI-regulated engagements run onshore, in your environment, with data held inside your boundary.

Where the data lives

In your environment by default. Alternatively a minimised, de-identified extract under NDA, held in Australia, processed onshore, destroyed on completion.

How we connect

Read-only access, isolated from live and OT systems. Every system stays as we found it, and agents remain untouched throughout a diagnostic.

What this connects to

Data to Intelligence

AI performs to the standard of the data beneath it. Quality, governance and AI-ready data products — the substrate everything above rests on.

Data to Intelligence →

Process Intelligence

The process twin gives an agent the operational context it acts within, and the baseline its behaviour is measured against.

Process Intelligence & BPM →

Government

Panels, clearance, independence and evidence. What the DTA policy, the NSW framework and Commonwealth procurement require of an agency — and of its suppliers.

Government →

Start with a conversation

Thirty minutes with your leadership team: the AI already running in your operation, what it is permitted to do, who signed off, and which of the dates above applies to you first. No cost, no obligation.