AI Governance Diagnostic

AI is making decisions inside your organisation. Can you prove you are in control?

A deterministic diagnostic that finds your governance gaps and produces a report your board, insurer, or regulator will accept.

Start Assessment

What you receive

This is what one finding looks like.

Financial Services · UK Critical
FS-G04

No named SM&CR accountable individual for AI decision system

Regulatory obligations

SM&CR Senior Managers Regime FCA Principle 3 DUAA 2025 UK GDPR Art 22

This becomes visible when

The FCA opens a supervision visit and asks who is accountable for AI decisions affecting clients. No named Senior Manager in a Statement of Responsibilities. The gap exists and is provable from your own governance documents. No incident required.

Required action

Update the relevant Statement of Responsibilities immediately. Name the accountable Senior Manager. Document the oversight protocol. Add AI systems to the Management Responsibilities Map.

This is not a consultant's opinion. It is a deterministic finding derived from intake signals against a fixed gap library. The same inputs produce this finding on every run.

Every finding in a CLEARANCE report follows this structure. Gap ID, regulatory obligation, the moment it becomes visible, and the action that closes it.

A full engagement covers your sector and produces findings across governance layers. The report is designed to be handed to a board, an insurer, or a regulator without further explanation.

10
minutes to complete the assessment
25
governance gaps in the library, mapped to named regulatory obligations
10
sector verticals covered, UK and US

How it works

Three steps from intake to evidence artefact.

01

Complete the assessment

A structured intake covering your AI deployment, decision points, autonomy boundaries, and data flows. Ten minutes. One question at a time. No technical knowledge required.

02

The engine runs

Your responses are evaluated against a fixed gap library. No consultant interpretation. No maturity scoring. The same inputs produce the same findings on every run. Deterministic by design.

03

Report delivered

A four-section PDF delivered to your inbox within minutes of payment. Executive summary, detailed findings, remediation roadmap, evidence appendix. Built to be handed to a board, insurer, or regulator unchanged.

Sector coverage

Built for regulated organisations.

Healthcare UK Healthcare US Financial Services UK Financial Services US Legal Recruitment & HR Charity UK Charity US Nonprofit US General Commercial

Each sector maps to the obligations that apply — UK regulatory frameworks, EU AI Act, HIPAA, and sector-specific rules. Covers agentic AI deployments including Salesforce Agentforce. The engine determines which gaps apply to your deployment.

What it is

A fixed-scope diagnostic. One engagement. One report.

Deterministic findings. Same inputs, same output, every time.

Fixed fee. Priced by sector. Shown before you pay.

Report delivered within minutes. No follow-up call required.

Defensible to your board, insurer, and regulator.

What it is not

Not a retainer. Not advice. Not a platform.

We do not build or fix your AI systems.

We do not provide legal advice.

We do not offer retainers or ongoing relationships.

We do not consult beyond the fixed scope of one engagement.

One engagement. One report. One outcome: evidence.

Fixed fee. Priced by sector. Report delivered within minutes of payment.

Start Assessment

The Diagnostic

Not an assessment. An evidence-producing instrument.

Built from cross-regulatory analysis across the EU AI Act, UK regulatory frameworks, and sector-specific obligations. Mapped to real agentic workflows. Deterministic by design.

A deterministic, point-in-time diagnostic that finds the structural governance gaps in your AI deployment and tells you exactly what to fix, why it matters, and what to do next. Same inputs. Same findings. Every time.

How it works

01

Intake and mapping

The intake captures where AI is operating inside your organisation: workflows, decision points, autonomy boundaries, and data flows. One question at a time. Ten minutes.

02

Deterministic gap model

Your intake is evaluated against a fixed-scope governance model. No maturity scoring. No opinion. The same inputs always produce the same outputs. Every finding maps to a named regulatory obligation.

03

Evidence artefact

A four-section report delivered within minutes of payment. Executive Summary, Gap Findings, Remediation Roadmap, Evidence Appendix. Designed to be handed to a board, insurer, or regulator unchanged.

