Sagentix Cyber & AI
A policy states principles.
A programme makes them binding.
Most organizations that have AI governance have a policy — and nothing downstream of it changed. We build the downstream: the instruments that turn principles into obligations somebody owns.
Built against the frameworks that actually bind, layered onto the risk process you already run, rather than a parallel one that competes with it.
What changes when the programme lands
The test is simple: after the work, can an AI system fail a gate? If nothing can fail, nothing is governed.
A policy that states principles
A directive that creates obligations — named roles, mandatory activities, and compliance milestones somebody owns
Guidance nobody can be held to
An IT security standard with testable technical requirements, so an assessment can pass or fail against it
A separate AI process beside the real one
A risk overlay inside the assessment framework you already run, so an AI system cannot route around it
Instruments that predate AI and never mention it
Amendment packages that reach into the standards already in force, rather than a parallel stack that competes with them
What the programme is made of
Six instruments that compose. Each one is usable on its own; together they close the loop from principle to enforceable requirement.
Governance programme directive
The instrument that creates the obligations: governance structure, roles and responsibilities, the mandatory activities every AI system passes through, and the compliance milestones against which the programme is measured.
IT security standard for AI
Mandatory technical requirements for the secure use and development of AI — data handling, logging, evaluation and red-teaming before deployment, agentic-system constraints, cryptography and decommissioning.
Amendment packages
Rather than a parallel stack, targeted amendments into the standards already in force — access management, identity, cloud, application security, logging, threat and vulnerability management — so AI obligations land where practitioners already look.
The risk overlay
An AI sensitivity and impact overlay on the risk-assessment framework the organization already operates, producing a consistent, defensible score and an assurance level that scales the depth of what follows.
Secure-design control baselines
Controls organized by deployment pattern rather than by product, with a scoping step that tells a team which subset is in scope for the thing they are actually building — and reference architectures that compose them.
Shadow-AI policy and discovery
A sanctioned, tolerated and prohibited classification; a discovery programme spanning cloud access controls, data-loss prevention, code repositories, expense records and surveys; acceptable-use rules; and the procurement clauses that stop the problem recurring.
Built against what binds
Not against the standards that make a good slide. Against the ones an auditor, a regulator or an accountable executive will actually hold you to.
- NIST AI Risk Management Framework 1.0
- NIST AI 600-1 — generative AI profile
- ISO/IEC 42001 — AI management systems
- OWASP Top 10 for LLM applications
- MITRE ATLAS — adversarial threat landscape for AI systems
- ISO/IEC 27001 and the existing security instrument stack
- ITSG-33 and the Canadian control catalogue, where the organization is federal
Delivered
Built and running at a major Canadian federal financial-sector institution as the cyber-architecture operationalization of that organization’s own information, data and artificial-intelligence policy — the directive, the technical standard, the amendment packages layered onto the existing standards stack, the risk overlay inside the existing assessment framework, control baselines organized by deployment pattern, the reference architectures that compose them, and the shadow-AI policy and discovery programme.
Delivered alongside a parallel post-quantum migration programme, with explicit composition between the two so the AI amendments layer cleanly on top of the cryptography ones rather than colliding with them.
No client is named. Engagements are described at method level; named references are available on request, subject to client consent.
Can an AI system fail a gate today?
Thirty minutes. We establish what your current instruments actually oblige, where an AI system routes around them, and what the shortest path to an enforceable programme looks like from where you already are.