Joint Tactical Operations Centre - Continuous Assurance Architecture

Govern your security, resilience and AI |
in a secure, intelligence-led environment.

The JTOC is a powerful operating system that converges your fragmented data, teams, and AI systems into a secure, governed environment, enabling confident, defensible decisions based on information generated by humans, AI or automated systems - with assurance reports produced on demand for regulators, insurers, clients, and boards.

DORA

DORA

Requires financial entities to evidence ICT governance and incident response.

Penalty: Up to €10m or 2% of global turnover.

NIS2

NIS2

Requires documented risk management and incident reporting for essential and important services.

Penalty: Up to €10m or 2% of global turnover for essential entities.

SM&CR

SM&CR

Senior Managers & Certification Regime: named senior individuals must be personally accountable for decisions within their scope, with an auditable record.

Penalty: Unlimited FCA fines; criminal prosecution possible.

s166 FSMA

s166 FSMA

Firms must produce complete, accurate records of how decisions were made and governed when the FCA demands them.

Penalty: Enforcement action, public censure, and significant financial penalties.

EU AI Act

EU AI Act

High-risk AI systems require logs, human oversight evidence, and documentation of how AI-influenced decisions were controlled.

Penalty: Up to €35m or 7% of global turnover.

HIPAA

HIPAA

Requires documented evidence of who accessed, used, or disclosed protected health information and under what authority.

Penalty: Civil penalties up to $1.9m per category; criminal penalties up to $250k and 10 years imprisonment.

FINRA

FINRA

Broker-dealers must maintain complete records of decisions and communications, with supervisory controls demonstrably in place.

Penalty: Fines into the tens of millions; potential suspension or industry bar.

GDPR

GDPR

Organisations must demonstrate lawful basis for data processing and evidence that data subjects' rights are upheld in practice.

Penalty: Up to €20m or 4% of global turnover.

FedRAMP

FedRAMP

Cloud providers seeking US federal contracts must demonstrate continuous monitoring and an auditable record of system governance.

Penalty: Loss of authorisation to operate and disqualification from federal contracts.

Duty of Care

Duty of Care

Requires evidence that reasonable steps to prevent foreseeable harm were actually taken, not merely stated in policy.

Penalty: Unlimited civil liability in negligence claims.

<10 min
Deployment time
Sovereign-capable
BYOD, BYOK, BYOM, BYOI
AI-queryable
Rapidly synthesise data. Reconstruct on demand.
Immutable
Every record, permanently attributed
The Problem

AI is accelerating decision-making.
Regulations are tightening.
Governance is struggling to keep up.

Businesses are adopting AI faster than they can prove that consequential decisions were authorised, bounded and defensible when something goes wrong.

01Who authorised the activity?
02What was the decision permitted to draw on?
03What actually happened?
04Who intervened, and when?
05What decisions were made?
06What evidence remains?
“

If the answer depends on reconstructing events from emails, messages, logs and policy documents, you are exposed.

”
The Solution

From Fragmentation to Control.

The JTOC helps you control, document and prove how consequential human, AI and automated decisions are made during operations, training and incident response.

What we do

  • Stand up your collective intelligence system(s) immediately - avoiding lengthy, costly in-house investment and ongoing exposure.
  • Ideal for contracts, projects, departments, companies or jurisdictions that all have unique data, security and stakeholder requirements.
  • Retained consultancy support to help you demonstrate ongoing compliance with obligations such as Article 4 of the EU AI Act (AI literacy).

What you get

  • A collaborative workspace in which you can control and prove how consequential AI-enabled and human decisions are authorised, executed and governed.
  • Ability to respond quickly and with confidence when decisions and processes are challenged by clients, regulators, insurers or investors.
  • Continuous, demonstrable compliance with ongoing obligations such as Article 4 of the EU AI Act, as your people, roles and AI use evolve.

Real commercial value

Reduced risk

Fewer unauthorised or uncontrolled AI-assisted decisions - less commercial & regulatory challenges.

Accountability

Clear evidence about who decided what, when, why, and under whose authority.

Time saved

Less manual work collecting approvals and evidence.

Insurable risk

Evidence insurers can use to price your AI and cyber risk accurately, rather than default to worst-case assumptions, or outright refusal.

Easier audits

Evidence is already organised and available, not reconstructed on request.

Safer AI adoption

Expand AI use while keeping human control over consequential decisions.

Three things should be true of every consequential decision.

Governance is demonstrable individual accountability for how a decision is authorised, implemented and evidenced.

A

Authorised

Someone specific, with full personal accountability, decides in advance what may be relied upon, by whom, and where that authority ends.

I

Implemented

The decision is carried out only within the bounds of the authority and intelligence granted. Any attempt to exceed that boundary - human or AI - is attributed and logged, whether blocked or successful.

E

Evidenced

A permanent record shows how the decision was reached, what it relied upon, and what did not happen. A response and a non-response are both captured.

Many solutions provide just one or two of these, usually in documentation.
The JTOC provides all three, architecturally. Your governance is built in.

Our Process

Converge. Govern. Decide. Assure.

AI systems are anchored to a trusted intelligence ecosystem.

01 · Converge

Fragmented data, teams and AI systems come together.

ConvergeGovernDecideAssure
The Transformation

The Transformation.

Without the JTOC
Decisions and approvals spread across systems, emails and people
Unclear who authorised an action
Evidence collected manually, after the fact
Difficult to reconstruct what actually happened
Significant time spent preparing for audits
AI can act beyond its intended limits
Compliance relies heavily on manual controls
With the JTOC
One traceable decision process
Clear responsibility and authority
Evidence captured automatically, as it happens
Full decision history available on demand
Faster audit and report preparation
Defined limits for AI versus human approval
A signed, human-reviewed record for regulators and stakeholders
Examples
The Core Deliverable

The Core Deliverable: signed reports for key
commercial and regulatory relationships.

In addition to collaborative systems enabling users to share and synthesise the same data sources, manage operations, training and incident response, build a knowledge base and enable decision advantage, the JTOC generates signed reports that help you assure key stakeholders of your ability to govern and manage risk.

Regulators

A clearer record of authority, activity and accountability.

Insurers

Historical operational evidence that helps insurers price AI and cyber risk more accurately, rather than estimate it.

Clients

Demonstrable governance capability that supports commercial assurance.

Investors & boards

A structured view of how consequential operational risk is being managed.

Governance Activity Report

A signed, human-reviewed record generated continuously as a byproduct of operations. The full record is retained internally; each report is scoped and redacted to what the recipient needs to know, drawn from:

  • Decisions made, and the authority relied on
  • Authorisations granted, and by whom
  • Intelligence relied upon, and what was excluded
  • Every attempt to act beyond an authorised decision, allowed or blocked
  • Non-responses, recorded with the same weight as actions
  • Communications and notifications sent, and to whom
  • Credential activity: issued, renewed, or revoked
Frequently Asked Questions

Commercial FAQs

Technical FAQs

Can you prove the decisions you made under pressure?