01 · Governance architecture

Make AI
governable.

AI security, governance and agents for Australian boards. Diagnostic-led. Built to defend.

1 item1 itemapproved{}Inputvalidated01 · INPUTToolmodel · api02 · AIHUMAN REQGatehuman required03 · GATEAuditevidence04 · LOGSYSTEMAGENTHUMANSYSTEM
MAPPED TO CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF
MOD-01 v1.0
02 · What we do

Govern. Secure. Build.

03 · Operating model

Four pillars. One operating system for AI.

The same four pillars used in every Mycelium Health Check, Agent Build and Board Briefing.

DIM 01–05
Govern
  • Strategy & alignment
  • Accountability & ownership
  • Risk appetite & tolerance
  • Model governance
  • Vendor & third-party governance
DIM 06–09
Protect
  • Data governance & protection
  • Model security & integrity
  • Identity & access management
  • Supply chain & tooling security
DIM 10–12
Operate
  • Monitoring & observability
  • Incident response & recovery
  • Change & release management
DIM 13–14
Enable
  • Capability & skills
  • Culture & awareness
CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF · AICD · Privacy Act 1988 (ADM 2026)
04 · Govern practice · 4-week diagnostic

Where does your AI risk actually sit?

A 4-week diagnostic across 14 dimensions and 4 pillars. RAG-scored, evidence-graded, designed for board, audit and regulator conversations.

See the Health Check ↗

AI Security Posture Scorecard
14 DIMENSIONS · 4 PILLARS · RAG SCORED
DimensionGovernProtectOperateEnable
D01 Strategy & alignmentA
D02 Accountability & ownershipR
D03 Risk appetite & toleranceG
D04 Model governanceA
D05 Vendor & third-party governanceR
D06 Data governance & protectionG
D07 Model security & integrityA
D08 Identity & access managementG
D09 Supply chain & tooling securityA
D10 Monitoring & observabilityA
D11 Incident response & recoveryR
D12 Change & release managementA
D13 Capability & skillsG
D14 Culture & awarenessA
Priority items
RD02 · Establish named board-level AI accountability
RD05 · Issue vendor AI assurance attestation
RD11 · Document kill-switch authority and test rollback
SAMPLE PREVIEW · ANONYMISED · v1.2
05 · Build practice

Agents built with approval gates, audit trails and human control.

Governed AI agents for regulated work — validated input, human approval, audit-grade evidence, by default.

1 item1 itemapprovedexecuted{}Inputvalidated01 · INPUTTool callsmodel · retrieval · api02 · AIHUMAN REQApproval gatehuman required03 · GATEActionexecuted04 · ACTIONAudit logevidence05 · LOGSYSTEMAGENTHUMANAGENTSYSTEM
AGENT-ARCH v1.0 · WORKFLOW VIEW
audit_log> 2026-06-07T14:22Z · agent=legal-intake · action=draft_brief · approver=K.Park · evidence=#A4621
Validated input

Every request schema-checked and scoped before the agent moves.

Human gate

High-risk actions require explicit human approval before execution.

Audit trail

Every decision logged with timestamp, owner and evidence reference.

AGENTS LIVE · Banking & Finance Ops · Project Management · Legal Intake · Supplier Assurance · Energy Operations

See the agent practice ↗

06 · Why now

The board’s exposure has changed.

01

APRA CPS 230 is in force.

02

AS ISO/IEC 42001 is now an Australian standard.

03

AI governance is moving from discussion to evidence.

CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF · AICD · Privacy Act 1988 (ADM 2026)
07 · Start here

The first call is diagnostic.

Thirty minutes. No pitch. No proposal until it makes sense.

Book a diagnostic
30-MINUTE DIAGNOSTIC CALL · VIDEO OR MELBOURNE · BOOK DIRECTLY
Or download the Boardroom Diagnostic (PDF, 2 pages) ↗