
AI Adoption is not Waiting for Permission.
Capable teams already use AI through personal accounts. The platforms you own are switching on AI features faster than procurement can review them, and boards and insurers now expect demonstrable oversight.
The use cases are legitimate; what is missing is the policy, the approval path, and the technical baseline that make them safe, contractually sound, and defensible.
This program puts that foundation in place, aligned to the NIST AI Risk Management Framework and ISO/IEC 42001.

Where the Risk Lives
Agentic AI takes real actions inside your environment; the value and the risk arrive together. Three exposures deserve leadership attention before the first agent is connected.

AI inherits your permissions
An agent sees what its user sees and acts with the same rights. An over- shared SharePoint makes it the best- read employee in the company.

Increased attack surface
Hidden instructions in an email, web page, or document can redirect an agent, and a wrong or manipulated action executes before anyone can stop it.

Liability without visibility
Consumer AI accounts put company and client data under personal terms. Your data can train someone else's model while you carry the exposure.
PHASE 5
Ongoing
A standing monthly engagement keeps the framework current as tools and regulations change, manages access and new-tool requests through the approval procedure, operates continuous Shadow AI monitoring, runs bi-weekly enablement sessions, and provides first-line AI incident support.
The Engagement
A fixed-scope, 120-day program that takes an organization from ad-hoc AI use to a defined, working governance framework, and keeps it there.
PHASE 1
Discovery
Stakeholder interviews map current AI use, demand, and risk appetite.
PHASE 3
Governance
AI Policy, Acceptable Use Protocol, data tiering, Approval SOP, and Tool Register, ratified.
PHASE 2
Technical Baseline
M365 CIS Benchmark, Copilot readiness (ARA), permissions audit, Shadow AI discovery.
PHASE 4
Enablement
Vendor risk assessments, managed onboarding of approved tools, awareness training.
What You Walk Away With
• AI Policy:
board-facing, aligned to NIST AI RMF and ISO/IEC 42001.
• Acceptable Use Protocol:
employee-facing rules for daily AI use.
• Data Classification:
a three-tier scheme deciding which information AI tools may touch.
• Approval Workflow:
intake forms, procedure, and Tool Register, so every new AI request gets a timely answer.
• Current-state Synthesis:
the AI currently in use across your teams, and the risk themes it creates.
• Technical Baseline Report:
CIS (Center for Internet Security) Benchmark, Copilot readiness, permissions, and Shadow AI findings in one document.
• Vendor Security Risk Assessments:
one for each tool you approve.
• Approved Tools, Live:
onboarded with security and monitoring controls in place.
• Trained Workforce:
AI awareness modules inside your existing training platform.
• Executive Risk and Roadmap Briefing:
your posture, your risks, and a 12 to 18 month plan.

Why Terra Advise
Independent
Advisory sits apart from our managed services; the team assessing you has nothing else to sell you.
Framework-based
The work is anchored to NIST AI RMF and ISO/IEC 42001, on a Microsoft 365 CIS Benchmark baseline.
We Stay
The team that builds the framework operates it with you as tools and rules change.
Hear from our Clients
Terra Dygital has proven to be a valuable partner to Avino Silver & Gold Mines Ltd. Their team consistently delivers a high standard of service, combining technical expertise with a clear understanding of the mining and resource sector. The benefit of having 100% Canadian-based support cannot be overstated, as their team operates with a strong awareness of our operational environment and business needs. Their managed services team is well aligned with the unique requirements of resource-focused organizations, particularly when it comes to building, securing, and maintaining resilient IT infrastructure.
— Nathan Harte, Chief Financial Officer, Avino Silver & Gold Mines Ltd.
Terra Dygital gives us confidence that our technology is working for our business, not creating barriers. Their team takes the time to understand our priorities and provides practical guidance that helps us make informed technology decisions. They are responsive when support is needed and proactive in identifying potential concerns before they affect our day-to-day operations. With Terra Dygital overseeing our systems, infrastructure, and security, our team can remain focused on advancing the business. Their dependable approach and consistent communication give us peace of mind that our IT environment is well managed and prepared to support Maple Gold Mines as our needs continue to evolve.
— Kiran Patankar, President, CEO & Director, Maple Gold Mines Ltd.
Terra Dygital delivers a high level of service combined with specialized expertise in every area of Information Technology, which is a rare find today. TD has advised me in a wide variety of areas ranging from helpdesk services and cybersecurity to installing audio-visual systems in boardrooms, network architecture, resolving Microsoft issues, artificial intelligence and even assisting at interviews for a senior IT position by assessing technical ability of candidates. I have only had positive feedback from users regarding TD services and view hiring TD as an important part of providing employees with access to tools and support to perform their jobs efficiently and securely. If you want fast, expert and friendly service, I highly recommend Terra Dygital.
— April Hashimoto, CFO, Ioneer Ltd.
.png)