The report

Four sections. One defensible artefact.

Executive Summary

Board-ready overview of governance posture, RAG status, confidence score, and deployment verdict.

Gap Findings

Every gap named, with the regulatory obligation it maps to and the consequence of leaving it open.

Remediation Roadmap

Prioritised actions at 30, 90, and 180 days. Named by domain. No padding.

Evidence Appendix

Raw assessment responses and audit trail. The record an insurer or regulator can verify.

Built for

Any organisation with a live AI deployment and no dedicated governance team.

Mid-market or SME. Regulated sector. No internal AI governance resource.

Deploying AI in hiring, legal, advisory, risk, or operational workflows.

Asked to evidence governance to a regulator, insurer, or enterprise client.

Deployment is live or in active pilot. Decisions are already being made.

Scope boundary

What we do not do.

We do not build or fix your AI systems.

We do not provide legal advice.

We do not offer ongoing retainers or advisory relationships.

We do not consult beyond the fixed scope of one engagement.

The evidence your organisation will be asked for.

Fixed fee. Report delivered within minutes of payment.

Start Assessment

About

Built to solve a structural problem.

AI is making decisions inside organisations faster than those organisations can evidence control. CLEARANCE fills that gap.

There is no single rulebook. In the UK, the ICO, FCA, CQC, and SRA are all enforcing AI governance obligations under UK GDPR and DUAA 2025. In the US, the FTC, SEC, EEOC, and HIPAA/OCR are active, and state-level laws in Colorado, California, and New York are already in force. The EU AI Act applies extraterritorially, with penalties up to 7% of global turnover for high-risk systems. The pressure is not coming from one direction. Most organisations cannot produce evidence that would satisfy any of them.

CLEARANCE is a fixed-scope, deterministic diagnostic that produces a repeatable, defensible governance artefact within minutes of payment. Not months. Not a retainer. One engagement, one report, one outcome.

The founder

I spent twenty-three years watching organisations document how their systems were supposed to work. When I started looking at agentic AI, I saw the same problem at scale.

CLEARANCE is what I built to fix that.

I am a systems analyst by training. My background is operational: retail, financial services and government, across business analysis, process modelling and requirements definition. The work was always the same: understand how systems behave under pressure, not how they are documented.

The gap library and governance architecture were built from first principles and verified against a certified test suite. Engagements are fixed in scope. Not open-ended.

Contact

Get in touch.

No sales process. A direct conversation about whether CLEARANCE is the right fit.

Location United Kingdom
Availability Intro calls and early-stage engagements

CLEARANCE evaluates governance structure only. It does not assess AI model performance, output accuracy, or system safety. The report identifies structural governance gaps. It does not determine whether a regulatory breach has occurred.

Sample Finding

This is what one finding looks like.

One gap. One citation. One consequence. One required action. Every finding in a CLEARANCE report follows this structure.

Financial Services · UK Critical
FS-G04

No named SM&CR accountable individual for AI decision system

Regulatory obligations

SM&CR Senior Managers Regime FCA Principle 3 DUAA 2025 UK GDPR Art 22

This becomes visible when

The FCA opens a supervision visit and asks who is accountable for AI decisions affecting clients. No named Senior Manager in a Statement of Responsibilities. The gap exists and is provable from your own governance documents. No incident required.

Required action

Update the relevant Statement of Responsibilities immediately. Name the accountable Senior Manager. Document the oversight protocol. Add AI systems to the Management Responsibilities Map.

This is not a consultant's opinion. It is a deterministic finding derived from intake signals against a fixed gap library. The same inputs produce this finding on every run.

CLEARANCE does not produce recommendations. It produces findings. Each one is tied to a specific regulatory obligation, a specific control that is absent, and a specific action that closes it permanently.

The same intake always produces the same findings. No consultant interpretation. No subjectivity. If a gap fires, the trigger condition was met.

A full engagement covers your sector and produces findings across governance layers. The report is designed to be handed to a board, an insurer, or a regulator without further explanation.

Start Assessment