An honest account of the AI already running in your business, including the parts nobody approved, scored against the TAG control catalogue.
Four rungs. Where a deployment sits decides how far a failure travels, and it is the first thing an assessment establishes.
AI is running. Nobody can say what it touches, what it costs, or who approved it.
Boundaries exist, but the content flowing through them is still trusted implicitly.
Actions are attributable. Limits are enforced, and a named person owns them.
Evidenced against the full catalogue, and defensible to a regulator or a client.
A system can look like Rung 3 and behave like Rung 1. Finding that gap is what the assessment is for, and it is why the ladder is established before a single control is designed.
Rung 4 describes a state your systems reach, evidenced against the catalogue. It is not a certification, and Tech Sight does not issue one.
Does this system do what the organisation actually decided it should?
What stops it, and has that stop ever been tested under load?
Would you know if it were wrong, and how long would that take?
Who is accountable, and what authority do they actually hold?
The catalogue grew from 46 controls to 57 across two ratified amendments. Each one is traceable to a specific event, not to a framework release.
Two hours, scored against the same catalogue. The output is a written scorecard you keep, and it becomes the proposal for whatever comes next.