Rules and decision criteria for AI use
How far generative AI may be used, and on whose approval. The checks and records for each use, and the criteria for approval and exceptions, organised.
Service Overview
Fragment Practice is an independent advisory practice. Where AI, security, and technology risk meet, it separates the issues and turns them into requirements, decision criteria, role splits, and briefing material the people who decide will use.
A one-page overview for first discussions, internal sharing, referrals, and early scoping. Mainly across AI governance, security, and technology risk.
What you can bring
Topics already in implementation can be brought too, for structuring, requirements, option comparison, or review. Explaining the work to management and stakeholders runs through every scene; where it is needed, the work includes that brief.
How far generative AI may be used, and on whose approval. The checks and records for each use, and the criteria for approval and exceptions, organised.
Security guidelines and internal rules, and what customers or a parent company ask of you, organised into requirements and review points that can be checked in practice. This scene also covers how to respond, as a company, to an external scheme or standard; decisions and roles when an incident or outage stops systems (IT continuity).
A platform or service concept, the requirements you give vendors, or a proposal or policy you already have — put into a form you can compare and decide on. Independent review is part of this: it returns findings and open questions, not a verdict, a score, or a maturity level, and it does not stand in for audit, assurance, or certification.
What the work structures
The work separates issues, clarifies review points and responsibility boundaries, and turns the result into material that can be used in meetings, reports, reviews, roadmaps, and handoffs.
Review the issue, stakeholders, existing material, business context, decision timeline, meeting cadence, and what remains unclear.
Separate use cases, assumptions, requirements, risks, open questions, reviewers, responsibility boundaries, and handoff items.
Create material for management discussion, stakeholder explanation, review, roadmap planning, scoped advisory, or next-phase handoff.
Problem
Even when an initiative is already moving, the decision criteria, review structure, and handoff conditions may still be weak.
Support
What is organised differs by scene; what remains is material for the people who decide, review, and hand off.
Outputs
Outputs vary by context, but the goal is to leave material that remains useful after meetings, reviews, and first-stage decisions.
Scope
The engagement boundary is kept clear so support does not drift into undefined execution ownership.
Engagement options
From-prices for new engagements (excl. tax); existing agreements are unaffected. Final scope and fees are designed by outputs, review volume, meeting cadence, stakeholders, response expectations, and responsibility boundaries.
From ¥300,000 (excl. tax)
A focused entry point for separating issues, stakeholders, decision points, review needs, responsibility boundaries, and next checks.
From ¥1,200,000 (excl. tax)
A bounded sprint for turning existing materials and interviews into decision material, review points, responsibility boundaries, and handoff material.
From ¥600,000 / month (excl. tax)
Recurring advisory support for document review, issue structuring, decision-material updates, and pre-meeting or stakeholder-explanation checks, with cadence and boundaries defined in advance.
Examples
Shown by sector or former employer, without client names or confidential detail.
Organised, use by use, the information handled, how output is used, human review, and approval and records — and combined system controls with rule-based operation into one approach to control.
Compared product-led, platform-extension and AI-SOC models, evaluated on cost acceptability, operational transparency, speed to launch, staged scalability, and low dependence on any one vendor.
Worked on IT business-continuity planning, incident-response readiness with the design and running of exercises, and the standardisation of supplier security assessment.
In third-party and risk assessment of a cloud AI platform, organised the evaluation points — permissions, logging, data protection, whether data is used for external training. In a device-platform renewal, structured requirements that connected the technical design to security needs.
Advisor profile
Yasuhiro Shinsho is an independent advisor who turns ambiguous issues into decision material, review criteria, responsibility boundaries, operating design, and handoff-ready next actions — across AI governance, security governance, external-scheme response, business continuity, and technology risk.
He has worked in systems development and security since 2014 — building and assessing systems at BIPROGY, consulting on IT risk and security at KPMG Consulting, and advising on security and cloud / AI risk at Nomura Research Institute / NRI Secure Technologies. His work has crossed system development, cybersecurity, IT risk, governance, cloud and AI risk review, and management-facing explanation material. He is based in Takamatsu, Japan.
Next step
Even when the request is not yet fully defined, the first step is to review the current situation, available materials, expected outputs, stakeholders, decision timeline, review target and volume, response expectations, and scope of involvement, then identify the appropriate format of support.