AI Governance & Implementation Audit
We audit what your AI systems
actually do.
Not what your policy says they do. Not what your vendor claims they do. We read the implementation — the code, the configuration, the data flows — and tell you where reality diverges from intent.
Ten years of technical consulting practice. Independent from all software and platform vendors.
10+
Years of practice
4
Core service tiers
0
Vendor relationships
100%
Written disclosure
What we do
Four service engagements. No platform, no lock-in.
Each engagement is scoped in writing before it starts. What was assessed and what wasn't is stated explicitly in the engagement letter.
AI Implementation & Behaviour Audit
We review what your AI systems actually do: what data they touch, what decisions they inform, and whether that matches what your documentation, your vendors, and your internal policy say. We look at code and configuration — not just interviews.
What you get
- Written findings report with evidence and risk classification
- Executive summary suitable for board or leadership
- Scoped engagement letter stating exactly what was and wasn't assessed
- No software to install, no ongoing system access required
AI Control & Exposure Assessment
We trace decision paths: where AI outputs go, who acts on them, and what the blast radius of a failure or manipulation looks like. Impact scoring is qualitative and explainable — not model-driven. Output is a risk-ranked map with specific, prioritised remediation steps, not a maturity score.
What you get
- Decision-path diagram per AI system in scope
- Impact matrix: financial, legal, and operational exposure
- Prioritised list of missing controls or human-approval gaps
- Recommendations for where kill-switches or escalation paths must exist
Employee AI Usage Governance
Most organisations don't know what AI tools their people are actually using. We build an accurate inventory — including shadow usage — provide a clear policy framework, and set up visibility without surveillance. We use progressive controls: observe first, then steer, then enforce.
What you get
- AI usage inventory at organisational level
- Policy framework with evidence of current usage
- DNS, identity, and network-level visibility design (no spyware)
- Monthly governance report against established baseline
AI Security & Data Sovereignty Review
We review your vendor DPAs, data flows, and architecture to identify where your data goes and whether it meets your GDPR, NIS2, or contractual obligations. No scanning, no traffic inspection — methodical reasoning from documentation and system architecture.
What you get
- End-to-end AI data-flow diagram per system in scope
- Data sovereignty matrix: jurisdiction, vendor access, leakage risk
- Enforceable data-boundary definitions (cloud vs. on-site criteria)
- Written gap analysis against applicable regulation
AI Orchestration Oversight Retainer
Continuous drift monitoring — vendor changes, regulatory updates, model changes — reviewed monthly against your original baseline.
How we work
Method, not software.
Our methodology produces a written, evidence-based assessment. There is nothing to install, no persistent access to your systems, and no vendor lock-in of any kind. The output is a document you own.
Typical engagement
Four weeks from kick-off to delivered report. Continuous monitoring runs on a fixed calendar cadence set at engagement close.
Discovery
Structured interviews with the teams actually using AI, plus a review of vendor contracts, data processing agreements, and existing tooling — official and shadow. We do not require system access at this stage.
Implementation mapping
We trace what AI systems actually do: what data they touch, what decisions they inform, and who acts on their output. Where the scope permits, we read the code and configuration directly — not just vendor documentation.
Risk & gap findings
A written, evidence-based report classifying each finding by likelihood and operational impact, with specific, prioritised recommendations. Every finding is cross-referenced against interview statements so you can see where stated policy and actual implementation diverge.
Continuous monitoring (optional)
A fixed-cadence check — monthly or quarterly — for material changes to implementation or behaviour since the last audit. Reported against the original baseline. No ongoing system access is required or held between checks.
Why independent matters
Independence is not a marketing position. It is the basis of the work.
No vendor relationships
We earn no commission, reseller margin, or referral fee from any software or platform vendor. Where your next step involves a governance tool or monitoring platform, we may point to one — but we are never selling it.
No ongoing system access
We hold no persistent access to your systems between engagements. Access granted for an audit is explicitly revoked at engagement close. This is stated in the engagement letter.
Written disclosure on every engagement
The engagement letter states exactly what was and wasn't assessed, what access was granted, and how independence is maintained. Not as a formality — as the basis of the work.
Ten years of practice
TwoAeon has operated as a technical consulting practice since 2014. Our work in AI governance is an extension of that practice — applied to a domain that now warrants dedicated rigour.
“We audit how AI is actually implemented — not how policy says it should be — and, where useful, continue checking on a fixed schedule for when that implementation or its behaviour changes.”
Get in touch
Schedule a conversation.
We start every engagement with a scoping call — no charge, no commitment. You describe the AI systems you want assessed, we explain what we would look at and what we would not, and we agree on scope in writing before any work begins.