governance plan. the written artifact that ships alongside every ai implementation: a policy doc describing what the ai can and cannot decide, an audit log showing every action and its outcome, and a rollback plan that returns the operation to its pre-ai state within one working day.
most ai consultancies deliver code. we deliver code plus a governance plan. the governance plan is not an optional add-on or a final-week afterthought. it is in the contract from day one, and it ships with the implementation.
#why governance is inside scope, not outside it
the pattern that kept surfacing across early engagements was this: a team spends weeks building and shipping an ai workflow. it goes live. then someone asks a question the team cannot answer cleanly. who approved this decision? what happens if the model produces a wrong answer at scale? how do we revert to the previous process if we need to?
those questions are not edge cases. they are the first questions a risk officer, a legal team, or a new operations lead will ask. if the answers are not documented — not in the model config, not in a readme, but in a readable written artifact — the ai workflow sits on soft ground.
we put governance inside scope because shipping without it is an incomplete delivery. the workflow runs, but the organization is not ready to own it.
#what the governance plan actually contains
three documents. they take a week to write and test, not a quarter.
- policy doc — what the ai is authorized to decide, what it must escalate to a human, and what it must never do. written for the operations team, not for engineers.
- audit log spec — the schema and retention rules for every ai action. who acted, on what input, with what output, at what time. this is the document your compliance team will eventually ask for.
- rollback plan — step-by-step instructions to revert the workflow to its manual or previous-state version. tested, not theoretical. a named person owns the plan, with a target window of one working day.
does the policy doc need a lawyer?
not for the first version. the policy doc is an operational document, not a legal one. it describes what the ai does and what humans own. if your organization later needs a formal ai use policy for compliance or regulation, the policy doc is the evidence base that makes writing one faster. we hand it to your team in plain english.
#the conversation that tends to happen at week three
on roughly half of implementations, a stakeholder — often a cfo, a head of compliance, or an ops director who was not in the initial brief — walks into the project in week three. the questions they ask are predictable: what does this model do when it's wrong? who is accountable? what is the worst-case failure and how do we recover?
when those questions arrive and the governance plan already exists, the meeting takes 20 minutes. when those questions arrive and the team has to go build the answers retrospectively, the project slows, sometimes stops, and occasionally gets cancelled. the governance plan is the document that keeps the week-three meeting from becoming a week-eight delay.
we are
ship three written artifacts — policy, audit log spec, rollback plan — as part of the fixed-fee scope. the governance plan is tested, authored in plain english, and owned by your team from day one.
we aren't
consultancies that add governance as a retainer module after go-live, or slide decks that describe 'responsible ai principles' without naming a single rollback procedure.
#what governance costs to produce
the governance plan adds roughly one week of work to a standard implementation engagement. a senior engineer and a strategist co-author it in parallel with the final testing phase. it does not extend the shipping date. it is inside the fixed fee.
standalone governance engagements — for organizations that already have ai running and need the written artifacts — have their own scope and price; specifics on the discovery call. the shape is a 2-week audit plus the three documents: the policy doc, the audit-log spec, and the rollback plan — whether or not we ship the build. if the ai is already in production and the governance plan is missing, the audit uncovers what is needed first.
#why we made it non-optional
the simplest reason: an ai workflow without a governance plan is an incomplete product. it may run today. it will cause problems the moment a team member changes, a regulator asks a question, or the model's outputs shift unexpectedly.
the second reason: optional add-ons are the ones that get cut in scope negotiations. governance is not a feature. it is the evidence that the implementation was done properly.
we are new. the terms on this page are what we will honor with the first client who signs. if you are scoping an ai implementation and want to see what a governance plan looks like before you commit, book a 30-min discovery call. we will walk through a redacted example on the call.
do you sell governance plans for ai we did not build?
yes. standalone governance engagements are scoped in writing before any work starts — price on the discovery call. the deliverable is the same three documents (policy doc, audit-log spec, rollback plan), written after a 2-week audit of the ai you have running. for organizations that shipped quickly and need the written foundation before the compliance conversation arrives.