Service Overview

Turn ambiguous, complex issues into something you can decide and act on.

Fragment Practice is an independent advisory practice. Where AI, security, and technology risk meet, it separates the issues and turns them into requirements, decision criteria, role splits, and briefing material the people who decide will use.

A one-page overview for first discussions, internal sharing, referrals, and early scoping. Mainly across AI governance, security, and technology risk.

What you can bring

Three scenes, and the situations that sit inside them.

Topics already in implementation can be brought too, for structuring, requirements, option comparison, or review. Explaining the work to management and stakeholders runs through every scene; where it is needed, the work includes that brief.

01

Rules and decision criteria for AI use

How far generative AI may be used, and on whose approval. The checks and records for each use, and the criteria for approval and exceptions, organised.

02

Security requirements and internal rules

Security guidelines and internal rules, and what customers or a parent company ask of you, organised into requirements and review points that can be checked in practice. This scene also covers how to respond, as a company, to an external scheme or standard; decisions and roles when an incident or outage stops systems (IT continuity).

03

Evaluating concepts, requirements, and proposals

A platform or service concept, the requirements you give vendors, or a proposal or policy you already have — put into a form you can compare and decide on. Independent review is part of this: it returns findings and open questions, not a verdict, a score, or a maturity level, and it does not stand in for audit, assurance, or certification.

What the work structures

Convert mixed issues into decision material and review structure.

The work separates issues, clarifies review points and responsibility boundaries, and turns the result into material that can be used in meetings, reports, reviews, roadmaps, and handoffs.

01

Clarify the current situation

Review the issue, stakeholders, existing material, business context, decision timeline, meeting cadence, and what remains unclear.

02

Structure decisions, review points, and responsibility

Separate use cases, assumptions, requirements, risks, open questions, reviewers, responsibility boundaries, and handoff items.

03

Leave usable material

Create material for management discussion, stakeholder explanation, review, roadmap planning, scoped advisory, or next-phase handoff.

Problem

What is still unclear before decisions or rollout

Even when an initiative is already moving, the decision criteria, review structure, and handoff conditions may still be weak.

  • Which AI use cases should be treated as low, medium, or high risk
  • Who reviews outputs, approves use, keeps records, or owns residual risk
  • Which security requirements, internal rules, or controls matter and what evidence is needed
  • What should be decided now and what should move into a later roadmap
  • How responsibilities should be divided across internal teams, vendors, and external specialists

Support

What gets organised in each scene

What is organised differs by scene; what remains is material for the people who decide, review, and hand off.

  • Rules and decision criteria for AI use — where AI is used, and what information it handles; how output is used, and where people review it; conditions for approval, exceptions, and stopping; roles across people, AI, and the teams involved
  • Security requirements and internal rules — what is being asked for, mapped to your own rules; controls and review points; evidence, and who checks it; who decides and who is told during an incident
  • Evaluating concepts, requirements, and proposals — scope; what you decide, and what you ask of vendors; required and desirable requirements; the options, what to compare them on, and the assumptions; what is still undecided

Outputs

Representative material left behind

Outputs vary by context, but the goal is to leave material that remains useful after meetings, reviews, and first-stage decisions.

  • Issue-structuring memo
  • Management / Stakeholder Brief
  • AI Governance & Responsibility Map
  • AI use-case and review-point matrix
  • Rule / Requirement / Review Mapping Memo
  • Independent Review Note
  • Roadmap and next-action note
  • Scoped advisory notes

Scope

What stays with your own teams or partners

The engagement boundary is kept clear so support does not drift into undefined execution ownership.

  • Not implementation ownership or system development
  • Not resident PMO or day-to-day progress management
  • Not continuous operations, BPO, or always-on response
  • Not legal judgment, audit assurance, certification, or conformity assessment
  • Not a replacement for internal owners or final management decisions
  • Not 24/7 response, immediate-response standby, or unlimited advisory communication

Engagement options

Three ways to engage. Start with the smallest that fits.

From-prices for new engagements (excl. tax); existing agreements are unaffected. Final scope and fees are designed by outputs, review volume, meeting cadence, stakeholders, response expectations, and responsibility boundaries.

Initial structuring session

From ¥300,000 (excl. tax)

A focused entry point for separating issues, stakeholders, decision points, review needs, responsibility boundaries, and next checks.

  • Early issue framing
  • Before internal reporting
  • Before deciding on a larger engagement

Decision-material sprint

From ¥1,200,000 (excl. tax)

A bounded sprint for turning existing materials and interviews into decision material, review points, responsibility boundaries, and handoff material.

  • AI or security governance structuring
  • Security requirement and control review
  • Management or stakeholder explanation material
  • Third-party review of existing material

Scoped advisory support

From ¥600,000 / month (excl. tax)

Recurring advisory support for document review, issue structuring, decision-material updates, and pre-meeting or stakeholder-explanation checks, with cadence and boundaries defined in advance.

  • Monthly or biweekly review support
  • External advisory role with clear scope
  • Repeated decision or review cycles

Examples

Work done as Fragment Practice, and the founder's prior roles.

Shown by sector or former employer, without client names or confidential detail.

Done as Fragment Practice

Financial institution — Governance for expanding generative AI use

Organised, use by use, the information handled, how output is used, human review, and approval and records — and combined system controls with rule-based operation into one approach to control.

Systems integrator — Viability conditions for an AI-enabled security monitoring service

Compared product-led, platform-extension and AI-SOC models, evaluated on cost acceptability, operational transparency, speed to launch, staged scalability, and low dependence on any one vendor.

The founder's prior roles

KPMG Consulting (the founder's prior role) — IT continuity and incident response, mainly in heavy industry and manufacturing

Worked on IT business-continuity planning, incident-response readiness with the design and running of exercises, and the standardisation of supplier security assessment.

Nomura Research Institute / NRI Secure Technologies (the founder's prior role) — Risk assessment and requirements for cloud and AI use at large enterprises

In third-party and risk assessment of a cloud AI platform, organised the evaluation points — permissions, logging, data protection, whether data is used for external training. In a device-platform renewal, structured requirements that connected the technical design to security needs.

Advisor profile

Yasuhiro Shinsho / Fragment Practice LLC

Yasuhiro Shinsho is an independent advisor who turns ambiguous issues into decision material, review criteria, responsibility boundaries, operating design, and handoff-ready next actions — across AI governance, security governance, external-scheme response, business continuity, and technology risk.

He has worked in systems development and security since 2014 — building and assessing systems at BIPROGY, consulting on IT risk and security at KPMG Consulting, and advising on security and cloud / AI risk at Nomura Research Institute / NRI Secure Technologies. His work has crossed system development, cybersecurity, IT risk, governance, cloud and AI risk review, and management-facing explanation material. He is based in Takamatsu, Japan.

AI governanceSecurity governanceGovernance / controlTechnology riskReview pointsResponsibility boundaries

Next step

Start by confirming the right scope of involvement.

Even when the request is not yet fully defined, the first step is to review the current situation, available materials, expected outputs, stakeholders, decision timeline, review target and volume, response expectations, and scope of involvement, then identify the appropriate format of support.

Helpful information for the first discussion

  • Current situation
  • Available materials
  • Expected outputs
  • Stakeholders / meeting cadence
  • Decision timeline
  • Review target / volume
  • Response expectations / scope of involvement