Skip to content
MAESTRO IRWIN

A/Are you AI audit ready?

Know every AI footprint in your company.

We find every model, copilot and agent your people already use, rate what each one puts at risk, then give you the guardrails, the guidance and the training to adopt AI properly. Four weeks. Evidence on every line.

Talk to an expertWhat you receive

Advisory for regulated organisations·Evidence-led·Independent

Schedule

AI systems register

W/P ref
B-1.2
Status
DRAFT
Illustrative extract from an AI systems register, showing six systems with their owning function, whether the organisation sanctioned them, the class of data they touch and their risk rating.
#SystemFunctionGovernanceData classRisk
001Microsoft 365 CopilotGroup ITSanctionedInternalLow
002Zoho CRM · ZiaSalesSanctionedCustomerMedium
003Chat assistant, personal planFinanceUnsanctionedCustomerHigh
004SAP SuccessFactors · hiringPeopleSanctionedSpecial categoryHigh
005Contract review assistantLegalUnsanctionedPrivilegedHigh
006Sage payroll · anomaly flagsFinance opsSanctionedEmployeeMedium
···11 further systems identified, including 3 in-house models — continued on B-1.3

Two exceptions raised. Customer and privileged data entered into tools with no processing agreement, no log retention and no named owner. Both rated high and carried to the remediation plan.

Illustrative extract·not a client file

APosition

Where most organisations actually are

Adoption already happened. Governance didn't.

AI arrived through expense cards, browser tabs and free tiers, not through a programme board. That is why the register is where every engagement starts: you cannot govern, defend or measure a system nobody has written down.

RefRateObservation
A-198%of organisations have staff using AI tools that were never approved.1
A-218%have a written AI policy that says what happens when they do.1
A-360%have already had data leave the business through a public AI tool.1
A-495%of generative AI pilots delivered no measurable impact on profit and loss.2
BServices

Four ways in

Start where the exposure is. Not where the slide deck is.

Each engagement stands on its own and produces something you keep. Most organisations begin with the register, because it decides what the other three should cost.

B-1/Track AI adoption

Runs 4 weeks

Find every system. Get the complete report.

A full sweep of what is running: sanctioned platforms, embedded vendor features, agents, browser extensions and the personal subscriptions nobody declared. Each system is traced to the data it touches, the person accountable for it and the exposure it creates.

Scope

  • Discovery across identity, network, expense and endpoint telemetry
  • Structured interviews with every function, to team level
  • Data-flow tracing for systems touching customer, regulated or privileged data
  • Third-party and embedded-feature review across your vendor estate
  • Risk rating against your own appetite, not a generic scale

You receive

  • AI systems register — system, owner, data class, rating, evidence reference
  • Shadow AI exposure summary, quantified by data class
  • Board-ready report with every finding rated, root-caused and owned
  • 90-day remediation plan sequenced by exposure, not by ease

B-2/Adopt AI with guidance

Runs 6 weeks

Put AI where it pays, and prove that it did.

Most AI spend lands in sales and marketing while the return sits in operations, finance and the back office. We score your use cases on value, feasibility and risk, make the build-or-buy call honestly, and set up benefits tracking that survives a challenge.

Scope

  • Use-case portfolio scored on value, feasibility and risk exposure
  • Build, buy or partner call for each case, with the reasoning written down
  • Sequencing against capacity, data readiness and control maturity
  • Baseline measurement before anything is switched on
  • Executive and board briefing on the resulting plan

You receive

  • Scored use-case portfolio with a recommended sequence
  • Business case per priority use case, with stated assumptions
  • Benefits tracking model tied to your existing financial reporting
  • Decision log your auditors and your board can both follow

B-3/Build AI guardrails

Runs 8 weeks

Controls that hold when the system acts on its own.

Policy is the easy half. We build the control library underneath it — human oversight that a person can actually exercise, logs that survive an investigation, release gates for agents, and evidence packs mapped to the frameworks your regulators and customers ask about.

Scope

  • AI policy and standards written for your operating model
  • Control library mapped to NIST AI RMF, ISO/IEC 42001 and the EU AI Act
  • Human oversight design — who intervenes, on what signal, with what authority
  • Logging, traceability and record retention to evidence standard
  • Evaluation, red-team and release gates for agentic systems
  • Model and vendor due-diligence pack, plus AI incident response

You receive

  • Approved AI policy and supporting standards
  • Control matrix with owners, test procedures and evidence requirements
  • Agent release gates, from assisted mode through to autonomous
  • Evidence pack ready for internal audit, customers and regulators

B-4/Discovery and training

Runs 2-day intensive, then ongoing

Make AI literacy real, and make it provable.

