Saguaro's illustrated workspace in forest green and warm stone, with a cactus, engineering desk, and robotics equipment

Saguaro Governance — AI security, governance and deployment risk

Explore our approachAI GOVERNANCE / PHYSICAL INTELLIGENCE01 — 06

AI system review

Scroll or select a branch

02 / Services

AI security & governance

Governance services

Engage Saguaro for an assessment, audit, implementation project, or ongoing advisory support. Explore each service for its scope and deliverables.

Robotics & physical-AI governance
Assess

Clarify the current position

Establish the scope, dependencies, risks, and evidence needed for a decision.

AI governance & readinessEstablish the AI inventory, responsibilities, and priorities for the systems in scope.
When to engage

Your teams are introducing AI, but ownership, review criteria, or the current inventory are incomplete.

Work included

  • Interview business, security, privacy, and technical owners to define use cases and affected stakeholders.
  • Review existing policies, AI inventories, approval routes, and risk-assessment practices.
  • Identify governance gaps and prioritize work against business needs and the organization’s risk tolerance.

What you receive

  • Scoped AI inventory and use-case profiles
  • Governance gap assessment and responsibility map
  • Prioritized implementation roadmap
Explore the deliverable
Discuss this service
AI risk & impact assessmentReview potential effects on people, business operations, and the use of AI outputs.
When to engage

An AI system influences decisions or services, and you need to understand its wider risks before adoption or expansion.

Work included

  • Identify affected people, intended benefits, foreseeable misuse, and potential adverse effects in the application context.
  • Review available evidence on reliability, privacy, harmful bias, transparency, and human oversight where relevant.
  • Document impact scenarios, assessment limitations, control needs, and decisions requiring specialist or leadership review.

What you receive

  • Scoped AI risk and impact assessment
  • Stakeholder, impact, and control mapping
  • Recommended mitigations and review triggers
Explore the deliverable
Discuss this service
AI security risk assessmentReview the architecture, data flows, permissions, and plausible threat scenarios.
When to engage

You need a risk decision on a generative-AI application, agent, enterprise platform, or material system change.

Work included

  • Map data sources, retrieval components, model services, tools, identities, and trust boundaries.
  • Assess prompt injection, sensitive-data exposure, excessive permissions, insecure integrations, and relevant poisoning scenarios.
  • Define risk-rating criteria, assess existing controls, and document assumptions and evidence gaps.
  • Review findings with the responsible teams and recommend risk treatment and reassessment triggers.

What you receive

  • System context and threat-model record
  • Risk register with rating rationale and control gaps
  • Technical findings, executive summary, and remediation recommendations
Explore the deliverable
Discuss this service
Vendor & system due diligenceExamine provider evidence before procurement, integration, or expansion.
When to engage

A vendor demonstration or questionnaire leaves questions about data use, security, support, or your responsibilities.

Work included

  • Compare documentation and available test evidence with the intended application and operating requirements.
  • Review data handling, retention, model limitations, dependencies, access, incident processes, and shared responsibilities.
  • Track unanswered questions and identify issues requiring security, privacy, legal, or engineering review.

What you receive

  • Vendor assessment and evidence-request register
  • Dependency and responsibility map
  • Decision brief with adoption conditions and unresolved questions
Explore the deliverable
Discuss this service
Test & audit

Examine controls and evidence

Choose an adversarial test, a governance audit, or a readiness engagement to match the question you need answered.

AI red teaming & adversarial evaluationTest how an agreed AI application behaves under misuse and adversarial inputs.
When to engage

You want to test safeguards before release or examine weaknesses after a material change.

Work included

  • Agree on authorized targets, objectives, test accounts, data handling, stop conditions, and rules of engagement.
  • Develop application-specific scenarios for prompt injection, instruction bypass, data exposure, retrieval manipulation, and unauthorized tool use.
  • Conduct scoped adversarial exercises; record reproducible observations, preconditions, affected controls, and business impact.
  • Review remediation with the delivery team and retest the agreed findings when included in scope.

What you receive

  • Rules of engagement and scenario coverage
  • Reproduction evidence and prioritized findings
  • Remediation recommendations and scoped retest results
Explore the deliverable

Testing covers the agreed environment and scenarios. Passing those tests does not establish that a system is free of vulnerabilities.

