Monforte

Monforte / Monforte General Services Division

Monforte General Services Division

AI Governance, Assurance & Organizational Competence

Two practitioners compare an operational procedure with a checklist.
Comparing procedure with practice.

Monforte helps organizations understand, govern, and evaluate their use of artificial intelligence. Our services connect organizational accountability, practical controls, workforce competence, and evidence-based assurance. We support organizations beginning their AI journey, strengthening existing governance, preparing for ISO/IEC 42001 certification, or seeking an objective assessment of how their AI arrangements perform in practice.

Our work addresses not only the technology, but also the people, decisions, processes, suppliers, and institutional responsibilities surrounding its use.

Core offering

Six flagship services

Flagship service 01

AI Governance Gap Assessment

Understand where your AI governance stands, what is missing, and what to address first.

Scope and deliverables

A structured assessment of the organization’s existing AI governance arrangements, including leadership accountability, policies, AI inventory, risk and impact assessment, supplier oversight, workforce competence, operational controls, monitoring, and reporting.

The engagement compares existing arrangements and available evidence against an agreed baseline. That baseline may include ISO/IEC 42001, selected NIST AI Risk Management Framework outcomes, organizational policies, or relevant contractual requirements. ISO/IEC 42001 provides a management-system framework; the NIST framework is voluntary risk-management guidance rather than a certification standard.

Typical deliverables: Executive findings report, requirements-to-evidence gap register, prioritized improvement roadmap, and recommended ownership of corrective actions.

Service options: An initial governance diagnostic or a more detailed evidence-based assessment. Maturity observations are distinguished from findings against specific requirements.

Discuss this engagement ↗

Flagship service 02

ISO/IEC 42001 Internal Auditing — Clause 9.2

Evaluate whether your AI management system conforms to requirements and operates effectively.

Scope and deliverables

Outsourced internal auditing of the organization’s AI management system, conducted on its behalf. ISO/IEC 42001 places internal auditing and the internal audit programme under clause 9.2.

The audit examines the management system against ISO/IEC 42001 and the organization’s own requirements, using document review, interviews, evidence sampling, and examination of actual practices. The scope can include governance processes, AI risk and impact assessments, applicable controls, competence arrangements, supplier management, and operational oversight.

Typical deliverables: Audit programme support, audit plan, evidence-based findings, nonconformity reports, management briefing, and agreed follow-up verification.

Service boundary: This is internal auditing of the AI management system—not merely an audit of the internal audit procedure, and not a certification audit.

Discuss this engagement ↗

Flagship service 03

Independent AI Governance and Control Assurance

Obtain an objective assessment of whether defined AI governance claims and controls are supported by evidence.

Scope and deliverables

A scoped assurance engagement examining a particular AI application, business process, governance arrangement, or set of controls. The assessment considers whether controls are suitably designed, implemented, and operating against agreed criteria.

Possible subjects include human oversight, approval authority, use restrictions, output verification, supplier controls, incident escalation, and the evidence supporting management’s representations about responsible AI use.

Typical deliverables: An assurance report identifying the subject matter, criteria, period covered, evidence examined, findings, conclusions, and limitations.

Service boundary: We accept independent assurance engagements only where independence can be established. It is not a blanket declaration that an AI system is “safe,” “ethical,” or legally compliant.

Discuss this engagement ↗

Flagship service 04

Industry-Specific AI Governance Workshops

Turn general AI principles into decisions, responsibilities, and controls relevant to your industry.

Scope and deliverables

Facilitated workshops built around the organization’s actual activities, AI applications, affected stakeholders, and operating environment. These are working sessions—not simply presentations on AI terminology.

Participants examine realistic situations, identify governance gaps, clarify accountability, and develop practical actions.

Workshop settings and exercises include:

Healthcare and healthcare administration
Clinical decision support, patient communications, documentation, scheduling, revenue-cycle activities, purchasing, and administrative decision-making.
Manufacturing, aerospace, and industrial operations
Automated inspection, predictive maintenance, production planning, engineering support, supplier evaluation, and technical-record preparation.
Financial services and insurance
Customer communications, credit and eligibility decisions, fraud detection, claims handling, and oversight of AI-supported recommendations.
Education and training
Assessment integrity, tutoring, admissions support, research assistance, student information, instructional design, and administrative use.
Government and public services
Public-facing information, eligibility decisions, case handling, procurement, transparency, accountability, and meaningful human review.
Professional services and government contractors
Translation, document analysis, advisory work, research, confidentiality, evidence integrity, and client or contract restrictions.
Food, retail, and hospitality
Demand forecasting, supplier oversight, quality and traceability records, customer communications, and AI-supported operational decisions.

Typical deliverables: Workshop findings, an initial use-case and risk map, agreed governance priorities, responsibility assignments, and a practical action plan.

Audience options: Executive leadership; application owners and operational managers; assurance and control functions; or cross-functional teams.

These bespoke organizational workshops are distinct from the standardized courses being developed by the Edifice Training Foundation.

