AI Governance-as-a-Service

Someone in your legislature is already using AI.

Staff are pasting documents into ChatGPT and procurement teams are signing AI vendor contracts — right now, without a framework to catch what goes wrong. Quorum builds the governance structure first, so you're not explaining an incident to Council, Parliament, or a portfolio committee after the fact.

Built for government departments & legislative bodies — SA, UK & Commonwealth
LIVE GOVERNANCE LEDGER FRAMEWORK v2.1
What's actually at stake

Unmanaged AI adoption doesn't stay small.

By the time it reaches a council meeting or a board agenda, it's not a pilot anymore — it's an incident.

01 — Procurement

Vendor risk nobody signed off on

AI tools get bundled into software renewals without anyone reviewing data handling, model training use, or where the processing actually happens.

02 — Compliance

POPIA exposure, unassessed

Feeding constituent, student, or personnel data into third-party models is a data protection question — one most institutions haven't formally answered.

03 — Reputation

The story writes itself if you're last

"Public body had no AI policy" is a headline. Being the institution with a documented, defensible framework changes that story entirely.

How it works

Three stages. Not a slide deck — a working framework.

STAGE 1
Assess

AI Readiness Audit

We map every AI tool currently in use across your institution — sanctioned or not — and score your exposure against procurement, data protection, and policy gaps. You leave with a prioritised risk register, not a generic checklist.

STAGE 2
Implement

Governance framework build

Policy, approval workflows, and an acceptable-use standard written for your actual departments — procurement, legal, IT, HR — not adapted from a template built for a private company.

STAGE 3
Sustain

Standing governance retainer

New tools, new risks, new regulation. A retainer keeps the framework current and puts a practitioner on call when a department wants to adopt something new.

Score yourself

How exposed is your institution, right now?

Eight questions, drawn from the same framework we use on engagements. Score each honestly — 1 means it doesn't exist, 5 means it's documented, owned, and reviewed.

01 — Data ownership
Every data source AI might touch has a named owner who can approve or deny its use.
NonexistentFully owned
02 — Classification
Information is labelled public, internal, confidential, or restricted before any AI tool can reach it.
NonexistentFully classified
03 — Access model
AI agents and connectors respect existing least-privilege permissions — nobody's built a "super-agent" account.
No controlFully enforced
04 — Approved truth
There's a defined, versioned set of sources AI is allowed to draw answers from — not "whatever it finds."
UndefinedFully defined
05 — Human authority
Finance, HR, legal, and security actions require named human approval before AI-recommended action executes.
No gateAlways required
06 — Audit trail
Every AI-assisted request, decision, and action is logged well enough to reconstruct what happened, and why.
No logFull chain
07 — Change control
Changes to prompts, models, connectors, or policy go through a tested, approved, and reversible process.
Ad hocFully controlled
08 — Ongoing review
Someone owns a recurring review of accuracy, incidents, and adoption — this isn't a one-time policy document.
Nobody owns itOwned & recurring
—/40
Answer all eight to see your score
This is a directional read, not an audit — it takes two minutes and shows you where a real assessment would start.
Nothing is sent until you click through — this stays on your screen until then.
Pricing

Fixed-scope engagements. No open-ended hours.

Assessment
From R45,000
A defensible starting point — know your exposure before anyone asks.
  • Full AI tool & shadow-IT audit
  • Risk register, ranked by exposure
  • Procurement & POPIA gap review
  • Findings presentation to leadership
Start with an audit
Retainer
From R18,000/mo
Ongoing coverage as tools, staff, and regulation change.
  • Quarterly framework review
  • New tool & vendor risk sign-off
  • Direct line to a governance practitioner
  • Regulatory update briefings
Discuss a retainer
Pricing shown in ZAR for SA public-sector clients. UK & Commonwealth engagements quoted in GBP on request.

"The gap isn't that public institutions don't want AI governance. It's that nobody's shown up who's actually built one — inside an institution, under the same constraints they're working with."

— the reasoning behind Quorum
PRACTITIONER
Senior IT professional inside a provincial legislative body — where this framework was designed and implemented first, not sold first.
CASE IN POINT
Applied inside a sitting legislature: [add your metric here — e.g. "cut AI-tool review time from weeks to days" or "closed X unsanctioned AI tools in the first audit"].
MARKETS
Government departments and legislative bodies across South Africa, the United Kingdom, and Commonwealth markets.
Get started

Find out what your institution doesn't know about its own AI use.

No obligation. A 20-minute scoping call, not a sales pitch.