Make ownership explicit
Define who can approve, operate, challenge and retire AI systems instead of leaving accountability between functions.
Practical operating models, risk decisions and lifecycle controls for Australian organisations using AI, with support for global operations where required.
Define who can approve, operate, challenge and retire AI systems instead of leaving accountability between functions.
Create an inventory and classification method that covers internally built systems, embedded features and third-party services.
Match assessment, testing, human oversight and monitoring requirements to the context and potential impact of each use case.
Build records, review triggers, incidents and change management into the lifecycle so governance continues after approval.
Portfolio-level accountability and system-level controls need to connect, but they solve different governance problems.
For organisations that need clear accountability, decision rights, policies, inventory, risk tiers and portfolio oversight.
For teams that need a practical assessment and evidence pattern from design and procurement through deployment and review.
Set accountability, risk appetite and decision forums that connect AI ambition with existing enterprise governance.
Translate governance expectations into usable design, testing, release and monitoring practices.
Create a shared evidence model across data, cyber, privacy, procurement, compliance and responsible AI concerns.
The work can focus on an enterprise operating model, a specific AI system or the interface between both.
Place AI decisions inside a governance structure people can actually use.
Create visibility across the AI systems the organisation builds, buys and enables.
Assess each use case in its real context rather than through a generic technology checklist.
Define controls that can be implemented and evidenced by delivery teams.
Treat supplier AI capability as part of the organisation’s risk surface.
Keep the governance system useful as AI capability, use and risk change.
Scoping starts with the AI estate, stakeholders, current governance foundations and the decision or assurance gap that is creating risk.
Fedorai founder Arafat Tehsin combines solution architecture, applied AI leadership and hands-on delivery experience. That technical grounding helps translate governance expectations into controls, evidence and operating decisions delivery teams can apply.
About Arafat and FedoraiThe work can map to relevant organisational and jurisdictional needs, including concepts from NIST AI RMF, ISO/IEC 42001 and Australia’s Guidance for AI Adoption. The final framework set is confirmed during scoping rather than imposed as a universal checklist.
No. Fedorai helps organisations design governance operating models, technical controls and evidence practices. Legal interpretation, regulatory opinions and formal certification remain with appropriately qualified legal, compliance and certification professionals.
Yes. The preferred approach is to connect AI governance to existing enterprise risk, security, privacy, procurement, model risk, product and change-management practices where those foundations are effective.
No. The operating model can cover predictive, decision-support, generative and agentic AI systems. Specific controls are tailored to the system type, context, users and potential impacts.
Yes. A system-level engagement can examine the use case, stakeholders, data, suppliers, model behaviour, human oversight, security, testing, monitoring and evidence before a major release or governance decision.
A focused system review or governance design sprint can be relatively short. An enterprise operating model involving multiple functions, policies and portfolio processes takes longer. Scope and sequence are agreed after the current state and decision need are understood.