CONSULTING · TRACK A · AI GOVERNANCE & ASSURANCE
Governance built to pass a board, and to pass an audit
A staged engagement that takes an organisation's AI governance posture from wherever it stands today to a state a board can sign and a regulator can inspect: a gap diagnostic against ISO/IEC 42001, remediation support, and an optional retainer to keep it current.
Engagement structure
Gap diagnostic, remediation support, retainer
Standard
ISO/IEC 42001, AI Management Systems
Delivery
Singapore-based, regional delivery on request
Requires
No prior AI governance programme in place
Led by
Terence Kok, RMC, ISO/IEC 42001 Lead Auditor, AIGP
Also drawn on for
The AI Governance & ROI Executive Programme
Overview
Most organisations are already running AI without the governance to answer for it
Sixty-four percent of organisations already have AI in production, and sixty-three percent experienced a compliance consequence tied to a gap in their AI governance in the past twelve months, according to Kiteworks' 2026 Annual Survey Report of 459 security, compliance and technology professionals across North America, Europe and the Middle East. The gap is not usually a knowledge problem. It is a sequencing problem: governance work tends to start after deployment, once an auditor, a regulator or an enterprise customer's own procurement team has already asked a question nobody prepared an answer for.
This track exists to close that gap before the question is asked, not after. The same survey found the average respondent's combined data-security and AI-governance maturity score sat at 16.2 out of 100, a composite the report calls the Data Security and Compliance Readiness Index. A number that low is not evidence of neglect so much as evidence that governance work has genuinely not started yet at most organisations already running AI in production, which is exactly the starting position the gap diagnostic below is built to assess.
Most AI governance work stalls at the same point the practice has written about before: a policy document that reads well and a set of controls nobody has actually rehearsed. A board asking whether its AI governance would survive a regulator's enquiry, or an enterprise customer's own due diligence, deserves a more specific answer than a slide asserting compliance.
This track builds that answer directly, working from ISO/IEC 42001's own control structure rather than a bespoke framework invented for this engagement, so what gets built is recognisable to an external auditor and portable beyond any one client relationship.
Why this track
I sit on IMDA's GenAI Sandbox evaluation panel, which means part of my working year is spent reading other people's governance submissions with an auditor's scepticism rather than a vendor's confidence. That seat, alongside the ISO/IEC 42001 Lead Auditor credential I hold through BSI, is where this track actually comes from. The governance framework I built for Meinhardt's own agentic AI deployment, covering a system's full lifecycle from discovery through to retirement and mapped against both IMDA's Model AI Governance Framework and the NIST AI RMF, is the same structure this track builds for a client rather than for a former employer.
A workshop can hand a board a checklist in an afternoon. It cannot hand them the procedures, the escalation records and the audit trail an external reviewer actually opens the file to check, which is why this track runs as three separate, separately priced stages rather than one open engagement. I have watched a policy document survive a board meeting and fail an audit inside the same organisation, and the diagnostic stage exists specifically to catch that gap before a regulator, or an enterprise customer's own procurement team, finds it first.
Capabilities
What gets drawn on, not necessarily in this order
The three stages below are the sequence. These are the specific pieces of work inside it.
-
Delegation & escalation design
Where human sign-off sits before an AI system acts, and the escalation path for the moment it's wrong.
-
Agentic AI risk assessment
Risk scoring built for systems that act with growing autonomy, not only systems that answer a question.
-
Vendor & contract governance
Contract terms that make a third-party model's failure the vendor's problem too, not only the client's.
-
Board & regulator reporting
A governance record structured for how a board reads it and how a regulator inspects it, not one document trying to do both.
-
Cross-framework mapping
One control set mapped to ISO/IEC 42001, IMDA's Model AI Governance Framework and the NIST AI RMF at once, so evidence built once satisfies more than one audience.
-
Management system documentation
The actual artefacts an ISO/IEC 42001 audit inspects: policies, procedures and records, not a slide asserting they exist.
Engagement structure
Three stages, not one open-ended retainer
Each stage is scoped and priced on its own. An organisation can stop after any one of them.
- 01
Gap diagnostic
An assessment of the organisation's current AI governance posture against ISO/IEC 42001's control set: what already exists, what is documented but not practised, and what does not exist yet. The same discipline behind the Eight-Dimension AI Readiness Assessment, applied to governance specifically rather than to readiness overall.
- 02
Remediation support
Closing the gaps the diagnostic finds: oversight structures, escalation paths, audit trails and the accountability record a board or regulator will actually ask to see, not a policy document written once and left unread.
- 03
Ongoing retainer
Governance is not a state an organisation reaches once. A retainer keeps the management system current as AI use expands, as agentic systems take on more autonomous decisions, and as the regulatory position itself continues to move.
