Cases

Work done, and the shapes consultations take.

Work done as Fragment Practice, the founder's earlier roles, and the common patterns a consultation takes.

Client names and confidential information are not shown. The patterns are shown as generalised types.

Work done

Done as Fragment Practice.

Shown by sector, with what was organised and the material that remained.

Financial institution

Governance for expanding generative AI use

Situation

Before widening use of an internal generative-AI environment, the organisation wanted criteria for what to allow and who checks it.

What was done

Organised, use by use, the information handled, how output is used, human review, and approval and records — and combined system controls with rule-based operation into one approach to control.

What remained

  • Draft AI governance policy
  • Control model by use scenario
  • Roadmap for widening use in stages
  • Issues framed for management reporting

Used for

Material for deciding where to start and what to check before widening use

Where the practice's part ended

Applying it to systems, and the day-to-day checks, sit with the internal teams that own them.

Systems integrator

Viability conditions for an AI-enabled security monitoring service

Situation

Before launching an AI-enabled integrated security monitoring (SOC) service, the team wanted the conditions under which it works as a business, and the shape of delivery.

What was done

Compared product-led, platform-extension and AI-SOC models, evaluated on cost acceptability, operational transparency, speed to launch, staged scalability, and low dependence on any one vendor.

What remained

  • Must / should / could requirements
  • Cost structure
  • Delivery-model comparison
  • Phased introduction and role split

Used for

Material for service planning and the design of the next stage

Where the practice's part ended

Building the service, contracting partners, and running it are the provider's own work.

Before the practice

The founder's prior roles.

Work from the founder's employment before independence — the experience the current work stands on.

KPMG Consulting (the founder's prior role)

IT continuity and incident response, mainly in heavy industry and manufacturing

What was done

Worked on IT business-continuity planning, incident-response readiness with the design and running of exercises, and the standardisation of supplier security assessment.

What remained

  • Risk scenarios and recovery steps
  • Role split and exercise scenarios
  • Supplier assessment items and flow

Nomura Research Institute / NRI Secure Technologies (the founder's prior role)

Risk assessment and requirements for cloud and AI use at large enterprises

What was done

In third-party and risk assessment of a cloud AI platform, organised the evaluation points — permissions, logging, data protection, whether data is used for external training. In a device-platform renewal, structured requirements that connected the technical design to security needs.

What remained

  • Risk-assessment points
  • Security requirements

Common patterns

The shapes a consultation takes.

Generalised types, grouped by scene: the situation, what gets organised, what remains, and where it is used.

Rules and decision criteria for AI use

Turning AI-use rules into review points teams can apply

For organizations with an AI-use policy or high-level rules, where business teams still cannot tell what is allowed, what can be entered, how output is handled, who reviews, and what to record.

AI-use rulesReview pointsPractical guidance
01

Situation

  • High-level AI rules exist or are being discussed, but business teams still need practical guidance
  • What information can be entered, how outputs can be used, who should review, and what should be recorded are unclear
02

What gets organised

  • Organise allowed and restricted use, input boundaries, output handling, human review, approval, records, and FAQ themes
  • Separate what rules handle, what people review, and what is escalated
03

What remains

  • AI-use review-point checklist
  • Input / output handling guidance
  • FAQ and escalation-point draft
04

Used for

  • Business-team guidance
  • Training or FAQ preparation
  • Practical AI-use rollout

Where the practice's part ends

The practice sets the criteria and escalation points. Publishing them internally, training teams, and answering day-to-day cases stay in-house.

If the job is to turn AI-use rules into review points your own teams can apply, without engaging anyone:

See the AI Governance Readiness Kit

Deciding whether a proof of concept should become real adoption

For organizations where technical validation has progressed, but the scope of use, responsibility boundaries, review method, conditions for pausing, and operating structure are not settled.

After a PoCAdoption decisionOperating structure
01

Situation

  • The proof of concept produced results, but not an answer to whether it should be rolled out
  • Scope of use, who approves, and what has to keep being checked once it runs are undecided
02

What gets organised

  • Separate what the validation actually demonstrated from what it did not
  • Organise the scope of use, responsibility boundaries, review points, conditions for pausing, and the operating structure adoption would need
03

What remains

  • Adoption decision material
  • Scope-of-use and responsibility-boundary memo
  • Review points, pause conditions, and operating requirements
04

Used for

  • Adoption or rollout decision
  • Management and stakeholder explanation
  • Handover to the implementing team

Where the practice's part ends

The practice prepares the decision material and operating requirements so the decision can be made and handed on. The build, the rollout, and the running of it belong to the implementing team.

Security requirements and internal rules

Turning outdated rules and controls into review points and update issues

For organizations where existing policies, internal rules, guidelines, or external requirements have become outdated, fragmented, or dependent on a few people.

Rules and controlRequirementsReview points
01

Situation

  • Rules or guidelines created years ago no longer match AI, cloud, external-service, or current security use
  • Questions from business teams and requirement decisions depend on a small number of people
02

What gets organised

  • Read current rules, related documents, external requirements, and recurring questions
  • Organise gaps, overlaps, review points, ownership, responsibility boundaries, and update issues
03

What remains

  • Rule / requirement mapping memo
  • Gap and unresolved-area list
  • Review-point and responsibility-boundary proposal
04

Used for

  • Rule and control updates
  • Requirement response
  • Stakeholder explanation

Where the practice's part ends

The mapping and proposals are handed over. Rewriting the official rule set, approving it, and maintaining it remain with the internal owners.

Evaluating concepts, requirements, and proposals

Independent review of a critical system, security policy, or risk material

For situations where existing security policy, system-renewal material, risk assessments, control assumptions, or next-phase plans need an independent reading before the next step.

Independent reviewSecurity policyRisk assessment
01

Situation

  • Security policy, risk assessment material, or system-renewal assumptions already exist
  • Residual risks, open questions, evidence expectations, and handoff points need clearer structure before the next phase
02

What gets organised

  • Read policies, risk material, assumptions, controls, evidence, residual risks, and operating implications
  • Organise review comments, unresolved points, assumptions, and recommended next actions
03

What remains

  • Independent review comments
  • Residual-risk and assumption memo
  • Recommended next actions and handoff points
04

Used for

  • Confirmation before the next phase
  • Refining a risk assessment
  • Stakeholder or vendor discussion

Where the practice's part ends

The review returns findings and open questions — not a verdict, a score, or a maturity level. It does not stand in for audit, assurance, certification, conformity assessment, or legal judgement, and how to act on the findings stays with the organization.

Next step

If one of these feels close, start with a conversation.

Start from Contact with the situation you recognise here. Services shows the three scenes and how the work is scoped.