Everyone who uses AI on your behalf — staff, contractors, service providers — needs to understand what it does, where it fails and when to stop. We deliver that by role, at the depth the role warrants, and leave you with the records to show it happened.

Scope

  • Discovery workshops to surface how each function already works with AI
  • Role-based curriculum, proportionate to risk and technical background
  • Board and executive sessions on accountability and disclosure
  • Hands-on labs by function, using your own tools and your own data
  • Champion network and escalation routes inside each business unit

You receive

  • Curriculum and materials you keep and can run again
  • Delivered sessions, by role, across the organisation
  • Competency assessment results per participant
  • Literacy evidence file: attendance, content, assessment, dates
CMethod

How an engagement runs

We test what is running, not what the policy says should be.

The sequence is borrowed from assurance work, because it is the only one that produces a finding you can defend six months later in front of someone who did not like it.

  1. 1Week 0

    Scope and access

    We agree what is in scope, who owns what, which systems we may touch and who receives the report. Nothing starts until that is signed.

  2. 2Weeks 1–2

    Fieldwork

    Telemetry pulls, interviews, control walkthroughs and sampling. Every observation is tied to a source you can go and look at yourself.

  3. 3Week 3

    Findings and rating

    Exceptions are rated, root-caused and assigned an owner. You see the draft and challenge it before anyone else reads a word.

  4. 4Week 4

    Report and handover

    Board-ready report, evidence pack and a 90-day plan. We walk your executive team through it, then hand over the file so your team can run it.

DAfrica

Continental position

Africa is already using AI. Almost nobody is counting.

The story that the continent is not ready has outlived the facts. The law is in place, the strategies are published, and the tools are already on your staff's phones. What is missing is not readiness. It is a register.

44E-1

countries with data protection law in force7

Thirty-eight of them have a regulator standing behind it. The legal basis for governing AI is already on your statute books — it is not something the continent is waiting for.

2024E-2

African Union Continental AI Strategy adopted8

Endorsed in Accra in July 2024, with implementation running to 2030. The first phase, 2025 to 2026, is the one where national governance structures actually get built. That phase is now.

10+E-3

national AI strategies published8

Nigeria, Kenya, Rwanda, Egypt, Ghana, Senegal, Benin, Mauritius, Algeria and others. Kenya's landed in the first quarter of 2025. The direction of travel is set; most companies have simply not read it yet.

Art. 2E-4

the EU AI Act already reaches you3

It applies to providers and deployers established outside the EU wherever the output of the system is used inside it. Serve a European customer, score a European applicant, license a tool to a European buyer — you are in scope, and high-risk providers must appoint a representative there.

The question is not whether the continent is ready.

It is whether you can name the AI systems your business is running today, say who approved each one, and show what they touch. Every organisation we have worked with assumed the answer was short. It never is. That is a four-week answer, not a five-year one.

Find your position
EFile

What you receive

A file your board, your auditors and your regulator can all read.

Every engagement closes the same way: the deliverables, the evidence behind them, and a plan with owners and dates. No slideware that dissolves under a follow-up question.

E-1AI systems registerLive inventory, ratings, owners
E-2Findings reportRated, root-caused, board-ready
E-3Control matrixOwners, test steps, evidence
E-4Evidence packSource records, cross-referenced
E-5Remediation plan90 days, sequenced by exposure
E-6Literacy fileCurriculum, attendance, assessment
E-7Governance packs and software pilotsOptionalPolicy packs per framework, scoped tooling pilot

The standard we work to

Maestro Irwin was built by people who spent their careers auditing risk in regulated industries. That leaves one habit worth paying for: nothing goes in the report that we cannot evidence, and nothing is rated a certainty when it is a judgement. You will always be able to see how we got there.

FContact

Talk to an expert

Start with a conversation, not a proposal.

Tell us where you are. A consultant reads every enquiry and replies within one working day with a straight answer on whether we can help, what it would take and what it would cost.

  • A named consultant replies, not a sales queue
  • One working day, or we tell you why not
  • Nothing shared outside Maestro Irwin

Prefer email? advisory@maestroirwin.com

We use these details to reply to you and nothing else. No list, no sequence, no third party.