Discuss this service
Governance audits & control reviewsEvaluate documented requirements against the evidence of how controls operate.
When to engage

You need to examine an existing governance program, investigate gaps, or prepare for an external review.

Work included

  • Define audit criteria, system and organizational boundaries, sampling, and the evidence period.
  • Review policies and records, interview control owners, and examine implementation and operating evidence.
  • Document findings, supporting evidence, limitations, and corrective actions with assigned owners.
  • Review closure evidence or conduct follow-up work when included in the engagement.

What you receive

  • Audit or control-review plan and evidence index
  • Findings report and requirements-to-controls mapping
  • Corrective-action register and follow-up record
Explore the deliverable

For an internal audit, competence, objectivity, and independence are agreed at scoping, including where Saguaro has helped implement the controls.

Discuss this service
ISO/IEC 42001 readinessPrepare the AI management system and evidence for an independent certification assessment.
When to engage

Your organization is considering ISO/IEC 42001 or needs a structured gap review before certification.

Work included

  • Define the AI management-system scope and compare current practices with applicable standard requirements.
  • Review responsibilities, risk and impact assessment processes, documented information, and control implementation.
  • Support remediation planning, evidence organization, management review preparation, and internal-audit planning.

What you receive

  • Readiness assessment and prioritized gaps
  • Requirements, controls, and evidence map
  • Remediation plan and audit-preparation checklist
Explore the deliverable

Readiness support does not confer certification. Certification decisions are made by an independent certification body.

Discuss this service
Implement

Operationalize governance

Build the process and prepare the people who will run it.

Governance implementationPut the policies, decision workflows, and control ownership into daily use.
When to engage

You have an assessment or policy, but teams need an operating process and help putting it in place.

Work included

  • Develop or revise AI policies, use-case intake, risk-tiering criteria, and approval workflows.
  • Assign control owners and define exception handling, risk acceptance, escalation, and change review.
  • Build procedures, templates, evidence requirements, and reporting suited to the teams and systems in scope.
  • Support rollout through working sessions and a scoped pilot; adjust the process using participant feedback.

What you receive

  • Governance playbook and responsibility matrix
  • Intake, assessment, approval, and exception templates
  • Change and incident procedures, rollout plan, and handoff materials
Explore the deliverable
Discuss this service
Team workshops & operating handoffHelp decision-makers and operators use the governance process consistently.
When to engage

A new policy, AI system, or workflow requires people to understand their responsibilities and apply them.

Work included

  • Run role-specific working sessions for leadership, technical teams, reviewers, or operators.
  • Walk through actual use cases, escalation decisions, evidence requirements, and exception scenarios.
  • Use tabletop exercises to examine incident response and human oversight responsibilities.

What you receive

  • Workshop materials and scenario exercises
  • Role-specific guidance and procedure updates
  • Attendance records, feedback, and follow-up actions
Explore the deliverable
Discuss this service
Maintain

Support ongoing oversight

Review changes and keep ownership, risk decisions, and operating records current.

Ongoing governance & advisoryKeep risk decisions, evidence, and review processes current as systems change.
When to engage

Your AI portfolio is operating and you need scheduled reviews or additional governance capacity.

Work included

  • Agree on a review cadence, systems covered, responsibilities, and advisory availability.
  • Review new use cases, vendor changes, incidents, exceptions, and material configuration changes.
  • Maintain action and risk registers, review remediation evidence, and prepare leadership reporting.
  • Recommend reassessment or specialist work when operating conditions or risk exposure change.

What you receive

  • Updated risk and action registers
  • Periodic governance and leadership reviews
  • Change assessments and reassessment recommendations
Explore the deliverable
Discuss this service
Frameworks and engagement scope

The engagement identifies the frameworks, organizational policies, systems, evidence, and review criteria that apply. NIST AI RMF can inform governance and risk-assessment work; ISO/IEC 42001 can provide the management-system criteria for readiness work. AI-security testing uses scenarios selected for the application, with references such as OWASP guidance where relevant.

NIST AI RMF ↗ISO/IEC 42001 ↗OWASP GenAI red teaming ↗

03 / Approach

Engagement structure

The Saguaro Method

The work is scoped around a specific system or deployment. Each phase establishes the decisions, responsibilities, and records needed for the next.

Align

Engagement scope

Agree on the business decision, workflow, accountable owner, and the people affected.