Discuss this engagement ↗

Flagship service 05

Workforce AI Competence and Responsible Use Assessment

Determine whether people can use, supervise, and challenge AI appropriately—not simply whether they have attended training.

Scope and deliverables

An evaluation of workforce capability beginning with Responsible AI Literacy as the organization-wide foundation, then examining the competence required for particular roles.

Assessment can cover understanding AI limitations, protecting sensitive information, verifying outputs, recognizing inappropriate uses, following organizational policy, exercising human judgment, and knowing when to escalate a concern.

The assessment combines knowledge assessment with scenarios, practical exercises, and examination of work practices. Self-reported confidence alone is not treated as evidence of competence.

The assessment connects assigned roles, responsibilities, and authorities under ISO/IEC 42001 clause 5.3 with the competence provisions under clause 7.2. NIST’s framework similarly connects defined responsibilities with training appropriate to people’s duties.

Typical deliverables: Workforce competence profile, role- or department-level gap analysis, prioritized development recommendations, and a reassessment plan.

Assessment populations: Executive accountability; application ownership and lifecycle management; enablement, control, and assurance; and workforce responsible use.

Discuss this engagement ↗

Flagship service 06

AI Governance Framework and ISO/IEC 42001 Implementation Support

Build governance that operates as part of the organization—not as a separate collection of documents.

Scope and deliverables

Practical assistance establishing or strengthening an AI governance framework and, where required, an AI management system aligned with ISO/IEC 42001.

The engagement defines decision rights, application ownership, approval processes, risk and impact assessment methods, competence responsibilities, supplier oversight, monitoring arrangements, and management reporting. It can incorporate the organization’s existing information-security, quality, privacy, and business-continuity arrangements rather than creating unnecessary parallel processes.

Integration with existing organizational processes and management structures is consistent with the approach described in ISO/IEC 42001.

Typical deliverables: Governance operating model, responsibility matrix, implementation roadmap, selected policies and procedures, control and evidence requirements, and certification-readiness action plan.

Service boundary: Implementation support and readiness review do not constitute certification.

Discuss this engagement ↗

Focused support

Targeted engagements

Engage us for a defined need, or combine these services into an organizational programme.

Targeted engagement 07

AI Inventory and Use-Case Discovery

Establish a practical understanding of where and how AI is being used.

Scope and deliverables

Identify approved applications, pilots, embedded AI features, supplier-provided capabilities, and previously unrecorded uses. Associate each use case with its purpose, owner, users, information handled, affected stakeholders, and decision-making role.

Typical deliverables: AI application and use-case register, initial classification, ownership gaps, and priorities for further assessment. Coverage is stated against the discovery methods and evidence available—not represented as an exhaustive detection guarantee.

Discuss this engagement ↗

Targeted engagement 08

AI Risk and Impact Assessment

Evaluate both organizational exposure and the consequences of AI use for people and other affected parties.

Scope and deliverables

Facilitate or review assessments of specific AI applications, considering intended use, foreseeable misuse, failure conditions, dependencies, affected groups, and proposed safeguards.

The assessment preserves the distinction between risks to the organization and impacts on individuals, groups, or society. ISO/IEC 42005 provides guidance specifically for AI system impact assessments and their integration with AI risk management and management systems.

Typical deliverables: Documented risk and impact assessments, treatment recommendations, residual-risk decisions for management consideration, and reassessment triggers.

Discuss this engagement ↗

Targeted engagement 09

AI Supplier and Procurement Due Diligence

Ask the right questions before buying, integrating, or relying on an AI-enabled service.

Scope and deliverables

Evaluate supplier representations and available evidence concerning intended use, limitations, information handling, security, subcontractors, model or service changes, incident notification, oversight, and exit arrangements.

This can support procurement decisions or a more formal second-party assessment against defined customer requirements.

Typical deliverables: Supplier assessment, evidence-gap register, procurement questions, recommended acceptance conditions, and continuing oversight requirements.

Discuss this engagement ↗

Targeted engagement 10

AI Agent and Autonomous Workflow Governance Review

Establish whether AI-enabled action remains within defined authority and control.

Scope and deliverables

Review workflows in which AI systems can invoke tools, access information, communicate externally, initiate transactions, or delegate tasks. Examine permission boundaries, approval requirements, delegated authority, logging, escalation, exception handling, interruption, and recovery.

The review focuses on the relationship between the agent’s technical capabilities and the authority the organization has actually granted.

Typical deliverables: Authority-and-permissions map, control findings, high-priority scenarios for testing, and recommended operating restrictions or safeguards.

Discuss this engagement ↗

Targeted engagement 11

AI Deployment and Operational Readiness Assessment

Determine what must be in place before an AI application enters routine use.

Scope and deliverables

A pre-deployment or expansion review covering ownership, intended-use limits, evaluation evidence, operating procedures, user competence, monitoring, supplier dependencies, incident response, and fallback arrangements.

Typical deliverables: Readiness assessment, unresolved issues, recommended conditions for deployment, and a management decision record.

