Who approved this AI tool, and on what basis?
For compliance, risk and procurement leads at mid-sized organisations.
The question you are asked
iSystematic works with compliance, risk and procurement leads who are asked who approved an AI tool, on what basis, and what changed in the rules this month. Each answer needs a record: a scored vendor questionnaire, a signed decision, and a dated version of every rule you watch.
Where most start
There are three levels. If one tool request is waiting, run the questionnaire yourself; if requests arrive every month, run it with us; if the whole programme is in question, start with readiness.
Run the AI Vendor Risk Framework (AVRF)™ yourself
Free: the deposited specification, in five stages: classify, diligence, contract, monitor, exit.
Run it with us
Vendor Intake and AI Diligence: we run the questionnaire with the requester, score the answers, and draft the gate decision and residual-risk line for a person to sign.
Govern the programme
AI Governance Readiness, for the whole AI programme, led by Nabeel Khan.
What we deliver
Three solutions and one readiness route, each leaving a record you can show.
Vendor Intake and AI Diligence
A scored questionnaire and a decision record for every AI tool request.
Policy and Regulation Watch
Checks named official sources, records versions, and reports real changes with links. It never reports no change when a source failed.
Knowledge Desk
Answers staff policy questions only from approved, versioned documents, cites the section, and refuses when the source is missing.
AI Governance Readiness
The readiness routes for the whole programme.
What you hold at the end: a fictional sample
This fictional extract is from a completed questionnaire for a fictional meeting-transcription vendor; the questions are paraphrased for illustration, and the real questionnaire is the deposited specification.
| Stage | Question, paraphrased | Vendor's answer | Evidence | Scored as |
|---|---|---|---|---|
| Classify | What data will the tool touch? | Meeting audio and transcripts | The requester's data map | Confidential data: full diligence required |
| Diligence | Is customer data used to train the vendor's models? | No | Contract clause supplied | Supported by evidence |
| Diligence | Where is data stored and processed? | In Canada | None supplied | Vendor's assertion only; sent back for evidence |
| Contract | Will the vendor give notice before changing the underlying model? | Not offered | Draft contract | Gap: a term to obtain before signing |
| Exit | Can all data be exported and deleted at exit? | Yes | Export tested by the requester | Supported by evidence |
Fictional draft gate decision: approve for one team once the model-change notice term is obtained. Residual risk: data location rests on the vendor's assertion until evidence arrives. Signed by the named risk owner.
What it is built on
Each solution names the frameworks it applies and the record you keep; the full stack is on How we build.
| Framework | In this work | You keep |
|---|---|---|
| AVRF | The five stages run with the requester; an answer without evidence is recorded as the vendor's assertion. | Completed questionnaire with evidence; vendor record |
| PEVG | The scoring step cannot assert a score the evidence does not support; unsupported answers go back. | Scored questionnaire with reasons |
| Five-Gate Deployment Model™ | Vendor clearance feeds G1; contract terms obtained feed G4. | Gate records |
| PARA, for the rule watch | Official sources are read only; there is no action faculty; adding or retiring a source needs the owner's authority. | Agent registry entry |
| The Boundary Invariant, for the rule watch | Never report no change when a source failed. | BOE Declaration; failed-source list per run |
| AI Incident Response Protocol (AIRP)™ | A material rule change becomes a trigger at G5 and can reopen validation of the systems it affects. | Version ledger per source; trigger register |
Buying from us
You contract with iSystematic Inc., in Canada. Build work is delivered by the studio's team of 10+ expert builders; enterprise readiness work is led by Nabeel Khan personally.
First steps, such as the Automation Assessment and a Pilot, are fixed fees, shared on a short call. A build is scoped after the pilot, and AgentOps is monthly.
Start
Start with the free specification, or bring us the request in front of you.
Where to go next
Operations leaders
For COOs: iSystematic's two-week Automation Assessment scores ten candidate tasks, recommends three solutions and sets a baseline before anything is built.
Engineering teams
For CTOs and AI leads: iSystematic builds agents on one governed line, each with declared contracts and five gate records, ready for second-line review.
Municipalities
Municipalities: iSystematic starts with a staff AI-use policy or an Automation Assessment, then prepares council packages and resident answers you approve.
Vendor Intake and AI Diligence
Vendor Intake and AI Diligence runs the AVRF questionnaire with each requester, scores the answers and drafts a gate decision for a named person to sign.
Policy and Regulation Watch
Policy and Regulation Watch checks the official sources you name, records each version and reports real changes, never “no change” when a source failed.
Readiness
Two readiness routes from iSystematic: AI Governance Readiness and E-23 Readiness, each a free check on nabeelkhan.com followed by one fixed-fee paid diagnosis.
Conformance is self-declared; no regulator endorses this work.