Search Precision Consulting
Type to search · ↑↓ to navigate · Enter to open · Esc to close
Independent AI Review and Governance
Independent AI review
a delivery confidence rating from reviewers who cannot win the fix
An independent AI review tells your board, sponsor or accountable official whether an AI programme or system will deliver the benefit it was funded for, safely, from reviewers with nothing to gain from the answer. Our senior reviewers rate delivery confidence against your adopted standard or a public framework, and every finding is traced to its evidence.
The first conversation is confidential, without obligation and without charge.
This is not a Gateway review. It does not replace a review that a framework requires, and it gives no access to one.
You commission this review, and it is independent of the Digital Transformation Agency's own assurance reviews.
Who is an independent AI review for?
It is for the person who has to answer for an AI system that someone else built: a senior responsible officer, an accountable official, a chief AI officer, a sponsor or an audit and risk committee chair. It is most useful before a decision is locked in.
It fits when:
- a high-risk Commonwealth use case is due for the review the policy requires at least every 12 months;
- a New South Wales system is heading to the AI Review Committee;
- your entity is responding to APRA's letter of April 2026, which found that "assurance practices are not keeping pace" with AI;
- your board wants an external view before it funds the next stage, or a vendor's claims need testing;
- an audit has asked about your AI register, ownership or benefits, as the ANAO's three audits of AI in agencies did.
It does not fit when:
- we designed, built, recovered or operate the system, or people we supplied helped build it. We decline the review;
- you want someone to fix the system and do not need independence. The Stop, Fix or Scale Review is the right door;
- you need a review that a framework requires. That runs through the framework's own process;
- you need certification, which only a certification body can give, or a legal opinion, which is for your counsel.
What do you receive?
A delivery confidence rating, findings traced to their evidence, and recommendations with no Precision work attached. If a fix is needed, you also receive a transition pack that any firm can start from.
- A delivery confidence rating on a defined scale, which the scope sets out with the review method.
- Confidential interviews with the people who sponsor, build, run and use the system.
- Findings on six questions: does the value case still hold; is the data ready; what will it cost to run in production; are the controls adequate; where do people oversee and approve; and has security been scoped. Each finding is traced to its evidence.
- The standard, named: your adopted standard, or a public framework such as the Commonwealth policy, the NSW framework, the APRA letter or the Guidance for AI Adoption.
- Recommendations written to stand without us.
- A transition pack where a fix is needed: the evidence base, the recovery objectives in order, and a short guide organised so another firm can start in days. It is included in every review. What the transition pack holds
How does the review run?
Over two to four weeks, led by a senior reviewer with an engineer for the technical evidence. The statement of work sets out the days each person spends.
Planned elapsed time Two to four weeks
| When | What happens |
|---|---|
| Before it starts | We check the conflict register. The scope names the review lead and the engineer, states that we build AI for other clients and may compete with the supplier whose system is under review, and discloses the fees we have earned from you in the past 24 months. |
| Week 1 | Documents, the business case and the system's evidence; confidential interviews begin. |
| Weeks 2 to 3 | Technical evidence on data, cost to run, controls, human oversight and security scope; interviews completed. |
| Final week | Findings traced to evidence and the rating agreed. A second reviewer who took no part in scoping reads every adverse finding about a system another supplier built. The review lead signs the report, and you receive it with the transition pack where one is needed. |
Two to four weeks is the planned elapsed time from scoping to report. We replace it with measured times as reviews complete.
What does engineer testing add?
Testing shows how the system behaves on your data, beyond what its documents and its builders say. It is available on request, scoped to your system.
Our testing method has not yet run on its first system. Until it has, we lead with the delivery confidence review, and a scope that adds testing says so.
An Independent AI Review with testing adds, to everything above:
- an evaluation harness run on your data: accuracy on an agreed question set, robustness, drift and bias where relevant;
- tests of the agent's permissions and of each point where a person must approve;
- your data flows mapped against what the hosting arrangement claims;
- misuse and prompt injection scenarios at design level, with any penetration testing carried out by a specialist partner under a disclosed subcontract, its fee shown as a separate line;
- a report written for your board, with every finding traced to its evidence and the limits of the testing stated;
- the harness handed over as built and documented, with a fixed period for questions and an optional support retainer;
- for government, inputs to the impact assessment and to any review committee referral.
Before testing starts, the scope names a test environment and an approved data extract, and includes either a cooperation letter from the supplier or a plain statement that the testing is black-box. You confirm in writing that you own, or are authorised to permit testing of, every system in scope, including any hosted by a third party, and you name anything out of bounds. Bias testing uses sensitive information only with your authority, in de-identified form where possible, after a privacy impact assessment.
Planned elapsed time: four to eight weeks. The work is scoped to your system, with any testing partner's fee shown as a separate line.
What standard do you review against?
The standard you have adopted, or a public framework, and the scope names which. We do not review against a standard we wrote unless you have adopted it as your own.
The public frameworks we use include the Guidance for AI Adoption, the Commonwealth policy for the responsible use of AI in government and its technical standard, the NSW AI Assessment Framework, ISO/IEC 42001 and APRA's April 2026 letter. We use our own Consolidated AI Bar as the standard only where you have adopted it, and the scope says so. We give no independent opinion on a governance framework we wrote for you, or on a governance process we run for you.
What happens if the finding is that the system needs fixing?
