CONSULTING · TRACK A · AI GOVERNANCE & ASSURANCE

Governance built to pass a board, and to pass an audit

A staged engagement that takes an organisation's AI governance posture from wherever it stands today to a state a board can sign and a regulator can inspect: a gap diagnostic against ISO/IEC 42001, remediation support, and an optional retainer to keep it current.

Engagement structure

Gap diagnostic, remediation support, retainer

Standard

ISO/IEC 42001, AI Management Systems

Delivery

Singapore-based, regional delivery on request

Requires

No prior AI governance programme in place

Led by

Terence Kok, RMC, ISO/IEC 42001 Lead Auditor, AIGP

Also drawn on for

The AI Governance & ROI Executive Programme

Overview

Most organisations are already running AI without the governance to answer for it

Sixty-four percent of organisations already have AI in production, and sixty-three percent experienced a compliance consequence tied to a gap in their AI governance in the past twelve months, according to Kiteworks' 2026 Annual Survey Report of 459 security, compliance and technology professionals across North America, Europe and the Middle East. The gap is not usually a knowledge problem. It is a sequencing problem: governance work tends to start after deployment, once an auditor, a regulator or an enterprise customer's own procurement team has already asked a question nobody prepared an answer for.

This track exists to close that gap before the question is asked, not after. The same survey found the average respondent's combined data-security and AI-governance maturity score sat at 16.2 out of 100, a composite the report calls the Data Security and Compliance Readiness Index. A number that low is not evidence of neglect so much as evidence that governance work has genuinely not started yet at most organisations already running AI in production, which is exactly the starting position the gap diagnostic below is built to assess.

Most AI governance work stalls at the same point the practice has written about before: a policy document that reads well and a set of controls nobody has actually rehearsed. A board asking whether its AI governance would survive a regulator's enquiry, or an enterprise customer's own due diligence, deserves a more specific answer than a slide asserting compliance.

This track builds that answer directly, working from ISO/IEC 42001's own control structure rather than a bespoke framework invented for this engagement, so what gets built is recognisable to an external auditor and portable beyond any one client relationship.

Terence Kok
Terence Kok Executive Director, AI Governance & Assurance Practice

Why this track

I sit on IMDA's GenAI Sandbox evaluation panel, which means part of my working year is spent reading other people's governance submissions with an auditor's scepticism rather than a vendor's confidence. That seat, alongside the ISO/IEC 42001 Lead Auditor credential I hold through BSI, is where this track actually comes from. The governance framework I built for Meinhardt's own agentic AI deployment, covering a system's full lifecycle from discovery through to retirement and mapped against both IMDA's Model AI Governance Framework and the NIST AI RMF, is the same structure this track builds for a client rather than for a former employer.

A workshop can hand a board a checklist in an afternoon. It cannot hand them the procedures, the escalation records and the audit trail an external reviewer actually opens the file to check, which is why this track runs as three separate, separately priced stages rather than one open engagement. I have watched a policy document survive a board meeting and fail an audit inside the same organisation, and the diagnostic stage exists specifically to catch that gap before a regulator, or an enterprise customer's own procurement team, finds it first.

Terence Kok's signature

Capabilities

What gets drawn on, not necessarily in this order

The three stages below are the sequence. These are the specific pieces of work inside it.

  • Delegation & escalation design

    Where human sign-off sits before an AI system acts, and the escalation path for the moment it's wrong.

  • Agentic AI risk assessment

    Risk scoring built for systems that act with growing autonomy, not only systems that answer a question.

  • Vendor & contract governance

    Contract terms that make a third-party model's failure the vendor's problem too, not only the client's.

  • Board & regulator reporting

    A governance record structured for how a board reads it and how a regulator inspects it, not one document trying to do both.

  • Cross-framework mapping

    One control set mapped to ISO/IEC 42001, IMDA's Model AI Governance Framework and the NIST AI RMF at once, so evidence built once satisfies more than one audience.

  • Management system documentation

    The actual artefacts an ISO/IEC 42001 audit inspects: policies, procedures and records, not a slide asserting they exist.

Engagement structure

Three stages, not one open-ended retainer

Each stage is scoped and priced on its own. An organisation can stop after any one of them.

  1. 01

    Gap diagnostic

    An assessment of the organisation's current AI governance posture against ISO/IEC 42001's control set: what already exists, what is documented but not practised, and what does not exist yet. The same discipline behind the Eight-Dimension AI Readiness Assessment, applied to governance specifically rather than to readiness overall.

