Sample deliverable
What an Enforcement Gap Review looks like
Within 48 hours of a complimentary 30-Minute Enforcement Gap Review, you receive a one-page written diagnosis mapped to the frameworks that apply to you. This page shows that report's structure, built around a fictional scenario.
Illustrative example, not a real engagement. The company, findings, and figures below are fictional. Aivance has not assessed this organisation because it does not exist. The purpose of this page is to show the format and level of specificity of a real diagnosis, not to report on an actual client.
Scenario (fictional)
Meridian Commerce · B2B invoicing SaaS · ~80 staff · Singapore-headquartered
In Q1 2026, Meridian deployed an AI agent to auto-approve customer credit adjustments up to SGD 500, escalating anything above that threshold to a human reviewer. The agent works well operationally. Meridian's CFO asked whether the governance around it would hold up if a customer disputed a decision, or if a regulator asked to see how it was controlled.
The three assurance questions
Does your control set satisfy the frameworks that apply to you?
PartialMapped against the IMDA Model AI Governance Framework v1.5 and PDPA. The escalation logic has not yet been assessed against IMDA's Agentic AI addendum.
Is it technically reliable?
NoThe escalation threshold that decides whether a credit adjustment needs human sign-off lives in an editable application config value, not an enforcement point the agent cannot bypass.
Can you evidence it?
NoNo audit log captures who last changed the threshold, when, or why. If an examiner or the board asked for that history today, there would be nothing to show them.
The finding
The single control most likely to cost Meridian in the next 12 months is the escalation threshold itself: it is a config value an engineer can change without triggering any governance review, and no log records when that happens. On paper, the agent escalates above SGD 500 every time. Technically, that boundary is only as real as the last person who edited the config file, and there is no record of who that was.
Framework mapping
| Framework | Status |
|---|---|
| IMDA Model AI Governance Framework v1.5 | Partially mapped |
| PDPA | Mapped, one gap flagged |
| MAS AIRG | Not applicable (non-financial services) |
Recommended next step
Move the escalation threshold out of application config and into an authorisation layer the agent cannot write to, with a change log that records who set it and when. This alone would close the technical-reliability and evidence gaps identified above; the framework mapping would still need a follow-on assessment once that control is in place.
Reminder: Meridian Commerce is fictional. This page exists to show what a real diagnosis contains and how specific its findings are, built on a made-up scenario rather than any actual Aivance client.
Your systems aren't fictional. Neither should your evidence be.
Start with the complimentary 30-Minute Enforcement Gap Review. We identify which of the three assurance questions above your organisation cannot currently answer, and deliver a written diagnosis mapped to your applicable frameworks within 48 hours.
Book Your Enforcement Gap Review