Govern your security, resilience and AI |
in a secure, intelligence-led environment.
The JTOC is a powerful operating system that converges your fragmented data, teams, and AI systems into a secure, governed environment, enabling confident, defensible decisions based on information generated by humans, AI or automated systems - with assurance reports produced on demand for regulators, insurers, clients, and boards.
DORA
Requires financial entities to evidence ICT governance and incident response.
Penalty: Up to €10m or 2% of global turnover.
NIS2
Requires documented risk management and incident reporting for essential and important services.
Penalty: Up to €10m or 2% of global turnover for essential entities.
SM&CR
Senior Managers & Certification Regime: named senior individuals must be personally accountable for decisions within their scope, with an auditable record.
Penalty: Unlimited FCA fines; criminal prosecution possible.
s166 FSMA
Firms must produce complete, accurate records of how decisions were made and governed when the FCA demands them.
Penalty: Enforcement action, public censure, and significant financial penalties.
EU AI Act
High-risk AI systems require logs, human oversight evidence, and documentation of how AI-influenced decisions were controlled.
Penalty: Up to €35m or 7% of global turnover.
HIPAA
Requires documented evidence of who accessed, used, or disclosed protected health information and under what authority.
Penalty: Civil penalties up to $1.9m per category; criminal penalties up to $250k and 10 years imprisonment.
FINRA
Broker-dealers must maintain complete records of decisions and communications, with supervisory controls demonstrably in place.
Penalty: Fines into the tens of millions; potential suspension or industry bar.
GDPR
Organisations must demonstrate lawful basis for data processing and evidence that data subjects' rights are upheld in practice.
Penalty: Up to €20m or 4% of global turnover.
FedRAMP
Cloud providers seeking US federal contracts must demonstrate continuous monitoring and an auditable record of system governance.
Penalty: Loss of authorisation to operate and disqualification from federal contracts.
Duty of Care
Requires evidence that reasonable steps to prevent foreseeable harm were actually taken, not merely stated in policy.
Penalty: Unlimited civil liability in negligence claims.
AI is accelerating decision-making.
Regulations are tightening.
Governance is struggling to keep up.
Businesses are adopting AI faster than they can prove that consequential decisions were authorised, bounded and defensible when something goes wrong.
If the answer depends on reconstructing events from emails, messages, logs and policy documents, you are exposed.
”From Fragmentation to Control.
The JTOC helps you control, document and prove how consequential human, AI and automated decisions are made during operations, training and incident response.
What we do
- Stand up your collective intelligence system(s) immediately - avoiding lengthy, costly in-house investment and ongoing exposure.
- Ideal for contracts, projects, departments, companies or jurisdictions that all have unique data, security and stakeholder requirements.
- Retained consultancy support to help you demonstrate ongoing compliance with obligations such as Article 4 of the EU AI Act (AI literacy).
What you get
- A collaborative workspace in which you can control and prove how consequential AI-enabled and human decisions are authorised, executed and governed.
- Ability to respond quickly and with confidence when decisions and processes are challenged by clients, regulators, insurers or investors.
- Continuous, demonstrable compliance with ongoing obligations such as Article 4 of the EU AI Act, as your people, roles and AI use evolve.
Real commercial value
Reduced risk
Fewer unauthorised or uncontrolled AI-assisted decisions - less commercial & regulatory challenges.
Accountability
Clear evidence about who decided what, when, why, and under whose authority.
Time saved
Less manual work collecting approvals and evidence.
Insurable risk
Evidence insurers can use to price your AI and cyber risk accurately, rather than default to worst-case assumptions, or outright refusal.
Easier audits
Evidence is already organised and available, not reconstructed on request.
Safer AI adoption
Expand AI use while keeping human control over consequential decisions.
Three things should be true of every consequential decision.
Governance is demonstrable individual accountability for how a decision is authorised, implemented and evidenced.
Authorised
Someone specific, with full personal accountability, decides in advance what may be relied upon, by whom, and where that authority ends.
Implemented
The decision is carried out only within the bounds of the authority and intelligence granted. Any attempt to exceed that boundary - human or AI - is attributed and logged, whether blocked or successful.
Evidenced
A permanent record shows how the decision was reached, what it relied upon, and what did not happen. A response and a non-response are both captured.
Many solutions provide just one or two of these, usually in documentation.
The JTOC provides all three, architecturally. Your governance is built in.
Converge. Govern. Decide. Assure.
AI systems are anchored to a trusted intelligence ecosystem.
01 · Converge
Fragmented data, teams and AI systems come together.
The Transformation.
The Core Deliverable: signed reports for key
commercial and regulatory relationships.
In addition to collaborative systems enabling users to share and synthesise the same data sources, manage operations, training and incident response, build a knowledge base and enable decision advantage, the JTOC generates signed reports that help you assure key stakeholders of your ability to govern and manage risk.
Regulators
A clearer record of authority, activity and accountability.
Insurers
Historical operational evidence that helps insurers price AI and cyber risk more accurately, rather than estimate it.
Clients
Demonstrable governance capability that supports commercial assurance.
Investors & boards
A structured view of how consequential operational risk is being managed.
Governance Activity Report
A signed, human-reviewed record generated continuously as a byproduct of operations. The full record is retained internally; each report is scoped and redacted to what the recipient needs to know, drawn from:
- Decisions made, and the authority relied on
- Authorisations granted, and by whom
- Intelligence relied upon, and what was excluded
- Every attempt to act beyond an authorised decision, allowed or blocked
- Non-responses, recorded with the same weight as actions
- Communications and notifications sent, and to whom
- Credential activity: issued, renewed, or revoked