The organization retains the deployment decision; Monforte provides the evidence-based assessment.

Discuss this engagement ↗

Targeted engagement 12

AI Policy and Responsible Use Programme

Translate organizational expectations into rules that people can apply in their work.

Scope and deliverables

Develop or revise AI policies, acceptable-use rules, approval procedures, information-handling requirements, output-review expectations, and escalation processes. Address both everyday employee use and more consequential operational applications.

Typical deliverables: Tailored policy suite, practical user guidance, manager briefing materials, communication plan, and acknowledgement or assessment arrangements.

The engagement supports implementation through guidance, communication, and acknowledgement or assessment arrangements.

Discuss this engagement ↗

Targeted engagement 13

Role-Based AI Competence Framework and Development Planning

Define what each role needs to know, demonstrate, and maintain.

Scope and deliverables

Establish competence requirements for executives, application owners, technical personnel, procurement teams, human overseers, compliance functions, and auditors. Connect those requirements to responsibilities, decision authority, and the consequences of error.

Typical deliverables: Role-based competence matrix, evidence and assessment criteria, development pathways, and reassessment triggers.

Following a workforce assessment, the competence framework establishes how the organization will address and manage the identified gaps.

Discuss this engagement ↗

Targeted engagement 14

AI Information Security and Data Governance Review

Examine how AI use affects the protection and appropriate handling of organizational information.

Scope and deliverables

Review information inputs and outputs, access rights, retention, provenance, supplier handling, confidential material, and the controls surrounding AI-enabled workflows. For generative AI engagements, selected reference material can include NIST’s Generative AI Profile, which complements its AI Risk Management Framework.

Typical deliverables: AI-related information-risk findings, data-handling control recommendations, and integration actions for existing security and privacy programmes.

Technical penetration testing or specialized model testing would require a separately defined scope.

Discuss this engagement ↗

Targeted engagement 15

AI Regulatory and Contractual Readiness Mapping

Connect applicable obligations to owners, controls, and evidence.

Scope and deliverables

Help organizations translate identified legal, regulatory, customer, and contractual requirements into operational responsibilities. The service can map obligations to AI applications, procedures, control owners, and records.

Typical deliverables: Obligations-to-controls matrix, evidence register, implementation gaps, and questions requiring legal interpretation.

This service supports counsel and compliance functions. Legal interpretation remains with counsel; the engagement does not provide an unrestricted compliance guarantee.

Discuss this engagement ↗

Targeted engagement 16

AI Incident Preparedness and Tabletop Exercises

Test whether the organization knows what to do when AI use produces an unacceptable result.

Scope and deliverables

Facilitated exercises involving situations such as incorrect advice, information disclosure, discriminatory outcomes, unauthorized agent actions, supplier changes, or loss of effective human oversight.

Participants practice detection, escalation, decision-making, containment, communications, evidence preservation, and recovery.

Typical deliverables: Exercise report, identified response gaps, revised responsibilities, and an improvement plan.

Discuss this engagement ↗

Targeted engagement 17

AI Root-Cause Analysis and Corrective Action Support

Address the conditions that allowed a failure—not merely the immediate error.

Scope and deliverables

Support structured investigation of AI-related incidents, audit findings, recurring control failures, and ineffective corrective actions. Examine the interaction of technology, procedures, incentives, oversight, competence, and management decisions.

Typical deliverables: Root-cause analysis, corrective-action plan, effectiveness criteria, and follow-up review.

Where Monforte helps design a corrective action, any later independent validation requires a separate independence assessment.

Discuss this engagement ↗

Targeted engagement 18

Retained AI Governance Advisory and Management Review Support

Maintain governance as applications, suppliers, responsibilities, and organizational needs change.

Scope and deliverables

A defined recurring advisory service supporting governance meetings, review of new use cases, changes to policies and registers, competence planning, action tracking, and preparation of management-review information.

Typical deliverables: Periodic governance briefings, updated action registers, management-review packs, and advice on emerging decisions within the agreed scope.

The advisory scope and review cadence are agreed for each engagement. Continuous technical monitoring is outside this service, and management retains accountability.

Discuss this engagement ↗

Beyond AI

Supporting organizational services

Information-security management, business continuity, IT service management, integrated management-system auditing, and root-cause and corrective-action workshops support existing client relationships and the wider AI offering.

For an organization introducing AI into a critical service, an integrated review can connect governance, security, continuity, and service responsibilities.

Monforte General Services Division architectural symbol

Bespoke organizational workshops and competence advisory work connect with the Edifice Training Foundation and its planned learning pathways.

Clear scope. Defined evidence.

How we work

Reference frameworks: ISO/IEC 42001 — AI management systems; NIST AI Risk Management Framework; ISO/IEC 42005 — AI system impact assessment; ISO/IEC 42006 — audit and certification bodies.

Discuss your governance priorities

Tell us the organizational question, application, or responsibility you need to address. We will help define an appropriate engagement.

Contact Monforte ↗