Staff are pasting documents into ChatGPT and procurement teams are signing AI vendor contracts — right now, without a framework to catch what goes wrong. Quorum builds the governance structure first, so you're not explaining an incident to Council, Parliament, or a portfolio committee after the fact.
By the time it reaches a council meeting or a board agenda, it's not a pilot anymore — it's an incident.
AI tools get bundled into software renewals without anyone reviewing data handling, model training use, or where the processing actually happens.
Feeding constituent, student, or personnel data into third-party models is a data protection question — one most institutions haven't formally answered.
"Public body had no AI policy" is a headline. Being the institution with a documented, defensible framework changes that story entirely.
We map every AI tool currently in use across your institution — sanctioned or not — and score your exposure against procurement, data protection, and policy gaps. You leave with a prioritised risk register, not a generic checklist.
Policy, approval workflows, and an acceptable-use standard written for your actual departments — procurement, legal, IT, HR — not adapted from a template built for a private company.
New tools, new risks, new regulation. A retainer keeps the framework current and puts a practitioner on call when a department wants to adopt something new.
Eight questions, drawn from the same framework we use on engagements. Score each honestly — 1 means it doesn't exist, 5 means it's documented, owned, and reviewed.
"The gap isn't that public institutions don't want AI governance. It's that nobody's shown up who's actually built one — inside an institution, under the same constraints they're working with."