White paper

AI governance
that survives an audit.

The EU AI Act, ISO/IEC 42001 and NIS2 all converge on the same demands: know what AI you run, govern it against explicit policy, name who is accountable, and prove every step. This paper looks at why most AI governance programmes can't produce that proof — and what a deterministic, evidence-first approach looks like.

The regulatory wave

AI regulation has moved from aspiration to enforcement. The EU AI Act imposes obligations by risk class, with real penalties. ISO/IEC 42001 turns AI management into a certifiable discipline, the way ISO 27001 did for information security. NIS2 and DORA extend operational-resilience expectations to the systems your critical services depend on — increasingly including AI. Different texts, one common core: inventory, governance, accountability, evidence.

What none of them accept is the current default: an AI policy PDF on the intranet, a partial spreadsheet of "known" models and agents, and good intentions.

The gap between policy documents and estates

Most organisations do have an AI policy. Almost none can say, for any given agent in their estate, whether it complies. The policy lives in prose; the estate lives in tenants and platforms; and the mapping between them is done — if at all — by hand, once, at approval time. From that moment the two drift apart. The agent gains a connection, the policy gains a clause, and nobody re-evaluates anything until an incident forces the question.

A policy that is not continuously evaluated against the estate is not governance. It is literature.

Policy as code, approved like code

The fix borrows from an adjacent discipline. Infrastructure teams solved policy drift years ago by expressing policy as code: versioned, reviewable, applied automatically, with the current state continuously checked against the declared intent. AI governance needs the same move. Policies become structured, data-only rules over agent facts — who owns it, what it can reach, which platform it runs on, what its risk posture is — rather than paragraphs to be interpreted.

Just as important is how policy changes. Each version is immutable once published, and publication requires an independent approver — the author cannot approve their own rules. When a verdict changes, you can point at exactly which policy version changed it, who wrote it and who signed it off. The governance system is itself governed.

Why determinism matters

It is tempting to point a large language model at the problem and ask it to judge compliance. For governance, that is precisely the wrong instrument. A verdict that can vary between runs, that cannot fully explain itself, and that might quietly change when a model is updated is a verdict an auditor — or a court — will not accept. Governance judgements must be deterministic: the same facts and the same policy version must always produce the same result, and the result must decompose into the exact rules that fired.

Determinism is what turns an assessment into evidence. It means a verdict from last March can be re-derived today, byte for byte, from the recorded facts and the recorded policy version — which is exactly the property regulators mean when they ask for explainability and traceability.

Accountability needs a name

Every framework in the wave asks some version of the same question: who is responsible for this system? "The AI working group" is not an answer. Effective governance binds every agent to two named humans — a business sponsor who owns the justification, and a technical owner who owns the implementation — with assignments recorded, historied and tracked for due status. When an agent misbehaves, the escalation path is a lookup, not an investigation.

If everyone is accountable for AI, no one is. Accountability is a name, a role and a date.

Approvals that expire

An approval is a statement about a moment: this agent, as it existed then, was acceptable. Agents change — new connections, new data, new scope — and the organisation's risk appetite changes around them. Governance that stands up over time therefore makes approvals perishable: every approved agent returns to the review queue on a fixed interval, and overdue recertifications are visible, assigned and escalated. The register never silently ages into fiction.

Evidence an auditor will accept

The final test of any governance programme is the audit. What did you know, when did you know it, what did you decide, who decided it, and what changed as a result? Answering from memory or reconstructed email threads is where programmes fail. Answering from an append-only event history — every discovery, verdict, decision, exception and remediation recorded as it happened, exportable with digest protection so its integrity can be verified — is what audit-ready actually means.

Apex Warden was designed around exactly this bar: policy-as-code with independent approval, deterministic evaluation, named sponsor and owner per agent, interval-based recertification, and append-only, digest-protected evidence. Not governance theatre — governance you can hand to an auditor.

See audit-ready governance running

Book a walkthrough of policy-as-code evaluation, accountability and evidence export on a live estate.

Get a demo