Headline product · Recurring service · Standalone or paired

The AI Governance Bundle.
Fixed-price. Vendor-neutral. Board-ready every quarter.

A fixed-price, fixed-scope service that establishes your AI governance framework, deploys Microsoft Purview controls, and delivers quarterly governance reporting your board can sign off on. Covers every AI vendor in your environment — not just Microsoft.

EVISENT // QUARTERLY Q2 · 2026
AI Governance Report
ACME PTY LTD · BOARD-READY
Executive summary
Inventory current Policy current Controls attention Reporting current
14
AI tools tracked
ISO 42001
Framework aligned
SIGNED OFF BY EVISENT SENIOR · EVERY QUARTER
"AI does not create risk. It exposes what already exists. The Bundle exists to make sure what's already there is on your terms, not theirs."
What's in the box

Five deliverables. One operating standard.

Every Bundle includes the same five fixed deliverables. We don't sell tiers and we don't lock features behind premium pricing. The work is the work.

1

Shadow AI Discovery audit

Every AI tool in use across your business — Claude, Copilot, ChatGPT, Gemini, Perplexity, whatever's there. Who's using it, what data flows through it, what risk it creates.

2

AI Acceptable Use Policy

Drafted for your industry and your regulator (TPB, ASIC, APRA, AHPRA, Law Society — whichever applies). One page, plain English, ready for legal sign-off.

3

Microsoft Purview & AI-tool configuration

Sensitivity labels, DLP rules, Essential Eight alignment. Tool-level guardrails configured for whichever AI vendors are in your environment — Claude, Copilot, and cross-vendor overlays for the rest.

4

Framework alignment mapping

ISO 42001 + Voluntary AI Safety Standard + your industry-specific regulator. The document your board will be asked to evidence when an audit lands.

5

Quarterly AI Governance Report

Board-ready, signed off by Evisent senior, every quarter. Traffic-light status across Inventory, Policy, Controls, and Reporting. The single artefact that proves the ongoing fee is being earned.

Setup phase · 4 weeks

From signed engagement to first board report — 30 days.

The Bundle's setup phase is sequenced. Each week has a defined goal, a defined output, and a defined gate to the next week. You always know where we are.

1

Week 1 — Onboarding

Tenant access, stakeholder map, condensed Discovery (if no Sprint completed).

2

Week 2 — Framework

AI Governance Framework drafted, mapped to ISO 42001 + your regulator. Stakeholder review.

3

Week 3 — Controls

Microsoft Purview deployment / refinement. Cross-vendor governance overlays applied.

4

Week 4 — Live

AUP rolled out, staff training delivered, AI inventory published. First monthly report generated.

Ongoing · what the monthly fee covers

The Bundle isn't a deliverable. It's a discipline.

AI changes monthly. So does your team's use of it. The ongoing fee covers the cadence of review and refinement that keeps your governance posture current.

Monthly

Inventory + drift check

  • ↳ AI tool inventory refresh — new tools flagged
  • ↳ Purview & AI-tool configuration drift check
  • ↳ AUP version control + change log
  • ↳ Incident review (leak attempts, policy bypass)
  • ↳ One-page status report to primary contact
Quarterly

Board-ready governance report

  • ↳ Quarterly AI Governance Report (sample below)
  • ↳ Live discussion with leadership (30-60 min)
  • ↳ Framework refresh against regulator updates
  • ↳ Recommended actions for next quarter
  • ↳ Roadmap reset where needed
Annual

Re-baseline + roadmap

  • ↳ Full framework re-baseline
  • ↳ Independent gap analysis
  • ↳ 12-month forward roadmap
  • ↳ Pricing & scope renewal
Always on

Regulator watch + same-day flag

  • ↳ APRA · ASIC · OAIC · TPB · AHPRA · Law Society
  • ↳ New guidance that affects you = same-day notice
  • ↳ Quarterly briefing on what changed industry-wide
The artefact your board will actually look at

Inside the Quarterly Governance Report.

Most governance work produces documents nobody reads. The Quarterly Report is built backwards from the one-page traffic-light summary a board chair will actually open.

