Who approved this AI tool, and on what basis?
For compliance, risk and procurement leads at mid-sized organisations.
The question you are asked
iSystematic works with compliance, risk and procurement leads who are asked who approved an AI tool, on what basis, and what changed in the rules this month. Each answer needs a record: a scored vendor questionnaire, a signed decision, and a dated version of every rule you watch.
Where most start
There are three levels. If one tool request is waiting, run the questionnaire yourself; if requests arrive every month, run it with us; if the whole programme is in question, start with readiness.
Run the AI Vendor Risk Framework (AVRF)™ yourself
Free: the deposited specification, in five stages: classify, diligence, contract, monitor, exit.
Read more →Run it with us
Vendor Intake and AI Diligence: we run the questionnaire with the requester, score the answers, and draft the gate decision and residual-risk line for a person to sign.
Read more →Govern the programme
AI Governance Readiness, for the whole AI programme, led by Nabeel Khan.
Read more →What we deliver
Three solutions and one readiness route, each leaving a record you can show.
Vendor Intake and AI Diligence
A scored questionnaire and a decision record for every AI tool request.
Read more →Policy and Regulation Watch
Checks named official sources, records versions, and reports real changes with links. It never reports no change when a source failed.
Read more →Knowledge Desk
Answers staff policy questions only from approved, versioned documents, cites the section, and refuses when the source is missing.
Read more →AI Governance Readiness
The readiness routes for the whole programme.
Read more →What you hold at the end: a fictional sample
This fictional extract is from a completed questionnaire for a fictional meeting-transcription vendor; the questions are paraphrased for illustration, and the real questionnaire is the deposited specification.
| Stage | Question, paraphrased | Vendor's answer | Evidence | Scored as |
|---|---|---|---|---|
| Classify | What data will the tool touch? | Meeting audio and transcripts | The requester's data map | Confidential data: full diligence required |
| Diligence | Is customer data used to train the vendor's models? | No | Contract clause supplied | Supported by evidence |
| Diligence | Where is data stored and processed? | In Canada | None supplied | Vendor's assertion only; sent back for evidence |
| Contract | Will the vendor give notice before changing the underlying model? | Not offered | Draft contract | Gap: a term to obtain before signing |
| Exit | Can all data be exported and deleted at exit? | Yes | Export tested by the requester | Supported by evidence |
Fictional draft gate decision: approve for one team once the model-change notice term is obtained. Residual risk: data location rests on the vendor's assertion until evidence arrives. Signed by the named risk owner.
What it is built on
Each solution names the frameworks it applies and the record you keep; the full stack is on How we build.
| Framework | In this work | You keep |
|---|---|---|
| AVRF | The five stages run with the requester; an answer without evidence is recorded as the vendor's assertion. | Completed questionnaire with evidence; vendor record |
| PEVG | The scoring step cannot assert a score the evidence does not support; unsupported answers go back. | Scored questionnaire with reasons |
| Five-Gate Deployment Model™ | Vendor clearance feeds G1; contract terms obtained feed G4. | Gate records |
| PARA, for the rule watch | Official sources are read only; there is no action faculty; adding or retiring a source needs the owner's authority. | Agent registry entry |
| The Boundary Invariant, for the rule watch | Never report no change when a source failed. | BOE Declaration; failed-source list per run |
| AI Incident Response Protocol (AIRP)™ | A material rule change becomes a trigger at G5 and can reopen validation of the systems it affects. | Version ledger per source; trigger register |
Buying from us
You contract with iSystematic Inc., in Canada. Build work is delivered by the studio's team of 10+ expert builders; enterprise readiness work is led by Nabeel Khan personally.
First steps, such as the Automation Assessment and a Pilot, are fixed fees, shared on a short call. A build is scoped after the pilot, and AgentOps is monthly.
Start
Start with the free specification, or bring us the request in front of you.
Where to go next
Operations leaders
For COOs: iSystematic's two-week Automation Assessment scores ten candidate tasks, recommends three solutions and sets a baseline before anything is built.
Read more →Engineering teams
For CTOs and AI leads: iSystematic builds agents on one governed line, each with declared contracts and five gate records, ready for second-line review.
Read more →Municipalities
Municipalities: iSystematic starts with a staff AI-use policy or an Automation Assessment, then prepares council packages and resident answers you approve.
Read more →Vendor Intake and AI Diligence
Vendor Intake and AI Diligence runs the AVRF questionnaire on each new AI tool and drafts a gate decision, with OSFI Guideline E-23 in view for FRFIs.
Read more →Policy and Regulation Watch
Policy and Regulation Watch checks the official sources you name, such as OSFI's guidance on Guideline E-23, records each version and reports real changes.
Read more →Readiness
Two readiness routes from iSystematic: E-23 Readiness for OSFI E-23 on 1 May 2027, and AI Governance Readiness, each a free check then a paid diagnosis.
Read more →Conformance is self-declared; no regulator endorses this work.