Skip to content
Atlas
GET IN TOUCH

D://LEAD46AI/ML Governance

Rules people
will follow.

AI governance sets out which tools are approved, what data may be used, who is accountable for output, and how that is monitored, written so it can actually be followed. It is for organisations that need a defensible position on AI for customers, insurers, or their board.

An AI policy nobody can follow is worse than none at all, because it moves the usage somewhere you cannot see it.

The cost of leaving this alone is rarely one visible failure. It is the slow accumulation: the workaround that became the process, the thing only one person knows, the renewal nobody questioned.

Our starting point is always the same: establish what is actually true today, then decide what to change. Work scoped against an assumption tends to solve a problem you do not have.

  • 01Nobody owns itIt sits with whoever touched it last, which is not the same as being managed.
  • 02No current pictureWhat you have, what it costs, and who has access are all slightly out of date.
  • 03Only handled when it breaksAttention arrives after the disruption rather than before it.

What the engagement covers

Scoped before it starts, so you know what is included and what is not.

  • 01

    Policy

    Short, specific, and readable. A twenty-page policy is a policy nobody has read, which makes it a liability rather than a control.

  • 02

    Approved tools

    A sanctioned list with a genuine route to add to it, because a closed list with no process guarantees shadow use within a month.

  • 03

    Accountability

    Who is responsible for AI-assisted output, a question that becomes urgent only after something has already gone wrong.

  • 04

    Monitoring

    How adherence is actually checked, so the policy functions as a control rather than as a document produced for an audit.

Discover, design, deliver, embed

Four stages with a written output at each one. You always know which stage you are in and what comes next.

  1. 01Weeks 1 – 2

    Discover

    We map how the work happens now, including the workarounds people are slightly embarrassed to mention.

  2. 02Weeks 3 – 4

    Design

    Options costed against benefit, so the choice is a decision rather than a preference.

  3. 03Per stage

    Deliver

    Built in slices that reach production and get used, each with a success measure agreed before it starts.

  4. 04Post-delivery

    Embed

    Training, documentation, and a check-in once the novelty has worn off. Adoption is the only measure that counts.

What you should expect

  • Someone other than you owns it, with that written down.
  • The current state is documented and stays documented.
  • Cost is planned ahead rather than discovered at renewal.
  • Decisions are made against evidence rather than assumption.

Questions we get asked

01What is AI/ML governance?

AI governance sets out which tools are approved, what data may be used, who is accountable for output, and how that is monitored, written so it can actually be followed. It is for organisations that need a defensible position on AI for customers, insurers, or their board.

02What should an AI policy actually cover?

Which tools are approved and for what. What categories of information may never go in, named specifically. That AI-assisted output is reviewed by a person before it is relied on or sent externally. Who is accountable when it turns out to be wrong. Whether clients need to be told AI was used, which some professional and contractual obligations require. And how someone requests a tool that is not on the list.

03Are there AI laws we need to comply with in New Zealand?

There is no dedicated AI statute here at present. That does not mean there are no obligations. The Privacy Act 2020 applies fully to personal information processed by AI tools, your professional and contractual duties do not change because a machine helped, and consumer law still applies to what you tell customers. Organisations selling into the European Union should also be watching the EU AI Act. We would treat existing law as the floor and governance as the thing that keeps you on the right side of it.

04Who is liable if AI produces something wrong and we act on it?

You are. This is the part that surprises people. The vendor’s terms will disclaim responsibility for output, and your customer, regulator, or professional body will hold your organisation to the same standard as if a person had produced it. That is precisely why a human review step before anything is relied on or sent is the one control worth being inflexible about.

05Do we need to tell clients we use AI?

Sometimes, and it is worth checking rather than assuming. Some professional obligations and an increasing number of client contracts require disclosure or prohibit certain uses outright. It is a question best answered before a client asks it, and for anything contentious take advice.

06How do we write a policy staff will actually follow?

Keep it to a page. Be specific about what is prohibited rather than gesturing at judgement. Explain why, because people follow rules they understand. Provide an approved tool that is genuinely good enough. And give them a fast route to ask about something new. A policy that fails any one of those becomes decoration.

07How much does AI/ML governance cost in New Zealand?

We quote after scoping rather than before. Anyone pricing this work without looking at your environment is guessing, and the guess is rarely in your favour. Scoping itself is quick, and we tell you what it costs before we start it.

08How long does it take to get started with AI/ML governance?

A first conversation takes about half an hour and costs nothing. Scoping is usually a week or two of our time depending on the size of the environment, and we agree the delivery dates with you before anything is booked in.

09Can you deliver AI/ML governance alongside our existing IT team or provider?

Yes, and it is common. We are happy to work as an extra pair of hands under your internal team, or alongside an incumbent provider on a defined piece of work. We will set out in writing where the responsibilities split, so nothing falls between us.

10Do we have to be an existing Atlas client to start a project?

No. This can be delivered as a standalone piece of work for an organisation we have never worked with before, or folded into a managed agreement if you already have one with us. Plenty of clients use us for one thing and keep everything else where it is.

11Do you deliver projects outside Auckland?

Our team is based in Auckland and we attend sites across the wider region. Most of this work is delivered remotely, so we support organisations throughout New Zealand, and we will say up front where being on site genuinely matters.

12Who from Atlas will be on the engagement?

Named people, not a queue. You get a lead who knows your environment and stays with it, which is the difference between explaining your business once and explaining it every time you make contact.

13What happens when the engagement ends?

You keep the documentation regardless, and anything registered in your name stays in your name. Whether we stay involved is your call. Some clients take it in house from there, others move it onto an ongoing agreement with us. We would rather you left cleanly than stayed because leaving was difficult.

Start with a conversation.

Tell us what you are dealing with and we will tell you whether this is the right service for it, and what it would take.

← All services