Agentic AI Governance
for Established Businesses
Once AI agents can send messages, query data or change company systems, policy and engineering have to agree. We map authority, ownership and evidence, then put the controls into the workflows themselves.
Agent asks to act
Rules are checked
Action is logged
You can see who allowed each action and why.
Named
OWNERS FOR AGENTS AND ACTIONS
Limited
ACCESS MATCHED TO THE TASK
Recorded
TESTS, APPROVALS AND CHANGES
Governance changes when AI can take action
An assistant that drafts a message and an agent that sends it need different controls. Authority depends on the tools, credentials and approval steps the application provides.
A general AI policy may cover staff use of public chat tools. It rarely defines how an agent gets production access, which actions need approval or who reviews failures.
Anything that can act on your behalf needs a policy, the permissions, and logs.
ASSISTIVE AI
- Suggests, a human acts
- Impact depends on the data and output
- Human review required before use
- Usage policy and data controls
- Review when use or data changes
AGENTIC AI
- Acts within granted permissions
- Impact depends on tool authority
- Mistake hits customers in seconds
- Needs policy, permissions, evals, logs
- Risk reviewed each time it changes
Where agent access goes wrong
These risks come from the OWASP Top 10 for Agentic Applications and published incidents. We use them to test the access, controls and records around each live agent.
Prompt injection
Instructions hidden in an email, PDF or web page can influence the agent. We test how untrusted content is handled and what actions remain possible if the model follows it.
Excessive agency
An agent's service account may have wider permissions than its task needs. We check database, payment and deployment access and separate duties where appropriate.
Tool misuse
Individually permitted tools can combine into an unsafe action. Tests need to cover recipients, data selection and approval of the final operation.
No observability
Without records of inputs, tool calls and outcomes, an owner may be unable to explain or investigate an action. Logging needs enough detail for review and an appropriate retention policy.
Shadow agents
Staff-built automations and personal AI accounts can gain operational access without appearing in an IT register. Discovery combines technical records with staff input within the agreed scope.
Standards relevant to business agent systems
The applicable standard depends on the system, data, sector and territories involved. We map each agent to the useful controls below and record which decisions still belong with your security, privacy and legal teams.
NCSC Guidelines for Secure AI System Development
NCSC guidance covers secure design, development, deployment and operation of AI systems.
DSIT AI Cyber Security Code of Practice
The DSIT code of practice, published in January 2025, provides voluntary security principles for organisations developing and using AI systems.
NIST AI RMF 1.0 + GenAI Profile
NIST AI RMF structures work around Govern, Map, Measure and Manage. Its Generative AI Profile adds relevant risks and suggested actions.
ISO/IEC 42001:2023
ISO/IEC 42001 specifies requirements for an AI management system. Whether certification is worthwhile depends on the organisation's assurance needs and obligations.
OWASP Top 10 for Agentic Applications
The OWASP Agentic Top 10, published in December 2025, provides categories for assessing agent-specific security risks.
EU AI Act (and what touches you)
Prohibited-practice rules have applied since February 2025 and provider obligations for general-purpose AI models since August 2025. We establish whether the business is acting as a provider, deployer or both before mapping the relevant duties.
We use the linked frameworks to support the assessment. Legal interpretation and acceptance of remaining risk stay with your responsible owners.
What the review gives you
We map the agents in scope, document their permitted actions and review how the application enforces those limits.
Each phase has agreed coverage, outputs and timing. You retain the resulting documents and custom code.
BOOK A GOVERNANCE CALLAgent inventory and risk map
We inventory agents found within the agreed teams and technical estate, recording their data, credentials, actions and owners. Any gaps in discovery are made explicit.
Policy people will follow
A usable policy covering what agents may do, which actions require approval, who can authorise a new agent and what must be logged. It is aligned to the controls relevant to your systems and written for the teams expected to follow it.
Guardrails in the code
Task-specific permissions, server-side tool validation, approval checks and limits on spending and request volume. Filtering untrusted content can help, but cannot replace those controls.
Evals, logs, red-team
A repeatable test suite for each agent: does it still refuse the things it should refuse, after every prompt change. Full traces of every prompt, tool call and decision in a searchable log. One round of adversarial testing before go-live. You leave with an audit trail you can show a customer, a regulator or your insurer.
Raq.com is our live governance environment
It coordinates people and agents through explicit accounts, tools, permissions and records. We use it to run real work, which exposes the operational governance problems that a policy document alone will miss.
When this is worth discussing
We work best when there is a real operating problem, enough volume to measure and people from the affected teams who can make decisions.
Usually a good fit
- An established UK business, usually with annual revenue above £10m
- A repeated process with a known cost, delay, error rate or capacity problem
- A senior sponsor and a day-to-day owner who understand the work
- Access to the relevant staff, systems, sample records and security requirements
We may point you elsewhere
- A standard product already covers the process well
- The requirement is a one-off small build with no wider operating case
- There is no owner or access to the people and data needed to test the result
- The plan relies on AI making high-impact decisions with nobody responsible for review
Questions from IT, legal and compliance
We're 30 people. Isn't this overkill?
The governance should match the agent's authority, data and possible impact. A business needs to know which credentials each agent holds, what actions it may take, who approved that access and how an incident would be detected and stopped.
Does the EU AI Act apply to us?
It depends on where the system is placed, used and what decisions it supports. We map the role of your business and the use case before stating which obligations apply. Legal interpretation remains with your legal adviser.
Do we need ISO/IEC 42001?
Certification may help with customer requirements, procurement or internal assurance. We assess those needs before recommending it. An engineering review can support the evidence but cannot certify your organisation.
What's the difference between governance and security?
Governance assigns responsibility and decides permitted uses. Security helps enforce those decisions and protect the system. The review connects policy, permissions, testing and incident response.
What about agents staff are using on their own accounts?
We include staff-built tools within the agreed discovery scope, explain permitted use and record identified accounts and integrations. Personal-account access and employee privacy boundaries are agreed before collection.
How long does it take and what does it cost?
Inventory and accountability come first. The timetable then depends on the number of agents, connected systems, decision risk and evidence required by technology, compliance or internal audit.
We haven't deployed any agents yet. Too early?
It's a good moment to start. Adding access rules, logging and evaluations before the first launch is usually simpler than reconstructing them around a live workflow. We set up reusable patterns without pretending every later agent will have the same risk.
Talk to us about agent governance
Tell us what the agents can read, decide and change today, plus what is due to launch next. We will identify the governance decisions and technical evidence needed before wider use.