All Services
AI under control

AI Exposure Audit

Name the AI risks leadership cannot currently see.

1 day on-site, briefing within 5 working daysAI assurance

One day on site identifies uncontrolled AI use, data exposure, ownership gaps, and the three decisions the leadership team needs to make next.

Led directly by SvenIndependent recommendationsScope agreed before delivery

Where this sits

  1. 1AI GRIP Scan (free, 2 minutes, self-service): Your first signal.
  2. 2AI Exposure Audit (1 day on site, fixed fee): Where AI actually lives and your three biggest risks, named.
  3. 3Shadow AI Assessment (multi-week): Full control: verified discovery, policy, enablement, governance, and a funded roadmap.
How this engagement stays controlledA senior mandate should make the decision, evidence, and accountability easier to control.

Decision first

The mandate starts with the decision, owner, time window, and evidence that could change the answer.

Evidence and boundaries

Scope, exclusions, evidence access, and uncertainty are made explicit before conclusions are presented.

Accountable handover

Sven leads the work directly and closes with clear ownership, decisions, and next actions.

Bring AI into view

How a one-day audit turns invisible AI use into three decisions

A focused verification of actual use, material exposure, immediate containment, and whether deeper governance work is warranted.

Exposure

Is Shadow AI already inside the organization?

Shadow AI includes generative AI tools, embedded assistants, browser extensions, personal accounts, and vendor features that people use without a clear organizational decision. The AI Exposure Audit is a focused one-day verification of where that use is creating material data, ownership, or decision risk.

Verification

What a one-day AI exposure audit can verify

The audit tests available evidence, interviews the agreed stakeholders, and maps the highest-priority AI use and data flows. It produces a concise exposure view, the three material risks, immediate containment actions where required, and the decisions leadership needs to make next.

Audit first, governance design second

FirstVerify exposure

This service answers where AI is already being used and what it is exposing.

Then, when neededDesign governance

It does not design the complete AI governance framework. When leadership needs policy, roles, approved use, controls, enablement, and a funded roadmap, the deeper Shadow AI Assessment is the appropriate next step.

Decision dossier

What this mandate decides, includes, and hands back.

The useful boundary is visible before the work begins: the decision, the evidence, what is excluded, and what happens next.

Decision

The decision this supports

Whether current AI exposure needs immediate containment, clearer ownership, policy changes, enablement, or a deeper facilitated assessment.

Included

In scope

Observed use patterns, available tool and expense evidence, data handling, ownership, policy, awareness, governance gaps, and the highest-priority exposure scenarios.

Boundary

Out of scope

A legal compliance opinion, exhaustive forensic investigation, employee surveillance, model penetration testing, or a complete AI governance program.

Evidence

Evidence required

Approved interviews, policy and tool records, relevant logs or expense data where lawfully available, data-handling rules, and direct observation with explicit scope and consent.

Handover

What happens next

Leadership receives the three material risks, immediate actions, and a clear recommendation on whether the full Shadow AI Assessment is warranted.

How the mandate is set up

Timing

1 day on-site, briefing within 5 working days

Delivery owner

Every mandate is led directly by Sven Van Roosenbroek. Specialist involvement, when needed, is made explicit in scope.

Commercial model

Fixed-fee one-day on-site audit with a follow-up leadership briefing.

What you receive

  • A verified view of where AI is already being used
  • Data exposure and ownership gaps identified
  • The three most material exposure risks named and prioritized
  • A boardroom briefing focused on decisions, not tooling
  • Immediate containment and governance actions where evidence supports them
  • A clear recommendation on whether deeper assessment is warranted

Use this when

  • Leadership teams adopting AI faster than they can govern it
  • Organizations with client or personal data flowing through AI tools
  • Boards that need a verified exposure view before choosing a governance response
  • Companies deciding whether a full Shadow AI Assessment is warranted

Bring the decision to a direct conversation.

Thirty minutes is enough to establish fit, the right depth, and the next responsible step.