Where to start
Most institutions have a written AI control framework and no way to tell which parts of it can be tested from data they already hold. The AI Control Testing Readiness Assessment answers that question control by control.
What you bring
The assessment takes two inputs. The first is your AI control library, in whatever form it exists: a GRC platform export, a spreadsheet, a policy document, or a framework you’ve adopted and not yet localised. The second is one AI-assisted process that’s live or about to go live, with its documentation, the structure of the records its systems already write (a field list or a redacted sample, not the records themselves), and access to the people who own it.
That’s deliberately narrow. One process is enough to answer the question that matters: whether the records your AI produces today can evidence the controls you’ve written, and if not, what would have to change.
Duration
Four weeks
from scoping call to read-out.
Your time
Eight to ten hours
of interviews across control owners, second line and technology, plus document retrieval.
Access
None
We do not connect to your systems and we do not receive decision data.
What you get
The output is a written readiness memo for the process examined. It’s yours to use whether or not you do anything further with us.

Illustrative data
Which controls in your library can be tested against decision records you already hold, across the whole population rather than a sample, and what population each test would cover.
Which controls resolve to whether the right document exists, is approved and is current, and where those artefacts live today.
Which controls require a person to read something and form a view, and therefore sit outside automated testing. We say so plainly rather than promising everything resolves.
For each control that cannot be tested from today’s records: which fields would need to be captured, at which point in the process, and from which system. Sequenced by exposure, so the first instrumentation decision is the one that unlocks the most testing.
Where the inputs, model version, tool calls, human review step and outcome for one decision live today, across your systems and your vendors’, and what assembling them would involve.
How it runs
Select a process, name the control owners and confirm what the memo needs to do for you internally.
Your control library, the process documentation, the structure of any existing AI logging or observability outputs, and the model or vendor documentation for the AI in the process. Shared under NDA through your usual channel.
Control owners in the first line, the second-line lead for the domain, and one person from data or technology who knows where the process’s records are written. Internal audit is welcome to sit in.
Each control in scope is classified as testable daily, testable by artefact, or requiring judgement, using the same testability tiers our platform applies. Where a control is written as a policy statement rather than a testable assertion, we propose a testable version beside it. You adopt or decline it through your own approval process.
A working session to walk through the classification and the instrumentation sequence, followed by the written memo.
Scope limits
We classify controls by how they can be evidenced. We do not say whether you comply with anything.
No maturity rating, no radar, no percentage. Every statement in the memo names a control.
We do not ask you to produce the record of a real decision under a clock. That exercise has its place, and it isn’t the first engagement.
The memo describes what testing each control would require, not a register of what’s failing. The information is the same, but it’s a materially different document if it’s ever read by someone hostile.
NDA, third-party risk assessment and whatever else your institution requires apply as they would to any engagement. We plan for it.
Who it’s for
The assessment is usually commissioned by the Head of Operational Risk, the CRO or the model risk lead, because they own the framework being examined. The first line participates and gets a clear account of what capture their systems would need. Internal audit gets a testability classification they can reuse when planning their own AI audit work.
If none of your AI is in or near production in a process that affects a decision, we’ll say so at the scoping call.
APRA’s April 2026 letter found that second-line and internal audit functions frequently lack the technical capability and tooling to assess AI systems.
The assessment is the easiest way to find out what that would take, before you commit to any tooling, including ours.
Enquire
Tell us about one AI-assisted process, live or about to go live. We’ll come back within two business days with a scoping call time and a one-page scope you can circulate internally.
Thanks. We will be in touch within two business days.