ThePlus Tech / GreavewiseSample pack · Fictional data
AI Governance and Control Readiness AssessmentAIG–SAMPLE–001Prepared 4 September 2026
Fictional demonstration · Not a client result

Agent authority and evidence records.

Northgate Wealth Partners · Client onboarding

01

Executive decision

Close accountability first

The estate meets nine of ten readiness criteria and still carries three critical findings. The score counts how much governance exists; the risk level answers what is wrong right now, so a single critical finding holds the level at high. Nothing here requires a model change — every open item is an owner, an approval control, or a mapping.

Governance readiness
90
Criteria met
9/10
Critical findings
3
Receipts verified
4/4

Fictional estate, generated by the assessment tooling rather than written by hand, and deliberately imperfect so the findings are visible. These are not measured ThePlus Tech customer outcomes.Pack hash 9ccf4d47d44f1e25d5b5c2b6a398cdd3dabf8f06135d91fba4105b72574b0ad6

02

Agent inventory

AgentHuman ownerAllowedBlockedRisk
Document Intake AgentHead of Client Operationsdocuments.read, documents.classifydocuments.deleteMedium
KYC Extraction AgentHead of Client Operationsdocuments.read, kyc.extract, registry.lookupkyc.approveHigh
Suitability Drafting AgentNone namedsuitability.draftNoneMedium
Adviser Notification AgentHead of Client Operationsnotify.internalemail.send, client.contactMedium
03

Authority map

AgentTool or data sourceAccessApprovalReason
Document Intake AgentClient Document StoreAllowedNoRead-only intake; cannot delete.
KYC Extraction AgentClient Document StoreAllowedNoExtraction requires the source pack.
KYC Extraction AgentCore Banking Read APIAllowedYesExisting-client cross-check is a four-eyes step.
KYC Extraction AgentCompanies House LookupAllowedNoPublic data; no client identifiers sent.
KYC Extraction AgentClient onboarding packsAllowedNoPrimary evidence for every extracted field.
Adviser Notification AgentInternal Notification ServiceAllowedNoInternal only; cannot reach a client.
Document Intake AgentCore Banking Read APIDeniedNoIntake has no business need for banking records.
04

Control gaps

Critical

At least one agent has no accountable human owner.

Assign a human owner to every agent.

Critical

Agent has no accountable owner (Suitability Drafting Agent).

Name the human accountable for this agent's behaviour.

Critical

High-risk tool requires approval control (Sanctions Screening Provider, confidential).

Require approval on this tool, or lower its data access level.

Medium

Authority boundary incomplete (Suitability Drafting Agent).

State what this agent may not do, not only what it may.

Medium

Governance rule lacks evidence mapping (Model version must be recorded).

Map this rule to a Control Plane pillar or a framework reference.

05

Evidence receipts

Every governed action leaves one, including the refused attempt. A record holding only successes cannot show a control working. The payloads never leave the tenant; only their digests appear here.

01

email.send · Denied

Adviser Notification Agent · approval not required43a77bd2fae0357bbafda86ff0a76435bc1cfe9012e9620ed699d7a79660eaf3

02

suitability.draft · Approval required

Suitability Drafting Agent · approval pending494e921da8f2b324aac24f560d7f8ef6da0cf80890d5307293872603bae21cc4

03

registry.lookup · Allowed

KYC Extraction Agent · approval not requiredb5b2be11789237900d2942e9e18876e1a93ab64230e89e71ef2f767c17c14381

04

kyc.extract · Approval required

KYC Extraction Agent · approval approved07026be614a5af463b7ee3591812a2181604ab6ff0c3c9e249ed9f6e63ca6b68

06

Framework mappings

Each control is bound to an external reference a reviewer can follow. These are pointers, not a compliance opinion, and nothing here certifies conformity. Unmapped pillar: revenue — an empty pillar is a finding, not a blank.

01

Named human owner per agent

Identity · ISO/IEC 42001 A.3
Each agent is owned by a named role accountable for its behaviour.

02

Authority boundaries per agent

Policy · OWASP LLM Top 10 LLM08
Excessive agency controlled by an explicit agent-to-tool authority map.

03

Human oversight of high-risk output

Policy · EU AI Act Art.14
Suitability summaries require adviser sign-off before filing.

04

Record-keeping of AI decisions

Audit · EU AI Act Art.12
Every governed action leaves a hashed evidence receipt.

05

Sensitive information disclosure

Evidence · OWASP LLM Top 10 LLM06
Receipts carry digests; client content never leaves the tenant boundary.

06

Risk measurement and tracking

Observability · NIST AI RMF MEASURE-2.5
Governance readiness scored and re-scored as the estate changes.

This is the shape of the evidence.Your assessment uses your agents, your tools, and your own control decisions.
Run this assessment on my AI estate © 2026 ThePlus Tech · Sample data · theo@theplus-tech.com