Track record
Governance work already delivered, not proposed
-
Meinhardt AI Centre of Excellence
Established and led Meinhardt's global AI Centre of Excellence, a production-oriented capability spanning AI governance, MLOps/LLMOps pipelines and federated delivery across enterprise and OT systems, targeting a 20 to 30 percent reduction in rework and validated ROI on most AI use cases within three years.
-
Global AI governance framework, Meinhardt Group
Designed the enterprise governance framework for autonomous agentic AI deployment across AEC operations, a lifecycle model covering discovery, operation and retirement, aligned with the IMDA Model AI Governance Framework and NIST AI RMF.
-
Framework and toolkit development, Public Investment Fund (KSA)
Delivered a four-phase technical capability diagnostic across six infrastructure domains, producing benchmarking scorecards and a real-time executive dashboard that enabled data-driven prioritisation of more than US$60 billion in improvement investment.
A 20 to 30 percent reduction in rework, with validated ROI on most AI use cases within three years.
Meinhardt AI Centre of ExcellenceWho this is for
Two different reasons to need the same governance posture
- Boards and executive leadership who need an AI governance posture they can sign off on, not one a vendor asserts on their behalf.
- Risk, compliance and internal audit functions preparing for an external audit, a regulator's enquiry, or a customer's own due diligence.
- Funded AI startups whose next enterprise deal or funding round depends on an enterprise buyer's procurement team trusting their governance posture, not just their product demo.
Led by
Terence Kok
Registered Management Consultant (RMC), Institute of Management Consultants Singapore · Certified AI Governance Professional (AIGP), Singapore Management University · ISO/IEC 42001 Lead Auditor, AI Management Systems, BSI · ISO 14064 Lead Auditor, Greenhouse Gas Verification, SGS Academy
Enterprise AI strategist and former Chief AI and Innovation Officer at Meinhardt Group, with twenty-five years leading transformation programmes across Asia and the Middle East, specialising in impact assessment, governance and deployment methodology.
Read the full profile ›From the practice
Recent writing on AI governance
Published research and frameworks this track's diagnostics are built on, not marketing copy written after the fact.
-
Your vendor can't explain the model either. That's the part people miss.
There's a version of the AI procurement conversation where documentation closes the transparency question. It doesn't, because most of what makes a modern model opaque was never the vendor's to hand over.
Terence Kok, Executive Director, AI Governance & Assurance Practice. Enterprise AI Strategist and Keynote Speaker
-
Parenting a superintelligent child: what values are we actually passing down?
Elon Musk called SpaceX and xAI staff the 'parents' of Grok. Two AI governance failures from the past eighteen months map almost exactly onto sixty years of parenting research, and only one of the four quadrants produces a system that keeps its values once nobody is watching.
Terence Kok, Executive Director, AI Governance & Assurance Practice. Enterprise AI Strategist and Keynote Speaker
-
Foundations of dependable agentic AI
Why engineering reliability into agentic systems depends on bounded task specifications and trajectory-level observability in production, not on how capable the underlying model is.
Terence Kok, Executive Director, AI Governance & Assurance Practice. Enterprise AI Strategist and Keynote Speaker
Common questions
Before you enquire
-
Is this the same as the AI Governance & ROI Executive Programme?
No. The Executive Programme is a four-hour diagnostic session that produces a governance checklist and a scored baseline for one organisation, in the room, in an afternoon. This track picks up from there, or starts fresh: a staged engagement that builds the governance system itself, over weeks rather than hours.
-
Do we need to have completed the Executive Programme first?
No. Many engagements start from the Executive Programme's governance checklist, since it already scopes the gaps. Others start directly from a scoping conversation, particularly where an audit or a procurement deadline is already set.
-
What does this cost?
Scoped at engagement, once the diagnostic has established how much remediation is actually required. We have not published a rate card for this track yet; ask directly and we will give you a straight answer on structure and range before any commitment is made.
-
We are a startup, not an enterprise. Does this apply to us?
If the reason you need this is that an enterprise customer's procurement or security team is asking questions about your AI governance before they will sign, yes, directly. This track is not a build engagement. It does not cover product development, and a startup looking for that is better served by the Engineering & Delivery track or by a different kind of partner entirely.
-
Who actually leads the engagement?
Terence Kok, personally, drawing on the same ISO/IEC 42001 Lead Auditor and Certified AI Governance Professional credentials stated on his speaker profile, and on governance frameworks he has built for enterprise agentic AI deployment.
Investment
Scoped at engagement
Each of the three stages above is priced on its own once the gap diagnostic has established how much remediation is actually required. We have not published a rate card for this track. Ask directly and we will give you a straight answer on structure and range before any commitment is made.