You choose who fixes it, and it will not be us. After an independent review we do not build, fix or run that system, or a system that replaces it, for 24 months, and the transition pack lets another firm start in days.
The transition pack holds:
- the evidence base behind the findings;
- the recovery objectives, in order;
- a short guide for the firm that takes on the work;
- the testing harness, where we built one.
Which door?
Choose an Independent AI Review if your board, a regulator or an audit committee needs a finding from a reviewer with nothing to gain from it. We cannot win the fix: after the review we do not build, fix or run the system, or a system that replaces it, for 24 months. If a fix is needed, we hand you a transition pack (the evidence, the recovery objectives in order, and the testing harness where we built one) so any firm can start in days.
Choose the Stop, Fix or Scale Review if you want a decision and a path and do not need independence. We say at the start that we would like to lead the fix, and we never describe this review as independent.
Stop, Fix or Scale ReviewHow do you keep a review independent?
By rules we publish and apply to every scope. The scope names the reviewers and engineers, says whether we might compete with the supplier whose system is under review, and discloses the fees we have earned from you.
- We give no independent review of a system we designed, built, recovered or operate, or that people we supplied helped design or build.
- An engineer who has worked on a competing build for you is excluded from the review.
- When we test a system another supplier built, we protect that supplier's confidential information, and the engineers who tested it do not build anything that replaces, competes with or integrates with it for you for 12 months.
- We decline the review where our delivery fees from you over the past 24 months exceed a threshold we set.
- The review lead signs the findings. Neither the firm's owner nor a delivery lead edits them.
- Reviewers' pay and targets do not depend on selling delivery work to the clients they review.
- What a reviewer learns on a review is used only for that review.
Each line above restates one of the fourteen conflict rules we publish and apply to every scope. Read our independence and conflict rules
Can you measure what a vendor's AI has actually delivered?
Yes. An Independent AI Value Review measures what a vendor's AI has delivered against its own business case, with the cost of running it.
Ask us about an Independent AI Value Review, and we will scope it with you.
What happens after the review?
If the system stays in production, Continuous AI Oversight keeps the view current. You receive a quarterly delivery confidence statement for each system, an annual review and reporting to your committee.
Oversight is only for systems we did not design, build, recover or operate, and only where your contract with the supplier gives us the access we need. A named reviewer and engineer work on it each month, over a 12-month term that you can renew.
Fees are scoped to the systems it covers, as a monthly fee agreed before the term starts.
Can your engineers work inside our second or third line?
Yes, on request. APRA expects second line risk management and internal audit to have the capability "to independently assess AI systems", and it expects that capability inside the entity.
Our engineers and evaluation tooling can work inside your team, to your methodology, so the capability stays with you. You receive test design, harness runs on your AI systems, findings drafted for your reviewers, and the harness and training handed to your team. Where you prefer to work through your existing co-source partner, we work as their subcontractor.
A senior reviewer supervises our engineers, and none of them tests a system we designed, built, recovered or operate. Anyone we place inside your audit or risk function takes no part in selecting, evaluating or accepting our work.
The work uses the testing method described above, which has not yet run on its first system, and the scope says so. What engineer testing adds
Fees are by day rate, or in quarterly blocks of days, scoped to your programme of work.
What do you offer government agencies?
A delivery confidence review of a single system, and on request the testing on its own, as an AI System Technical Assessment.
An AI System Technical Assessment is the testing without a delivery confidence rating or advice on the programme's governance: the evaluation harness run on agreed data, the agent's permissions and approval points tested, data flows mapped against the hosting claim, and a technical report with every finding traced to its evidence and the limits of the testing stated. The harness is handed over. We work in your environment by default, and the scope allows for your onboarding time and any clearances you require. It is planned at three to six weeks from data access.
It uses the same testing method, which has not yet run on its first system, and the scope says so.
Where our work defines requirements for a later procurement, we declare our interest in that later work and accept any probity measure you set, including exclusion from it.
Common Questions
The questions we are asked most
How much does an independent AI review cost?
A delivery confidence review of one programme or system is scoped to your situation, and its fee is agreed before work starts. Continuous oversight after a review is a monthly fee, scoped to the systems it covers.
Does this review replace one that a framework requires?
No. It does not replace a review that a framework requires, and it gives no access to one. You commission this review, and it is independent of the Digital Transformation Agency's own assurance reviews.
What is a delivery confidence rating?
It is a reviewer's judgement, on a defined scale, of how likely a programme or system is to deliver the benefit it was funded for, safely, given the evidence at the date of the review. Our report shows the evidence behind each finding, so a committee can see how the rating was reached.
Can you review a system a vendor built?
Yes. Every independent review we do is of a system someone else built. We protect the supplier's confidential information, we say in the scope whether we might compete with that supplier, and testing needs either the supplier's cooperation or a scope stated plainly as black-box.
Will you fix what you find?
No. After an independent review we do not build, fix or run the system, or a system that replaces it, for 24 months. If you want a decision and a path and do not need independence, choose the Stop, Fix or Scale Review at the start.
How is an independent review different from AI governance?
Governance sets the rules for all the AI an organisation runs. A review tests whether one programme or system meets the rules, and whether it will deliver what it was funded for. Many clients need both, and our governance work is described on its own page.
How we work, in writing
Before the decision is locked in.
An independent view is most useful while there is still time to act on it.
The first conversation is confidential, without obligation and without charge.