  2. 02

    Remediation support

    Closing the gaps the diagnostic finds: oversight structures, escalation paths, audit trails and the accountability record a board or regulator will actually ask to see, not a policy document written once and left unread.

  3. 03

    Ongoing retainer

    Governance is not a state an organisation reaches once. A retainer keeps the management system current as AI use expands, as agentic systems take on more autonomous decisions, and as the regulatory position itself continues to move.

Track record

Governance work already delivered, not proposed

  • Meinhardt AI Centre of Excellence

    Established and led Meinhardt's global AI Centre of Excellence, a production-oriented capability spanning AI governance, MLOps/LLMOps pipelines and federated delivery across enterprise and OT systems, targeting a 20 to 30 percent reduction in rework and validated ROI on most AI use cases within three years.

  • Global AI governance framework, Meinhardt Group

    Designed the enterprise governance framework for autonomous agentic AI deployment across AEC operations, a lifecycle model covering discovery, operation and retirement, aligned with the IMDA Model AI Governance Framework and NIST AI RMF.

  • Framework and toolkit development, Public Investment Fund (KSA)

    Delivered a four-phase technical capability diagnostic across six infrastructure domains, producing benchmarking scorecards and a real-time executive dashboard that enabled data-driven prioritisation of more than US$60 billion in improvement investment.

See the full engagement record on Terence Kok's profile ›

A 20 to 30 percent reduction in rework, with validated ROI on most AI use cases within three years.

Meinhardt AI Centre of Excellence

Who this is for

Two different reasons to need the same governance posture

  • Boards and executive leadership who need an AI governance posture they can sign off on, not one a vendor asserts on their behalf.
  • Risk, compliance and internal audit functions preparing for an external audit, a regulator's enquiry, or a customer's own due diligence.
  • Funded AI startups whose next enterprise deal or funding round depends on an enterprise buyer's procurement team trusting their governance posture, not just their product demo.
Terence Kok

Led by

Terence Kok

Registered Management Consultant (RMC), Institute of Management Consultants Singapore · Certified AI Governance Professional (AIGP), Singapore Management University · ISO/IEC 42001 Lead Auditor, AI Management Systems, BSI · ISO 14064 Lead Auditor, Greenhouse Gas Verification, SGS Academy

Enterprise AI strategist and former Chief AI and Innovation Officer at Meinhardt Group, with twenty-five years leading transformation programmes across Asia and the Middle East, specialising in impact assessment, governance and deployment methodology.

Read the full profile ›

Common questions

Before you enquire

  • Is this the same as the AI Governance & ROI Executive Programme?

    No. The Executive Programme is a four-hour diagnostic session that produces a governance checklist and a scored baseline for one organisation, in the room, in an afternoon. This track picks up from there, or starts fresh: a staged engagement that builds the governance system itself, over weeks rather than hours.

  • Do we need to have completed the Executive Programme first?

    No. Many engagements start from the Executive Programme's governance checklist, since it already scopes the gaps. Others start directly from a scoping conversation, particularly where an audit or a procurement deadline is already set.

  • What does this cost?

    Scoped at engagement, once the diagnostic has established how much remediation is actually required. We have not published a rate card for this track yet; ask directly and we will give you a straight answer on structure and range before any commitment is made.

  • We are a startup, not an enterprise. Does this apply to us?

    If the reason you need this is that an enterprise customer's procurement or security team is asking questions about your AI governance before they will sign, yes, directly. This track is not a build engagement. It does not cover product development, and a startup looking for that is better served by the Engineering & Delivery track or by a different kind of partner entirely.

  • Who actually leads the engagement?

    Terence Kok, personally, drawing on the same ISO/IEC 42001 Lead Auditor and Certified AI Governance Professional credentials stated on his speaker profile, and on governance frameworks he has built for enterprise agentic AI deployment.

Investment

Scoped at engagement

Each of the three stages above is priced on its own once the gap diagnostic has established how much remediation is actually required. We have not published a rate card for this track. Ask directly and we will give you a straight answer on structure and range before any commitment is made.

Enquire about this track
Dr. Jayarethanam Pillai

Before you go

I ran accreditation processes for the better part of a decade, and the lesson that never stopped being true is that an institution can pass a review on paper while the practice underneath it lags years behind. ISO/IEC 42001 is a newer instrument aimed at the same gap, and Terence holds the Lead Auditor credential most consultants only cite secondhand. What I would ask a board considering this track to sit with is the staged structure below: a diagnostic before a remediation plan, evidence built before it is asserted. Skipping straight to a claim of compliance is exactly the failure I watched accreditation reviews punish.

Signature, Jayarethanam Pillai