GOVERNANCE

Governance that runs with the work.

Most governance is written down and then left behind. APIP runs it as a working system — controls applied as work happens, intelligence on how it really flows, and evidence that is ready before anyone asks.

MODULES

Six parts of a governance system

Each one stands on its own. Together they form the governance layer inside APIP.

CONTROLS

Control library

Policies, standards and obligations written once as machine-readable rules, then applied to every case as it runs — not sampled months later.

  • Rule-based checks
  • Severity and ownership
  • Versioned change history
INTELLIGENCE

Process intelligence

See how work actually flows: hand-offs, waiting time, rework and the exceptions that quietly drive cost and risk.

  • Variant analysis
  • Bottleneck scoring
  • SLA and breach tracking
ASSURANCE

Assessment overlays

Score maturity against COBIT and ITIL against your real processes, so an assessment reflects the work rather than a workshop.

  • Current vs target levels
  • Risk ratings
  • Named owners
AI

Human-approved AI

AI drafts the summary, the cause and the improvement. A person approves it. Nothing unapproved reaches a report.

  • Confidence-rated suggestions
  • Review queue
  • Full decision trail
AUTOMATION

Governed automation

Trigger the next step in the tools your teams already use, with every run logged against the rule that fired it.

  • Event triggers
  • Conditional actions
  • Run history
EVIDENCE

Reporting and evidence

One document with live figures, open exceptions and approved insights attached — ready for a board, a regulator or an auditor.

  • Live metrics
  • Attached evidence
  • Export and share
INSIGHTS

Practical thinking on governance and AI

Short, useful writing from the AGS team on how governance, automation and process intelligence work in real organisations — including where they go wrong.

GOVERNANCE

Governance is a system, not a document

Why policy libraries fail and what happens when controls are wired into the flow of work instead.

August 2026

AI

Human-in-the-loop is not a nice-to-have

How to use AI in governance work without surrendering judgement, accountability, or the audit trail.

July 2026

PRODUCTIVITY

The hidden cost of the approval chain

Most productivity loss is not effort — it is waiting. A practical method for finding and fixing the queues.

July 2026

PROCESS

Map what happens, not what should happen

Process mapping only pays off when it captures the workarounds. Here is how to get honest input.

June 2026

GROWTH

Scaling without importing chaos

What to standardise, what to leave local, and how to tell the difference before it costs you.

June 2026

EDUCATION

Teaching process intelligence in plain English

A teaching sequence that gets students from flowcharts to genuine systems thinking in six sessions.

May 2026

LIVE REGISTERS

Policies, standards, risks and owners

A working example of the governance registers APIP keeps: every standard traces to a policy, every risk to an owner, and every entry to a named person accountable for it.

6

Policies

8

Standards

8

Open risks

5

Named owners

Policy register

POL-001SecurityActive

Information Security Policy

Sets the baseline expectations for protecting systems and information across every service, supplier and device.

Owner: Tom Callaghan · Review due 2027-03-31

POL-002PrivacyActive

Data Protection & Privacy Policy

Defines lawful basis, retention, subject rights handling and breach reporting under UK GDPR.

Owner: Greg Mensah · Review due 2027-01-31

POL-003AIActive

AI Use & Human Oversight Policy

Requires every AI-assisted decision to be confidence-rated, reviewed by a named person and logged.

Owner: Priya Raman · Review due 2026-12-31

POL-004OperationsUnder review

Process Change Control Policy

Controls how a live process may be changed, who approves it, and what evidence is kept.

Owner: Sian Roberts · Review due 2026-11-30

POL-005Supply chainActive

Third Party & Supplier Assurance Policy

Sets due diligence, contractual control and ongoing monitoring expectations for suppliers.

Owner: Priya Raman · Review due 2027-06-30

POL-006AssuranceDraft

Records & Evidence Retention Policy

States what evidence must be retained for each controlled process and for how long.

Owner: Dr Amina Yusuf · Review due 2027-02-28

Standards

RefStandardControl statementFrameworkPolicyOwner
STD-001Access Control StandardAccess is granted by role, reviewed quarterly, and removed within one working day of a leaver being confirmed.ISO 27001 A.5.15POL-001Tom Callaghan
STD-002Encryption StandardAll personal and commercially sensitive data is encrypted in transit and at rest using approved algorithms.ISO 27001 A.8.24POL-001Tom Callaghan
STD-003Subject Rights Response StandardData subject requests are acknowledged within three working days and answered within one calendar month.UK GDPR Art. 12POL-002Greg Mensah
STD-004AI Review StandardNo AI-generated insight is published until a named reviewer approves it; the decision trail is retained.ISO 42001 8.3POL-003Priya Raman
STD-005Process Change Evidence StandardEvery change to a governed process records the requester, approver, rationale and effective date.COBIT BAI06POL-004Sian Roberts
STD-006Supplier Assurance StandardCritical suppliers are assessed before onboarding and re-assessed annually against agreed controls.ISO 27001 A.5.19POL-005Priya Raman
STD-007Incident Reporting StandardReportable incidents reach the accountable owner within one hour of detection.ITIL Incident ManagementPOL-001Tom Callaghan
STD-008Audit Evidence StandardControl evidence is captured automatically at the point of work rather than assembled retrospectively.COBIT MEA02POL-006Dr Amina Yusuf

Risk register

RSK-001AIMonitoring

Unreviewed AI output reaches a report

An AI-drafted insight is published without human approval, weakening the audit trail.

Score 10 (L2 × I5) · mitigate

Owner: Priya Raman · Policy POL-003

RSK-002SecurityOpen

Leaver access not removed promptly

Departing staff retain system access beyond their last working day.

Score 12 (L3 × I4) · mitigate

Owner: Tom Callaghan · Policy POL-001

RSK-003PrivacyMonitoring

Subject access request missed

A request is not logged centrally and the statutory deadline passes.

Score 8 (L2 × I4) · mitigate

Owner: Greg Mensah · Policy POL-002

RSK-004OperationsOpen

Undocumented process change

A team changes a live process locally without approval, and the control no longer applies.

Score 12 (L4 × I3) · mitigate

Owner: Sian Roberts · Policy POL-004

RSK-005Supply chainOpen

Critical supplier fails a control

A supplier degrades below agreed control levels between annual assessments.

Score 12 (L3 × I4) · transfer

Owner: Priya Raman · Policy POL-005

RSK-006AssuranceMonitoring

Evidence cannot be produced at audit

Evidence for a controlled process is incomplete when an auditor asks for it.

Score 10 (L2 × I5) · mitigate

Owner: Dr Amina Yusuf · Policy POL-006

RSK-007OperationsOpen

Backlog hides an SLA breach

Waiting time inside a hand-off is not visible until the service level is already missed.

Score 12 (L4 × I3) · mitigate

Owner: Sian Roberts · Policy POL-004

RSK-008PrivacyOpen

Shadow tooling holds personal data

Teams adopt an unapproved tool that stores personal data outside the retention schedule.

Score 15 (L3 × I5) · avoid

Owner: Greg Mensah · Policy POL-002

Accountable owners

Dr Amina Yusuf

Director of Clinical Governance

Operations

1 policies · 1 risks

Greg Mensah

Data Protection Officer

Legal

1 policies · 2 risks

Priya Raman

Chief Risk Officer

Risk & Compliance

2 policies · 2 risks

Sian Roberts

Head of Process Excellence

Transformation

1 policies · 2 risks

Tom Callaghan

Head of Information Security

Technology

1 policies · 1 risks

See governance working inside APIP

Watch the step-by-step walkthrough of the platform these modules run on.

Explore APIP →