Services

What you can bring.

Where AI, security, and technology risk meet, there are three scenes you can bring to us. In each, the work separates the issues and produces the material the people who decide will use.

Topics where implementation or adoption is already under way can be brought too, for structuring, requirements, option comparison, or review.

Scenes

Three scenes you can bring.

AI governance

Rules and decision criteria for AI use

How far generative AI may be used, and on whose approval. The checks and records for each use, and the criteria for approval and exceptions, organised.

Common situations

  • People have started using generative AI, but what can be entered, how output is used, and who checks it are still unclear
  • The PoC went well, but the roles, review points, and conditions for stopping that real operation needs are not set
  • The team pushing AI and the team managing risk talk past each other — no one has separated which decisions belong to whom

What gets organised

  • Where AI is used, and what information it handles
  • How output is used, and where people review it
  • Conditions for approval, exceptions, and stopping
  • Roles across people, AI, and the teams involved

What remains

  • AI Governance & Responsibility Map
  • Role / Operating Design Memo
  • Management / Stakeholder Brief

Used for

  • Deciding whether to widen use
  • Updating internal rules
  • Rolling out to teams

Work done in this scene

  • Financial institutionGovernance for expanding generative AI use

Security governance

Security requirements and internal rules

Security guidelines and internal rules, and what customers or a parent company ask of you, organised into requirements and review points that can be checked in practice.

Common situations

  • Company-wide security governance is the aim, but there is no internal agreement on how to revise the rules and guidelines
  • A customer's security questionnaire, or a query from a regulator or parent company — and how far to respond is not settled

What gets organised

  • What is being asked for, mapped to your own rules
  • Controls and review points
  • Evidence, and who checks it
  • Who decides and who is told during an incident

What remains

  • Rule / Requirement / Review Mapping Memo
  • Role / Operating Design Memo

Used for

  • Revising rules and guidelines
  • Settling the response to customers or regulators, and how far it goes
  • Checks on the ground

Also within this scene

  • How to respond, as a company, to an external scheme or standard
  • Decisions and roles when an incident or outage stops systems (IT continuity)

Technology risk

Evaluating concepts, requirements, and proposals

A platform or service concept, the requirements you give vendors, or a proposal or policy you already have — put into a form you can compare and decide on. Independent review is part of this: it returns findings and open questions, not a verdict, a score, or a maturity level, and it does not stand in for audit, assurance, or certification.

Common situations

  • There is a platform or service concept, but no agreement on what to require or what to compare
  • Vendor proposals have arrived, and there is no agreed way to evaluate them
  • A management meeting needs decision material, or a vendor needs clear requirements — and neither exists yet

What gets organised

  • Scope
  • What you decide, and what you ask of vendors
  • Required and desirable requirements
  • The options, what to compare them on, and the assumptions
  • What is still undecided

What remains

  • Rule / Requirement / Review Mapping Memo
  • Management / Stakeholder Brief
  • Independent Review Note

Used for

  • Setting out requirements for vendors
  • Internal approval
  • Comparing proposals, and explaining the choice

Nor does an independent review stand in for conformity assessment or legal judgement; its findings state what was not assessed and where the review's limits lie.

Work done in this scene

  • Systems integratorViability conditions for an AI-enabled security monitoring service

Explaining the work to management and stakeholders runs through every scene; where it is needed, the work includes that brief.

Ways to engage

Match the level and duration of involvement to the situation.

The engagement shape does not need to be decided before the first conversation; it can be defined together after reviewing the situation. Start with an initial structuring session, use a decision-material sprint when material is needed soon, or continue with scoped advisory support when review and interpretation needs keep returning.

01

See what to decide first

Initial structuring session

Clarifies the issue, decision order, review points, and next actions when the situation is still too mixed to scope cleanly.

Price guide

From ¥300,000

Excl. tax. Typically 1–2 sessions, including advance review of existing material.

Best for

When the issue exists, but the decision point, review need, role boundary, or next move is still unclear.

Includes

Initial issue reviewFocused discussionIssue separationDecision and review pointsNext-step options

Leaves behind

  • Issue memo
  • Decision-point summary
  • Next-action note
02

Ready before the decision

Bounded sprint

Decision-material sprint

Assembles the issues, responsibility boundaries, review points, and outputs that a dated decision, rule update, third-party review, or handoff needs.

Price guide

From ¥1,200,000

Excl. tax. Usually 2–6 weeks. Scoped by output, cadence, and involvement.

Best for

When a meeting, report, decision, review, rule update, or handoff needs usable material soon.

Includes

Current-state reviewWorking sessionsReview-point designRole / responsibility structuringOutput drafting

Leaves behind

  • Management / Stakeholder Brief
  • AI Governance & Responsibility Map
  • Rule / Requirement / Review Mapping Memo
  • Roadmap / next actions
03

Keep one theme under review

Scoped advisory support

Provides continuing expert judgment and review on a defined theme, keeping decision material current at the points that matter.

Price guide

From ¥600,000/month

Excl. tax. Designed by theme, cadence, review scope and volume, response expectations, outputs, and responsibility boundaries.

