Make AI risk visible, owned and auditable.
Open the framework ↗AI security, governance and agents for Australian boards. Diagnostic-led. Built to defend.
Make AI risk visible, owned and auditable.
Open the framework ↗Find the gaps before the auditor does.
Open the Health Check ↗Ship governed AI agents with approval gates and audit trails.
Open the agent practice ↗The same four pillars used in every Mycelium Health Check, Agent Build and Board Briefing.
A 4-week diagnostic across 14 dimensions and 4 pillars. RAG-scored, evidence-graded, designed for board, audit and regulator conversations.
| Dimension | Govern | Protect | Operate | Enable |
|---|---|---|---|---|
| D01 Strategy & alignment | A | |||
| D02 Accountability & ownership | R | |||
| D03 Risk appetite & tolerance | G | |||
| D04 Model governance | A | |||
| D05 Vendor & third-party governance | R | |||
| D06 Data governance & protection | G | |||
| D07 Model security & integrity | A | |||
| D08 Identity & access management | G | |||
| D09 Supply chain & tooling security | A | |||
| D10 Monitoring & observability | A | |||
| D11 Incident response & recovery | R | |||
| D12 Change & release management | A | |||
| D13 Capability & skills | G | |||
| D14 Culture & awareness | A |
Governed AI agents for regulated work — validated input, human approval, audit-grade evidence, by default.
Every request schema-checked and scoped before the agent moves.
High-risk actions require explicit human approval before execution.
Every decision logged with timestamp, owner and evidence reference.
APRA CPS 230 is in force.
AS ISO/IEC 42001 is now an Australian standard.
AI governance is moving from discussion to evidence.
Thirty minutes. No pitch. No proposal until it makes sense.
Book a diagnostic