ENGAGEMENT WORKSPACE
Review
  • Define intended use and operating limits.
  • Agree on success criteria and exclusions.
Record

Use-case charter and decision brief

Phases can be revisited as the system changes.
Scoping, working sessions, and delivery

04 / Evidence

Reports and operating records

Engagement deliverables

Explore what goes into each record. The agreed scope determines the deliverables, evidence depth, and review activities.

Documents the system reviewed, the assessment criteria, available evidence, limitations, and findings.

Records risk scenarios and the decisions or actions assigned to address them.

Supports a procurement or adoption decision using the evidence available for the proposed application.

Documents authorized test coverage, observed behavior, and findings that the delivery team can investigate.

Connects the agreed audit criteria to examined records and documented findings.

Organizes the gaps and evidence needed to prepare an AI management system for further assessment.

Defines the operating process and the responsibilities needed to use it consistently.

Records the agreed application boundaries, responsibilities, and evidence for the deployment decision.

Summarizes the risk position, material changes, and decisions requiring leadership attention.

ILLUSTRATIVE CONTENTS01 / 09

Assessment report

Documents the system reviewed, the assessment criteria, available evidence, limitations, and findings.

  • Scope, system context, and evidence sources
  • Assessment approach, assumptions, and limitations
  • Prioritized findings and recommended next steps
Format and handoff

Records are prepared in the formats agreed with your team. The handoff reviews the evidence, assumptions, outstanding actions, and responsible owners. These descriptions illustrate scope; they are not published client work samples.

Deliverables agreed for each engagement.

05 / Physical-AI governance

Deployment and operating risk

Physical-AI governance

Review the machine in its operating environment, including the people responsible for its use.

01 / Before deployment

Deployment readiness

Define the task, operating limits, site constraints, and exception scenarios.

Explore the service

Review routes, surfaces, access restrictions, connectivity, remote access, charging, support ownership, and interactions with people or other equipment. Work with the operator and integrator to document site assumptions, operating limits, foreseeable exceptions, and acceptance requirements.

Engagement outputs

Application and site-readiness review; deployment conditions; open-issue register.

Record

Readiness record · Go / revise / stop decision

02 / At the system boundary

Cyber-physical risk review

Assess how software access, data, and system interfaces could affect the machine’s physical behavior.

Explore the service

Review autonomy permissions, interfaces, remote access, software dependencies, update paths, and the effect of a compromised or incorrect command. Document control ownership and escalation. Coordinate application-engineering and machine-safety evidence with the responsible specialists.

Engagement outputs

Cyber-physical risk scenarios; control and responsibility map; specialist evidence requests.

Record

Risk register · Control & responsibility map

03 / At the human handoff

Oversight & acceptance planning

Establish who can intervene, who handles an exception, and what evidence supports acceptance.

Explore the service

Define operator responsibilities, intervention and escalation arrangements, training evidence, and agreed acceptance criteria. Coordinate review of test records and unresolved exceptions with the OEM, integrator, and operator before the client’s acceptance decision.

Engagement outputs

Oversight plan; acceptance-evidence checklist; exception and handoff records.

Record

Oversight plan · Acceptance & handoff record

04 / Throughout operation

Lifecycle governance

Define how configuration changes, incidents, and service history trigger review during operation.

Explore the service

Establish system and asset records, configuration baselines, maintenance evidence, incident review, and reassessment responsibilities. Define which software, hardware, task, environment, or supplier changes trigger a new review and how unresolved issues reach management.

Engagement outputs

Lifecycle review procedure; change and incident history; recurring governance report.

Record

Asset record · Change & incident history

Governance, integration, and specialist responsibilities

Saguaro’s governance work covers the agreed assessment, requirements, coordination, operating procedures, and evidence. Robotics application and integration work can be scoped alongside it. Machine-safety validation, specialist engineering sign-off, and certification require appropriately qualified parties and defined responsibilities.

Explore robotics applications ↗
06 / SAGUARO
01 / 03
AI GOVERNANCE

Govern the
intelligence.

Risk assessments and governance processes for teams developing, buying, or using AI.

ROBOTICS INTEGRATION

Integrate
the machine.

Application review, integration planning, and deployment support for operators and OEMs.

Explore Saguaro Robotics
SCOPED ENGAGEMENTS

Start small.
Leave with proof.

Begin with a defined use case, agreed deliverables, and a review of the evidence.

Start a conversation