Title card: What an AI governance consultant should hand you. AI use register, Decision rights, Evidence test, Control mapping, Exit plan.

What an AI governance consultant should hand you (and what to refuse to pay for).

Short answer. An AI governance consultant should hand you five things: a use register, a decision-rights map, a one-workflow evidence test, a control mapping, and an exit plan. The mapping ties each control to a framework clause your firm is actually bound by, such as NIST AI RMF or ISO/IEC 42001, with evidence behind it. A policy binder with none of this behind it is not governance work. It is a document.

“AI governance consulting” now covers everything from a two-page policy template to a multi-month control build. The market has no shared definition, so the buyer has to set the bar. This is a guide to the deliverables that survive contact with an auditor, and the ones you should refuse to pay for.

What five deliverables actually hold up when an auditor asks?

Each of the five below produces something you can hand to a third party without the consultant in the room. If a deliverable only makes sense with the consultant explaining it, it has not done its job.

  • An AI use register. A list of every AI system or feature in active use across the organisation, who owns each one, what data it touches, and where it sits against your risk tiers. Not a list of tools someone once approved. A living record, updated when a new tool appears.
  • A decision-rights map. A record of who can approve an AI system for use, who can approve a specific high-impact action inside it, and who can pause it. Named roles. A department name is not enough. Without this, “someone reviews it” means nobody is accountable when something goes wrong.
  • An evidence test on one real workflow. Proof that a governed action can be traced end to end: the identity that acted, the proposal it made, the human decision, and the state of the system afterward. One workflow, tested properly, beats a slide describing controls across twenty.
  • A control mapping to the frameworks the firm is actually bound by. Not every framework that exists. The ones your contracts, your regulator or your insurer actually require, with each control tied to a specific clause and a specific piece of evidence.
  • An exit and retention plan. What happens to the register, the logs and the mapping when the engagement ends. Who owns them, where they live, and how your own staff keep them current without the consultant.

What does each deliverable prove, and what does a weak version look like?

Use the table below to check what you were handed against what a weak version looks like in practice.

Deliverable What it proves What a weak version looks like
AI use register You know what AI is actually running today, beyond what was approved on paper A spreadsheet built once for the sales pitch, never updated since
Decision-rights map A named person is accountable for each approval and each pause “The business owner reviews outputs,” with no name and no record of a review
Evidence test A governed action can actually be traced, end to end, on one real workflow A demo environment with sample data nobody in the organisation actually uses
Control mapping Each control ties to a clause you are actually bound by, with evidence behind it A framework logo on the report with no clause numbers and no evidence column
Exit and retention plan Your own staff can keep the register and logs current after the consultant leaves A final report in a shared folder, with no owner named to maintain it

What red flags should you check for before you hire?

Check for these before you sign anything, and again partway through the engagement.

  • Check whether the “policy binder” you were handed has a single record behind any of its claims. A policy describes intent. A record shows what happened.
  • Check whether a framework badge on the proposal comes with a clause-by-clause mapping, or just the logo. A badge with no mapping tells you the firm read the framework’s name. It has not worked through the requirements.
  • Check whether the firm has ever run a synthetic test on a real workflow, with a rejected proposal and an independent check of the system afterward. If every example is a passed approval, ask to see a failure.
  • Check whether every deliverable has a named owner inside your organisation once the engagement ends. If ownership sits with the consulting firm alone, the governance work leaves when they do.

How do you scope a first engagement, in order?

  1. Pick one real workflow that already uses AI, or is about to. Do not start with a survey of every AI tool in the organisation.
  2. Ask the consultant to build the AI use register for that one workflow first, and show you the record for a second, unrelated tool as a check on their method.
  3. Ask for the decision-rights map before any control work starts. If nobody can name who approves what, fix that first.
  4. Run the evidence test together: one governed action, approved once and rejected once, with the source system checked independently both times.
  5. Request the control mapping only after the evidence test, tied to the specific frameworks your contracts or regulator name. A mapping built before the test is a guess.
  6. Agree the exit plan and name your internal owner before the final invoice is paid.

Step one matters more than it looks. A firm that wants to start with an organisation-wide inventory, before touching one real workflow, is selling you a project instead of a proof.

How do you judge a consultant’s own evidence?

Ask the firm to show you its own version of the five deliverables, for its own practice, before you buy. A consultant that cannot produce a register of the AI tools it uses internally, or a decision-rights map for its own approvals, is asking you to build something it has not built itself.

Ask which frameworks the firm maps its own advice against, and check the mapping the same way you would check a vendor’s. The NIST AI Risk Management Framework organises this kind of work under Govern, Map, Measure and Manage, with named accountability structures and documented test results expected at each stage. ISO/IEC 42001 sets out requirements for a certified AI management system, with defined ownership and audit cycles. Neither framework hands you a finished control set. Both give you the clause numbers to check a firm’s mapping against.

The same test we set out for evaluating an AI vendor applies to a governance consultant. See how CISOs evaluate AI vendors and how to prove AI controls to an auditor for the fuller evidence sequence behind this guide.

Questions buyers ask.

Is a policy document enough to show an auditor our AI governance is working?

No. A policy describes what should happen. An auditor samples what actually happened, and asks for the record behind a specific action. A consultant who hands you a policy binder with no register, no decision-rights map and no evidence test has not finished the work.

Should a governance consultant map our controls to every AI framework that exists?

No. Map controls to the frameworks your contracts, your regulator or your insurer actually require. A mapping to a framework nobody is holding you to is effort spent on the wrong document, and it can hide gaps in the frameworks that do apply.

How do we know if the evidence test was run on a real workflow?

Ask to see the source system before and after the test yourself. A consultant’s summary of the result is not enough on its own. A test run on sample data in a demo environment does not show what happens when your own staff and your own systems are involved.

What happens to the governance work when the consulting engagement ends?

That depends entirely on the exit and retention plan agreed at the start. Ask who inside your organisation owns the register and the logs after the invoice is paid, and confirm they can update these records without calling the consultant back.

Handvantage is a consultancy in this space. Apply the same test in this guide to us before you apply it to anyone else. This is an evaluation method. It is not a certification, and it sits behind the twelve tests in the Agentic AI Procurement Handbook. It is not legal advice. Your own counsel should confirm what your contracts and regulator actually require.

Josh Olayemi · Founder, Handvantage · September 2026 · About the author


Similar Posts

Leave a Reply

Your email address will not be published. Required fields are marked *