  • 1
    Executive summary
    Traffic-light status across Inventory, Policy, Controls, Reporting. Three changes this quarter. Recommended attention items.
  • 2
    AI inventory
    All AI tools in use, by team, by data classification. New tools introduced. Tools retired.
  • 3
    Policy posture
    AUP version. Training completion. Violations logged.
  • 4
    Controls posture
    Purview rule effectiveness. AI-tool guardrail performance across deployed vendors. Cross-vendor coverage. Incidents and near-misses.
  • 5
    Framework alignment
    ISO 42001 / AU Voluntary AI / industry regulator. Gaps closed. Gaps remaining.
  • 6
    Regulatory calendar
    Upcoming deadlines and how you track against them.
  • 7
    Recommended actions
    Prioritised list for next quarter with effort estimates.
Quarterly AI Governance Report
Acme Pty Ltd · Q2 2026
Inventory — current · 14 tools tracked
Policy — current · v3.2 · 96% training complete
Controls — attention · 2 Purview rules need refresh
Reporting — current
↳ Microsoft Copilot (M365) · 87 licences
↳ Microsoft Copilot Studio · 4 agents live
↳ Power Automate · 23 flows
↳ Anthropic Claude (API) · 2 integrations
↳ ChatGPT (shadow) · 12 users flagged
↳ Gemini (shadow) · 3 users flagged
Pricing

Same scope. Same price. Published.

Every other AI consultant starts a discovery call with "that depends." We publish the price and the deliverable. You can decide if we're worth booking before you book the call.

SETUP · ONE-OFF
From $4,950
+ GST · 30 days · flexes with org size, tenant count & AI footprint
  • Onboarding + tenant access
  • Shadow AI Discovery audit
  • AI Acceptable Use Policy drafted
  • Microsoft Purview & AI-tool configuration
  • Framework alignment mapping
  • Staff training (1hr, recorded)
  • First monthly governance report
Book the Bundle
ONGOING · MONTHLY
From $2,000/mo
+ GST · monthly · flexes with reporting cadence & inventory size
🎯 Commit to 12 months — save 10%.
  • Monthly inventory + drift check
  • Quarterly board-ready governance report
  • Quarterly leadership review (30-60 min)
  • Annual framework re-baseline
  • Same-day regulator alerts
  • Full documentation kept current
  • Vendor-neutral · portable by design
Start the Bundle
For businesses 20+ in size — operational note
For clients 20+ in size we'll recommend moving Managed IT to Evisent — not because the Bundle requires it, but because clean admin access keeps governance work secure and avoids co-administration risk. MSP pricing is from $185/user/month, 10-user minimum ($1,850/mo floor). Sub-20-seat businesses are welcome to engage on the Bundle alongside any incumbent IT provider.
What's deliberately not in scope

Honest about the boundary.

Common questions

AI Governance FAQ

What is AI governance, and why does my business need it?+

AI governance is the set of policies, controls and oversight a business puts around how it uses AI — who can use which tools, on what data, with what review. Most Australian businesses already have shadow AI (staff using ChatGPT, Claude, Copilot, Gemini) without a policy. The exposure is data leakage, IP loss, regulatory breach, and decisions made on unverified AI output. Governance is the structural fix.

What is in the AI Governance Bundle?+

A complete governance foundation: AI Acceptable Use Policy, risk register, vendor assessment process, board reporting templates, staff training collateral, and quarterly review cadence. Built on ISO 42001 principles and mapped to Australian regulators (Privacy Act, APRA CPS 230 where applicable). Delivered as editable artefacts that vest with you.

Is the Bundle aligned with ISO 42001?+

Yes. The Bundle is mapped to ISO/IEC 42001:2023 (the international AI Management System standard). If your business plans to pursue certification, the Bundle gives you a working management system that is already aligned. If certification is not on your roadmap, the Bundle still gives you the operating discipline of one.

Does APRA or the Privacy Act require AI governance?+

There is no AI-specific Australian statute yet, but several existing obligations apply when AI is used. APRA CPS 230 (operational risk management) covers material service providers — increasingly that includes AI vendors. The Privacy Act applies whenever personal information goes through an AI system. ASIC has signalled directors duties extend to AI oversight. Sector regulators (TGA, ACMA, AHPRA) each have their own positions. The Bundle maps the obligations that apply to your industry specifically.

We already have IT security policies — do we need separate AI ones?+

Yes. AI raises issues that traditional infosec policies do not address: model output reliability, training-data leakage, prompt injection, vendor data residency for AI providers, and accountability when AI gets a decision wrong. The Bundle complements your existing security policies rather than replacing them.

How long does the Bundle take to deliver?+

Typically 4–6 weeks end-to-end. Most clients run the 2-week Sprint first to establish their foundation, then move into the Bundle. The Sprint cost credits against the Bundle if you choose to proceed.

The 2-week first step

Start with the Sprint. Grow into the Bundle.

Most Bundle clients start with a 2-week AI Readiness Sprint to size the work first. From $4,950 + GST, it gives you the discovery, AUP draft, and board summary — and a clear shape for the ongoing governance work.

★★★★★50 Google Reviews Chat to us