Control library
Policies, standards and obligations written once as machine-readable rules, then applied to every case as it runs — not sampled months later.
- Rule-based checks
- Severity and ownership
- Versioned change history
Most governance is written down and then left behind. APIP runs it as a working system — controls applied as work happens, intelligence on how it really flows, and evidence that is ready before anyone asks.
Each one stands on its own. Together they form the governance layer inside APIP.
Policies, standards and obligations written once as machine-readable rules, then applied to every case as it runs — not sampled months later.
See how work actually flows: hand-offs, waiting time, rework and the exceptions that quietly drive cost and risk.
Score maturity against COBIT and ITIL against your real processes, so an assessment reflects the work rather than a workshop.
AI drafts the summary, the cause and the improvement. A person approves it. Nothing unapproved reaches a report.
Trigger the next step in the tools your teams already use, with every run logged against the rule that fired it.
One document with live figures, open exceptions and approved insights attached — ready for a board, a regulator or an auditor.
Short, useful writing from the AGS team on how governance, automation and process intelligence work in real organisations — including where they go wrong.
Why policy libraries fail and what happens when controls are wired into the flow of work instead.
August 2026
How to use AI in governance work without surrendering judgement, accountability, or the audit trail.
July 2026
Most productivity loss is not effort — it is waiting. A practical method for finding and fixing the queues.
July 2026
Process mapping only pays off when it captures the workarounds. Here is how to get honest input.
June 2026
What to standardise, what to leave local, and how to tell the difference before it costs you.
June 2026
A teaching sequence that gets students from flowcharts to genuine systems thinking in six sessions.
May 2026
A working example of the governance registers APIP keeps: every standard traces to a policy, every risk to an owner, and every entry to a named person accountable for it.
6
Policies
8
Standards
8
Open risks
5
Named owners
Sets the baseline expectations for protecting systems and information across every service, supplier and device.
Owner: Tom Callaghan · Review due 2027-03-31
Defines lawful basis, retention, subject rights handling and breach reporting under UK GDPR.
Owner: Greg Mensah · Review due 2027-01-31
Requires every AI-assisted decision to be confidence-rated, reviewed by a named person and logged.
Owner: Priya Raman · Review due 2026-12-31
Controls how a live process may be changed, who approves it, and what evidence is kept.
Owner: Sian Roberts · Review due 2026-11-30
Sets due diligence, contractual control and ongoing monitoring expectations for suppliers.
Owner: Priya Raman · Review due 2027-06-30
States what evidence must be retained for each controlled process and for how long.
Owner: Dr Amina Yusuf · Review due 2027-02-28
| Ref | Standard | Control statement | Framework | Policy | Owner |
|---|---|---|---|---|---|
| STD-001 | Access Control Standard | Access is granted by role, reviewed quarterly, and removed within one working day of a leaver being confirmed. | ISO 27001 A.5.15 | POL-001 | Tom Callaghan |
| STD-002 | Encryption Standard | All personal and commercially sensitive data is encrypted in transit and at rest using approved algorithms. | ISO 27001 A.8.24 | POL-001 | Tom Callaghan |
| STD-003 | Subject Rights Response Standard | Data subject requests are acknowledged within three working days and answered within one calendar month. | UK GDPR Art. 12 | POL-002 | Greg Mensah |
| STD-004 | AI Review Standard | No AI-generated insight is published until a named reviewer approves it; the decision trail is retained. | ISO 42001 8.3 | POL-003 | Priya Raman |
| STD-005 | Process Change Evidence Standard | Every change to a governed process records the requester, approver, rationale and effective date. | COBIT BAI06 | POL-004 | Sian Roberts |
| STD-006 | Supplier Assurance Standard | Critical suppliers are assessed before onboarding and re-assessed annually against agreed controls. | ISO 27001 A.5.19 | POL-005 | Priya Raman |
| STD-007 | Incident Reporting Standard | Reportable incidents reach the accountable owner within one hour of detection. | ITIL Incident Management | POL-001 | Tom Callaghan |
| STD-008 | Audit Evidence Standard | Control evidence is captured automatically at the point of work rather than assembled retrospectively. | COBIT MEA02 | POL-006 | Dr Amina Yusuf |
An AI-drafted insight is published without human approval, weakening the audit trail.
Score 10 (L2 × I5) · mitigate
Owner: Priya Raman · Policy POL-003
Departing staff retain system access beyond their last working day.
Score 12 (L3 × I4) · mitigate
Owner: Tom Callaghan · Policy POL-001
A request is not logged centrally and the statutory deadline passes.
Score 8 (L2 × I4) · mitigate
Owner: Greg Mensah · Policy POL-002
A team changes a live process locally without approval, and the control no longer applies.
Score 12 (L4 × I3) · mitigate
Owner: Sian Roberts · Policy POL-004
A supplier degrades below agreed control levels between annual assessments.
Score 12 (L3 × I4) · transfer
Owner: Priya Raman · Policy POL-005
Evidence for a controlled process is incomplete when an auditor asks for it.
Score 10 (L2 × I5) · mitigate
Owner: Dr Amina Yusuf · Policy POL-006
Waiting time inside a hand-off is not visible until the service level is already missed.
Score 12 (L4 × I3) · mitigate
Owner: Sian Roberts · Policy POL-004
Teams adopt an unapproved tool that stores personal data outside the retention schedule.
Score 15 (L3 × I5) · avoid
Owner: Greg Mensah · Policy POL-002
Director of Clinical Governance
Operations
1 policies · 1 risks
Data Protection Officer
Legal
1 policies · 2 risks
Chief Risk Officer
Risk & Compliance
2 policies · 2 risks
Head of Process Excellence
Transformation
1 policies · 2 risks
Head of Information Security
Technology
1 policies · 1 risks
Watch the step-by-step walkthrough of the platform these modules run on.