Independent · ISSO-grade · Vendor-neutral

Governed Architecture Review

An independent read of whether your AI system's control architecture actually holds at runtime. Where the design lets the AI act beyond its authority, where the human gates are missing, and whether every consequential action leaves evidence you can defend a year from now.

By William J. Storey III · 17-year U.S. Army information systems security officer · builder of the GIA runtime-governance platform.

What I look at

Four questions your architecture has to answer.

Not a code audit and not a model evaluation. A senior read of the control design, at the layer between a decision and its execution, where accountability actually lives.

01 · AUTHORITY

Where can it exceed authority?

Tool permissions, delegation rights, data access, destructive actions, and spend. The places the agent can act beyond what it was ever granted.

02 · GATES

Where are the gates?

Which actions pause for a human, whether the approval is enforced or decorative, and whether escalation reaches the right person in time or is review theater.

03 · EVIDENCE

Can it be proven?

Whether consequential actions leave a record that is tamper-evident, reconstructable, and defensible long after the fact, not just a log that can be edited.

04 · FAILURE

How does it fail?

What happens when a control, an approver, or the evidence service is unavailable. Fail-open or fail-closed, and whether that was a decision or an accident.

Engagements

Three ways to have it reviewed.

You get the verdict and the fix path, delivered as a written findings report. Your source and your secrets stay yours.

Express

Single-Gap Review

$500

One system or branch · ~3 business days

One focused question, answered fast: your single most serious control gap, and how to close it.

  • One system, one core question
  • Your biggest control gap, named
  • Short written findings + fix
Full · most chosen

Architecture Review

$1,500

Complete control read · ~1 week

The whole control architecture across authority, gates, evidence, and failure, with a prioritized remediation order and a walkthrough call.

  • All four dimensions reviewed
  • Gaps ranked by severity
  • Remediation order + walkthrough call
  • Branded findings report
Ledger-Anchored

Verifiable Review

$2,500

Everything in Full, made provable · ~1 week

Everything in the Full review, with the findings anchored to GIA's immutable governance ledger: a verifiable artifact you can show investors, customers, or auditors.

  • Everything in the Full review
  • Findings anchored to the governance ledger
  • A credential others can independently verify

Each review is scoped on a short call first, so you only pay for the read you need. Not sure which fits? Start with the free readiness assessment.

GIA

Reviewed by the person who built the control plane, not a checklist vendor.

William J. Storey III spent 17 years as a U.S. Army information systems security officer and built GIA, a runtime-governance platform that enforces authority, gates, and forensic evidence on live AI systems. This review is that same discipline, turned on your architecture.

17-yr Army ISSO SDVOSB NIST AI RMF ISO/IEC 42001 EU AI Act

What this review is, and is not.

This is an independent governance read of your system's control design, delivered as written findings. It is not a source-code audit, a penetration test, a model-safety evaluation, or a certification, and it does not require access to your source or your secrets. The findings are professional judgment intended to help you close control gaps before you scale. The Ledger-Anchored tier records that a review took place and what it concluded; it attests to the review, not to the safety of your system.

Before you scale it, have someone prove where it stops.

If your AI is already acting in operations and you cannot yet show where it has to stop, that gap is the work. Let's scope it in twenty minutes.

Or reach out directly: operations@aceadvising.com