Best for

When recurring external advice is needed without a resident or all-in role, and scope and response expectations should stay bounded.

Includes

Monthly or biweekly advisoryDocument review within scopeIssue interpretationStakeholder explanation supportNext-action review

Leaves behind

  • Advisory notes
  • Review comments
  • Issue logs
  • Decision / handoff material

These are starting points (excl. tax) for new engagements, not fixed packages. Final scope and fees are designed around the theme, number of stakeholders, outputs, meeting cadence, and asynchronous response. Existing agreements are unaffected.

What remains

Material, by who uses it and what for.

Each scene leaves some of these. They are written so the people who use them can keep updating them after the work.

Management / Stakeholder Brief

Used by: Management, approvers, and the teams involved

Material for comparing options and conditions, deciding, and explaining why.

Contains

BackgroundCurrent stateDecision pointsOptionsRisksRequested actions

Helps answer

Typical questions

  • What should be explained now?
  • What should management or stakeholders decide?
  • What should move to the next phase?

Used before management discussion, stakeholder explanation, planning, rollout, or handoff.

AI Governance & Responsibility Map

Used by: Business, IT, and risk teams

A table to work from when agreeing who approves, who reviews, and who decides on exceptions and stops.

Contains

AI use casesInput / output boundariesHuman review pointsApproval logicRecordsResponsibility boundaries

Helps answer

Typical questions

  • What AI use cases are in scope?
  • Who reviews or approves the output?
  • Where should responsibility stay explicit?

Used when AI adoption needs to become reviewable, explainable, and workable.

Role / Operating Design Memo

Used by: The teams that run the work, and their vendors

A memo of what people, AI, internal teams, advisors, and vendors each support, review, decide, and hand off.

Contains

Human / AI rolesOperating workflowReview pointsRecordsOwnersOpen questions

Helps answer

Typical questions

  • What should AI or external support handle?
  • Where should people review or decide?
  • How can the workflow continue without becoming unclear?

Used when AI adoption, business efficiency, or external support needs to become a practical operating model.

Rule / Requirement / Review Mapping Memo

Used by: Security, risk, and IT teams

Organised for revising rules, setting out requirements for vendors, and checking on the ground.

Contains

Relevant rulesRequirementsCurrent-state gapsPriority areasReview pointsRecords / evidenceUpdate cycle

Helps answer

Typical questions

  • Which rules or requirements matter in this context?
  • Who should review, decide, or update them?
  • What should become records or stakeholder material?

Used when rules, requirements, guidelines, or control expectations need to become internal discussion and operating material.

Independent Review Note

Used by: Whoever owns the policy or proposal

Findings for checking what an existing policy or proposal rests on, and what it misses.

Contains

Review scopeObservationsMaterial issuesDecisions requiredAssumptionsAreas not assessedLimitations

Helps answer

Typical questions

  • Does this hold, and on what assumption?
  • What risk remains after it?
  • What should we decide before proceeding?

Used before the next phase, and in discussions with stakeholders or vendors.

What you receive, and when

Material you can use from early on, not only at the end.

The first conversation confirms what is moving, who needs to decide or review, what feels unclear, and what material needs to remain — and from that, the support shape and the outputs. From early on you hold a written view that separates what is established, what is still a working hypothesis, what is unknown, and what has to be decided.

At the first conversation

Share the current issue

Describe what is moving, who needs to decide or review, what feels mixed or unclear, and whether the need is one-time or recurring. No finished brief or perfect category is needed.

Current stateDecision pointContext

At the first conversation

Confirm the support shape

Confirm whether the issue fits an initial structuring session, decision-material sprint, scoped advisory support, product kit, or another path.

FitScopeSupport shape

At the first conversation

Define outputs and scope

Clarify outputs, cadence, review volume, role, response expectations, and limits so the work stays a defined, bounded engagement — including the conditions for returning a decision, handling exceptions, and escalating.

ScopeOutputsStop and exception conditions

Once the work starts

What is established, what is assumed, what is unknown

The work does not wait until everything is known. From the material received and the conversations so far, the current understanding is written down early — what is established, what is still a working hypothesis, what is unknown, and what has to be decided and by whom. It is not a finished recommendation; it is there to align how each side reads the situation.

Established / assumed / unknownIssuesWho decides

Once the work starts

You do not have to respond in full

There is no need to go through it item by item. Tell us where it reads differently to you, or where you want a closer look, and the next questions are narrowed from there. The question you brought is looked at the same way rather than taken as settled. What comes out of that is added to the existing structuring rather than restarted, and what remains is material usable for explanation and for the decision.

No full review neededAdded to the same structuringDecision material

Scope

Where the work stops, and who carries it on.

Building and running systems, and managing day-to-day progress, stay with your own teams or implementation partners. Fragment Practice produces the material their decisions and handoffs rest on. Detailed exclusions are on FAQ.

Next step

Start from the current issue and define the right scope of support.

Use an Initial structuring session when the issue needs its first clear shape. Use a Decision-material sprint when a report, meeting, rule update, or handoff needs usable material soon. Use Scoped advisory support when recurring review and interpretation are needed without replacing internal owners.