Stage 2 of the method

AI Audit

“Audit” is used here in its ordinary technical sense, as in a security audit or a code audit. An AI Audit by Tech Sight (Pty) Ltd is a technical assessment of deployed AI systems: what they can do, what they can spend, and what controls exist. It is not an audit as defined in the Auditing Profession Act 26 of 2005. It is not a financial audit, an independent review, or any other assurance engagement, and it produces no audit opinion and no assurance conclusion. Tech Sight (Pty) Ltd is not registered with the Independent Regulatory Board for Auditors (IRBA), is not a firm of registered auditors, and does not hold itself out as one.

An honest account of the AI already running in your business, including the parts nobody approved, scored against the TAG control catalogue.

The Blast Radius Ladder

Four rungs. Where a deployment sits decides how far a failure travels, and it is the first thing an assessment establishes.

Rung 1

Ungoverned

AI is running. Nobody can say what it touches, what it costs, or who approved it.

Rung 2

Scoped

Boundaries exist, but the content flowing through them is still trusted implicitly.

Rung 3

Identity-governed

Actions are attributable. Limits are enforced, and a named person owns them.

Rung 4

Framework-certified

Evidenced against the full catalogue, and defensible to a regulator or a client.

A system can look like Rung 3 and behave like Rung 1. Finding that gap is what the assessment is for, and it is why the ladder is established before a single control is designed.

Rung 4 describes a state your systems reach, evidenced against the catalogue. It is not a certification, and Tech Sight does not issue one.

What you receive

  • An inventory of the AI actually in use, including the tools nobody registered.
  • A score against 57 controls across fourteen domains, with your rung determined.
  • Findings ranked by blast radius, each with a recommended remediation and an effort estimate.
  • A prioritised roadmap to the next rung: what to fix first, what to document, what to stop.
57controls assessed
14domains
9veto-class controls

Four pillars

Alignment

Does this system do what the organisation actually decided it should?

Guardrails

What stops it, and has that stop ever been tested under load?

Telemetry

Would you know if it were wrong, and how long would that take?

Oversight Core

Who is accountable, and what authority do they actually hold?

The catalogue grew from 46 controls to 57 across two ratified amendments. Each one is traceable to a specific event, not to a framework release.

Start with the diagnostic

Two hours, scored against the same catalogue. The output is a written scorecard you keep, and it becomes the proposal for whatever comes next.

Book the two-hour diagnostic