The Method · Area 4 of 7
Your controls
What "AI-ready" looks like in this area
- Every control your auditors care about can be expressed in something a system can evaluate — not just a policy document.
- AI actions are evaluated against the same control set as human actions.
- When a control changes, the system enforces the new version on the date it takes effect — without waiting for someone to remember to update a workflow.
What we typically find on Day 1
- Policy documents that describe the control in prose but no system that enforces it.
- Controls enforced inconsistently — one team is strict, another is not, both following the same document.
- Controls that exist for AI actions only in the form of "don't let it do that" — no positive specification.
What changes during a Business Transformation
- Controls get expressed as rules a system can evaluate: pre-conditions, post-conditions, exception paths.
- The validation tooling evaluates every AI action against the control set, and ships with the foundation for your future AI work to run against.
- Audit becomes a query against the logs, not a manual sample-and-spot-check.
What stays the same
- Your policies do not change because we showed up. The expression of the policy in machinery is what changes.
- Compliance and risk decisions stay with the people responsible for them.
- We do not introduce new controls that are not already required somewhere; we surface the gap if a required control is not enforced anywhere.
How this area connects to the rest
This is one of the seven areas an Enterprise Readiness review examines. The reference architecture that shows how all seven fit together is the agentic stack. The discipline that makes every engagement run the same loop is the repeatable process.
Want to talk about this area in your business?
The intro call is a 30-minute conversation. If "your controls" is where you suspect the work is stuck, this is the place to start.
