Interactive demo, sample data only

AI Governance Overview

A worked example: a mid-size APRA-regulated organisation, 30 June 2026.

Governance posture

AI Posture Score

42/100

+4 vs last quarter · target 75/100

Agents Inventoried

8

Estimated 12-15 total · target ≥95% coverage

Shadow AI Detected

2

ChatGPT, Cursor00

MCP Servers Governed

1

Cursor MCP ungoverned · target 3

Agents with Named Owner

75%

6 of 8 · target 100%

Audit Readiness

38/100

APRA-aligned scoring · target 80/100

!

Attention required

  • 2 shadow AI systems detected without governance controls
  • 2 critical compliance findings require immediate remediation

Posture Score Trend

Posture and audit readiness recorded each quarter

AI posture score and audit readiness over time, each out of 100.
DatePosture scoreAudit readiness
Sept 252822
Dec 253430
Mar 263835
June 264238

AI Agent Registry (5/8 governed)

View all

Microsoft Copilot M365

Microsoft · IT Operations

HIGHapproved

Claude (Anthropic) - Legal Team

MCP

Anthropic · General Counsel

MEDIUMapproved

GitHub Copilot

Microsoft/GitHub · Engineering

MEDIUMapproved

Active Findings

View all
CRITICAL

Unmanaged personal ChatGPT accounts in active use

CPS 234 para 21 (d); APRA Letter to Industry on AI (30 Apr 2026)

CRITICAL

Cursor MCP server has read access to credentials in source repositories

CPS 234 para 21 (b); APRA Letter to Industry on AI (30 Apr 2026), IAM for non-human actors

HIGH

AI inventory incomplete - estimated 30-40% of agents unrecorded

APRA Letter to Industry on AI (30 Apr 2026), AI inventory; CPS 230 para 20-22

Action Plan (7 recommended)

See the report
IMMEDIATE

Bring 2 shadow AI systems under governance

Assign an accountable owner, risk-assess each, then approve for sanctioned use or decommission. Ungoverned shadow AI is the single biggest driver of a red posture and the first thing a regulator asks about.

IMMEDIATE

Remediate 2 critical findings

Critical findings represent active control failures. Close each, or formally accept the risk with board sign-off, before the next reporting cycle.

In the full product each action is tracked in the findings register with an owner, status, notes and an append-only audit trail, and the board report shows what is already being worked.

Does it crawl our systems?

No. Your register is populated in a discovery session, by bulk import, or by read-only connectors you authorise. Nothing touches your systems.

Is this AI-generated?

No. Every score and recommendation comes from fixed, auditable rules. Every number traces to a register row you can show an auditor.

How does it stay current?

Every view is dated as-at. A quarterly refresh keeps the register true, and agents connecting via MCP are logged as they act.

This is a worked example. Yours would show your real AI inventory.

Start with the free AI Health Check, or talk to Veyruna about running Oversight for your organisation.