Loading...
AI Security Engineering / Pillar
Governance and policy frameworks for organisations deploying AI into regulated environments — before the audit finds the gaps. ISO 42001, NIST AI RMF, and NZISM alignment.
Definition. AI governance is the practice of establishing organisational policies, risk frameworks, accountability structures, and control catalogues that make AI deployment defensible to boards, regulators, and internal audit. It is not a single document; it is a working programme aligned to recognised standards like ISO/IEC 42001, NIST AI RMF, and — for NZ organisations — NZISM and the Privacy Act 2020.
In 2025 the AI cybersecurity market reached US$31.48B, projected to hit US$93.75B by 2030 (AI Security Intelligence, Q1 2026). 51% of enterprises now deploy security AI and automation. 89% expect higher AI spending next year. Organisations that fail to govern shadow AI face an average penalty of US$670,000 in increased breach costs (IBM 2025).
The regulatory landscape is catching up. ISO/IEC 42001 (AI Management Systems) is now the recognised international standard. The EU AI Act is enforceable. NIST AI RMF is widely referenced by NZ and AU regulators. The NZ Privacy Commissioner has published expectations for AI use of personal information. Waiting for a specific regulator to name the requirement is not a defensible strategy.
CyberTeam builds AI governance frameworks that are actually operable — not shelfware. Every deliverable is tested against a real business scenario before you sign it off.
Framework
An AI governance framework is not a single standard — it is a mapping across multiple frameworks so each stakeholder can find their reference:
Deliverables
A full governance engagement produces the following artefacts, each tested against a live scenario before sign-off:
Approach
Governance work is often shelfware. Ours is not. Three principles drive the engagement:
For most NZ organisations in 2026, alignment is sufficient. Certification pathways are still maturing and the certification cost is significant. Alignment gives you the same governance rigour and satisfies most regulators, boards, and customers today. If a specific tender or contract requires certification, we help you get there — but we will not push certification for its own sake.
ISO 27001 and NZISM cover information security management but do not adequately address AI-specific risks like model bias, hallucination, or agent autonomy. AI governance extends your existing programme rather than replacing it. CyberTeam builds the extension so certifications and accreditations are preserved.
A framework build from a low starting point takes 8-12 weeks. If you have existing information security governance we can extend, 4-6 weeks is realistic. The board-reporting rhythm and policy sign-off cycle typically extend into the following quarter, but the deliverable is ready before then.
Ownership varies. In organisations with a CISO, the AI governance function reports there. In organisations with a Chief Data Officer or CIO, it often reports there. In smaller organisations, the CFO or COO holds it as part of enterprise risk. CyberTeam helps you decide the right ownership model for your governance architecture — this is one of the first decisions in the engagement.
Yes. Third-party AI is often the biggest exposure — you inherit their controls, their data handling, and their model behaviour. Vendor AI assessment (Microsoft 365 Copilot, GitHub Copilot, OpenAI Enterprise, Anthropic Claude Enterprise) is a standard component of an AI governance engagement.
A 30-minute conversation gives you a clear view of where your AI governance sits against ISO 42001, NIST AI RMF, and NZISM, and what a framework build would look like for your organisation.
Talk to Tom