The problem

Your AI risk is known. Classifying it is the work.

Fourteen dimensions. Four pillars. One published key. Mycelium scores your AI governance against evidence you already hold, classifies every finding, and dates it so it stays true.
Live register · cycle 2026–0611 / 14
E-0142 · II Model security & integrity Partial
E-0138 · I Accountability, ownership & transparency Attested
E-0151 · III Change & release management Absent

Illustrative. Every claim carries a reference, a classification, a state and a date, on the website, in the board pack and in the platform, because it is the same record.

01 · How the work runs

Diagnose. Design. Embed. Sustain.

Four stages, in order. Most organisations enter at Diagnose and stop when the record is standing on its own.
01DiagnoseFind where the risk sits, against evidence you already hold.
02DesignPut accountability, appetite and lifecycle control in writing.
03EmbedGive your people literacy that names your tools and your escalation route.
04SustainKeep the record current, dated and defensible on a cadence.

See all services ↗

02 · The gate

Nothing material executes without a named human approving it.

The approval is not a safeguard bolted onto the architecture. The approval is the evidence, the artefact that lets a board attest and an auditor follow the trace.

The gate is the point. Every evidence cycle, every published pack and every agent Mycelium assesses resolves to a named human, a timestamp and a reference.

03 · Operating model

Four pillars. Fourteen dimensions. One key.

The same operating model sits behind every Health Check, every governance engagement and every board briefing. Colour tells you what a finding is. Ink tells you where it stands.
I · Govern
D01–D05
  • D01 · Strategy & alignment
  • D02 · Accountability, ownership & transparency
  • D03 · Risk appetite & tolerance
  • D04 · Model governance
  • D05 · Vendor & third-party governance
II · Protect
D06–D09
  • D06 · Data governance, quality & protection
  • D07 · Model security & integrity
  • D08 · Identity & access management
  • D09 · Supply chain & tooling security
III · Operate
D10–D12
  • D10 · Monitoring & observability
  • D11 · Incident response & recovery
  • D12 · Change & release management
IV · Enable
D13–D14
  • D13 · Capability & skills
  • D14 · Culture & awareness

* Data is classified into Protect, and is a dependency of all four pillars.

* Agentic AI is not a fifteenth dimension. A single agent typically touches seven of the fourteen at once.

CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF 1.0 · AICD · Guidance for AI Adoption · Privacy Act 1988 (Cth) · APP 1.7 · EU AI Act

Open Framework v2.0 ↗

04 · Independence

You attest. We evidence.

Mycelium reports what human-reviewed evidence demonstrates. It does not certify compliance and it does not issue assurance opinions, those stay with your management, your board and your assurance providers. Four constraints make that boundary real rather than stated. Three further tests turn on the engagement rather than the business model, so they are declared each time.
01 No platform licences

We hold no interest in any tool we might recommend. The finding is the product.

02 No systems integration

We do not assess work we would then be engaged to remediate.

03 No referral arrangements

No recommendation of ours creates a downstream interest for us, from anyone, at any point.

04 No assessment into a subscription we own

The rule runs both ways. An organisation we assess does not go onto the Evidence Platform for twelve months, and an organisation on the platform is not assessed by us until twelve months after it comes off.

Declared on every engagement

05Relationships

Any personal relationship between a Mycelium assessor and a person at the organisation is declared before scope is agreed.

06Perception

A conflict a reasonable third party could perceive is handled as a conflict, whether or not one exists.

07Our own prior work

Where a record includes work Mycelium designed or delivered, the entry says so.

Where Mycelium designs an AI governance operating model, it does not also assess that model independently within the same twelve months. The record is yours. Every register, assessment and evidence pack is delivered in a form you can keep current without Mycelium and without the platform.

05 · AI Governance Health Check

Where does your AI risk actually sit?

A four-week diagnostic across all fourteen dimensions. Scored against evidence you already hold, classified by pillar, and stated as a state rather than a colour, because a board needs to know whether a control is evidenced, not whether it is amber.

See the Health Check ↗

Executive Scorecard
Sample Executive Scorecard: fourteen dimensions, each with its classification pillar and evidence state.
Pillar barCl.DimensionState
I D01 · Strategy & alignment Partial
I D02 · Accountability, ownership & transparency Absent
I D03 · Risk appetite & tolerance Evidenced
I D04 · Model governance Partial
I D05 · Vendor & third-party governance Absent
II D06 · Data governance, quality & protection Evidenced
II D07 · Model security & integrity Partial
II D08 · Identity & access management Evidenced
II D09 · Supply chain & tooling security Partial
III D10 · Monitoring & observability Partial
III D11 · Incident response & recovery Absent
III D12 · Change & release management Partial
IV D13 · Capability & skills Evidenced
IV D14 · Culture & awareness Partial
Exceptions this cycle
D02Establish named board-level AI accountability
D05Issue vendor AI assurance attestation
D11Document kill-switch authority and test rollback
06 · Agentic AI

We govern the agents your organisation builds.

Mycelium does not build agents and does not sell agent platforms. Your engineers and your vendors do that. The question nobody owns is what happens once dozens are running: who authorised this one, what can it reach, what does it need a human for, and what proves any of that held.

See agentic AI governance ↗

01

Inventory

Most organisations cannot produce the list. That is the finding.

02

Authority

What each agent may decide, and who granted it.

03

Identity

What the agent authenticates as, and who is accountable for it.

04

The gate

Which actions need a named human, and whether the gate is enforced.

07 · Why now

The board’s exposure has changed.

  • 01

    APRA CPS 230 is operative.

    In force since 1 July 2026, remade by determination No. 1 of 2026, which revoked the 2023 determination under which the previous standard took effect on 1 July 2025. It does not name AI. AI is captured where it supports a critical operation, or where an AI vendor meets the material service provider test.

  • 02

    AS ISO/IEC 42001 is an Australian standard.

    Management-system requirements for organisations using AI, mapping across all four pillars. Voluntary, and increasingly assumed.

  • 03

    Automated decisions become disclosable.

    From 10 December 2026, APP entities must disclose in their privacy policy the kinds of personal information used, and the kinds of decisions made, by computer programs that significantly affect an individual. The trigger is a computer program, not “AI”.

CPS 230 · CPS 234 · AS ISO/IEC 42001 · ASD ISM · NIST AI RMF 1.0 · AICD · Guidance for AI Adoption · Privacy Act 1988 (Cth) · APP 1.7 · EU AI Act
We had the policy. We could not show the board it was operating.
From a live engagement · detail withheld under client confidentiality
An APRA-regulated organisation had no evidence for nine of fourteen dimensions at first diagnostic, not because controls were missing, but because nothing evidenced them on a cadence. The gap was between what was true and what could be shown.
08 · Start here

The first call is diagnostic.

Thirty minutes. No pitch. No proposal until it makes sense.