Governance, Oversight and Risk.
The agentic AI governance, oversight and risk master class: the control-function depth a buyer cannot delegate, taken after Outsourcing Lifecycle Management.
Ownership and accountability for agentic AI is the single lowest-rated condition in the study (3.47), and on canceled engagements it collapses to 2.32. No participant reported a proven governance playbook. Meanwhile EU AI Act Article 26 deployer obligations take effect on August 2, 2026. A buyer that cannot say who owns the mandate, what its agents may do unsupervised, and how it answers an examiner is exposed on all three at once. This class builds that control function.
The control function a buyer cannot delegate.
This is a 1-day master class, delivered onsite to a cohort of 15, taken after the foundational Outsourcing Lifecycle Management class. It goes past running the lifecycle to governing it: how a buyer designs the oversight function, bounds agent autonomy, and holds the duty it cannot hand to a vendor.
Seven risk categories, five autonomy tiers, one duty register.
The governance and oversight function
One buyer function co-chairing one joint body, with a mandate, seats, decision rights, and an operating calendar, plus the interim oversight floor to run until it is stood up.
Ownership and the AI mandate
How to end the contest between the finance, technology, and procurement chiefs over who owns agentic AI, using the two-register discipline: a shared, negotiable risk register, and a unilateral, non-delegable duty register that never merges with it.
The joint risk model
Seven risk categories, including vendor-capability risk, scored on likelihood and impact with the buyer’s own control as a routing attribute, mapped onto concentration risk and the OWASP and CSA agentic-threat work.
Decision rights and agent autonomy
Five autonomy tiers per task-class, promotion only on evidence, and de-escalation held as a unilateral safety right. This answers the weakest terminal condition in the study: on canceled engagements, clarity on what agents may do without human approval rated 2.16.
Human oversight as a control function
Certified oversight capacity that caps autonomy, with attrition as a trigger for de-escalation. The oversight layer averaged 4.19 on job satisfaction, and most of it intends to leave. The control cannot assume it.
Regulatory operations and the interoperability crosswalk
EU AI Act Article 26 deployer duties, effective August 2, 2026, the US Interagency lifecycle, DORA, and sector rules, run as an operating rhythm that produces an examiner-ready ledger rather than a compliance scramble.
The measured points where the control function fails.
The class targets the conditions the study rates weakest. Ownership at 3.47, agent-autonomy clarity at 2.16 on canceled engagements, and an oversight workforce at 4.19 are not abstractions. They are the measured points where the control function fails, and the points this class is built to close. The figures describe the study, not a delivered result.
One day, onsite, after the foundational class.
One day, onsite, cohort of 15. Taken after Outsourcing Lifecycle Management. Scheduling is confirmed on enquiry.
Part 5 · The Executive Agenda
The six actions a board can act on, including treating human oversight as a control function.
Part 4 · The Delivery Workforce
The oversight layer’s own numbers: 4.19 job satisfaction, and most intend to leave.
To enquire about a cohort or dates, the route is one conversation with Phil Hatch or a firm contact.
