AI Governance Overview
A worked example: a mid-size APRA-regulated organisation, 30 June 2026.
Governance posture
AI Posture Score
+4 vs last quarter · target 75/100
Agents Inventoried
Estimated 12-15 total · target ≥95% coverage
Shadow AI Detected
ChatGPT, Cursor00
MCP Servers Governed
Cursor MCP ungoverned · target 3
Agents with Named Owner
6 of 8 · target 100%
Audit Readiness
APRA-aligned scoring · target 80/100
Attention required
- 2 shadow AI systems detected without governance controls
- 2 critical compliance findings require immediate remediation
Posture Score Trend
Posture and audit readiness recorded each quarter
| Date | Posture score | Audit readiness |
|---|---|---|
| Sept 25 | 28 | 22 |
| Dec 25 | 34 | 30 |
| Mar 26 | 38 | 35 |
| June 26 | 42 | 38 |
AI Agent Registry (5/8 governed)
View allMicrosoft Copilot M365
Microsoft · IT Operations
Claude (Anthropic) - Legal Team
MCPAnthropic · General Counsel
GitHub Copilot
Microsoft/GitHub · Engineering
Active Findings
View allUnmanaged personal ChatGPT accounts in active use
CPS 234 para 21 (d); APRA Letter to Industry on AI (30 Apr 2026)
Cursor MCP server has read access to credentials in source repositories
CPS 234 para 21 (b); APRA Letter to Industry on AI (30 Apr 2026), IAM for non-human actors
AI inventory incomplete - estimated 30-40% of agents unrecorded
APRA Letter to Industry on AI (30 Apr 2026), AI inventory; CPS 230 para 20-22
Action Plan (7 recommended)
See the reportBring 2 shadow AI systems under governance
Assign an accountable owner, risk-assess each, then approve for sanctioned use or decommission. Ungoverned shadow AI is the single biggest driver of a red posture and the first thing a regulator asks about.
Remediate 2 critical findings
Critical findings represent active control failures. Close each, or formally accept the risk with board sign-off, before the next reporting cycle.
In the full product each action is tracked in the findings register with an owner, status, notes and an append-only audit trail, and the board report shows what is already being worked.
Does it crawl our systems?
No. Your register is populated in a discovery session, by bulk import, or by read-only connectors you authorise. Nothing touches your systems.
Is this AI-generated?
No. Every score and recommendation comes from fixed, auditable rules. Every number traces to a register row you can show an auditor.
How does it stay current?
Every view is dated as-at. A quarterly refresh keeps the register true, and agents connecting via MCP are logged as they act.
This is a worked example. Yours would show your real AI inventory.
Start with the free AI Health Check, or talk to Veyruna about running Oversight for your organisation.