AI Systems Assurance · Governance

The Resync AI Assurance Framework.

How we govern AI before we ask you to trust it. Resync operates a full AI Management System aligned to ISO/IEC 42001:2023 — built from scratch for our own AI products, and the same discipline we bring to assuring yours.

Plenty of firms talk about responsible AI. We did the governance work.

Because Resync builds and operates AI products, we hold ourselves to the standard we assess others against. Our AI Management System covers all 38 Annex A controls of ISO/IEC 42001:2023 across the full governance lifecycle — policy, scope, risk, impact assessment, roles, development lifecycle, acceptable use, and ongoing review. Not a framework we bought. A framework we built.

What the framework contains

  • AI Policy — our top-level commitment to responsible AI use
  • AIMS Scope Document — which systems are governed, and why
  • AI Risk Register — 12 identified risks with rated controls and residual risk
  • Statement of Applicability — all 38 Annex A controls — assessed, justified, evidenced
  • AI System Impact Assessment — potential harms, affected parties, and mitigations for our Sentinel platform
  • Governance Roles & Responsibilities — who owns what, with a RACI
  • AI Acceptable Use Guidance — practical rules for our team
  • AI Development Lifecycle — how we build AI products responsibly
  • AIMS Document Register — master index with version control
  • Annual Review Checklist — governance that still works next year

Aligned to the standards your auditors will cite.

Our AIMS aligns to ISO/IEC 42001:2023, the international standard for AI governance. Our Sentinel platform is built around ISO/IEC TS 42119-2:2025, the technical specification for testing AI systems — data quality, model testing, bias and fairness, adversarial testing, explainability, and drift. When we assess a client’s AI system, we’re applying discipline we practise on our own products first — and our free Testing AI Systems training teaches the same material to the wider NZ QA community.

What this means if you engage Resync

You are working with a consultancy that has done the governance work its own products demand: a documented AI policy, a live risk register, impact assessments, defined human oversight, and an annual review cycle. If you are a government agency or regulated entity that must account for how suppliers use AI, we can show you — not just tell you. Start with our AI Systems Assurance service or read the announcement.

Trust is built before the engagement starts.

Ask us to walk you through the framework — and what the same discipline would look like applied to your AI systems.