Crescent Capital Advisors

AI Governance Program

Version 1.1 · Last updated July 24, 2026

Sujit Maharana · Managing Director, Technology & AI Advisory

The engagement that runs between the diagnostic and the target architecture: five phases that take a portfolio company from unlisted AI systems to a board-ready, regulator-ready governance posture.

What It Is

The AI Governance Readiness Assessment tells a portfolio company where it stands. The Enterprise AI Control Plane describes where it needs to get to. This program is the work between the diagnostic and the target architecture. It runs as a fixed-scope engagement.

Most mid-market portfolio companies cannot produce a list of the AI systems running inside the business. That list would include sanctioned tools, shadow SaaS, internal builds, and agents wired into production data. Because nobody owns the inventory, nobody is accountable for the risk either. Governance starts by making that list.

The Phases

Five phases, run in sequence, each with a checkpoint before the next begins.

Discover. Inventory every AI system in use, sanctioned and unsanctioned, across cloud infrastructure, SaaS subscriptions, and internal builds. Build a model catalog: purpose, data touched, business owner, approval status. Most engagements end this phase with more systems on the list than the CTO expected.

Assess. Score the 65 controls across the five pillars (Data Trust, Model Governance, Agent Autonomy, Enterprise Operations, Responsible AI) against the five-level maturity ladder. Quantify risk by system, not in the aggregate. Determine EU AI Act exposure where it applies.

Map. Trace the data and AI flows: what data feeds which model, which vendors touch it downstream, where the compliance obligations apply. This phase turns "we use AI" into a diagram that a regulator or an acquirer's diligence team can follow.

Control. Put in the guardrails: agent boundaries and tool-call logging, model approval workflows, access controls, and the selection and oversight of any LLM-firewall or monitoring tooling the portco needs. CCA selects and governs the tooling. We do not resell it, and we have no vendor relationship that would influence the recommendation.

Comply. Assemble the evidence that maps to NIST AI RMF, ISO/IEC 42001, and the EU AI Act. A board review, an auditor, or the next buyer's diligence team can then work from a documented record.

Two Engagement Formats

90-Day Assessment & Roadmap. Discover, Assess, and Map, delivered as a maturity scorecard, a risk heat map, an EU AI Act exposure assessment, a 90-day quick-wins plan, and a 12-18 month roadmap. Board-ready on delivery. Fixed-fee, scoped before kickoff.

Implementation Partnership. Executes the roadmap: Control and Comply. Quick wins first, then the managed controls and the evidence program, run as an ongoing operating-partner engagement rather than a fixed-duration project. Fixed-fee, scoped before kickoff.

Every engagement starts with the 90-day assessment. The client decides whether to continue into implementation after the roadmap is delivered.

Deliverables

  • AI model inventory and catalog
  • Control maturity scorecard across the five pillars
  • Risk heat map, ranked by exposure
  • Data and AI flow map
  • EU AI Act exposure assessment
  • 90-day quick-wins plan
  • 12-18 month roadmap
  • RACI for ongoing governance ownership
  • Regulator- and board-ready evidence pack

Who It's For

A portfolio-company CISO or CTO facing a board AI-risk review with no inventory to bring to it. A PE deal team using AI governance as an add-on to PRISM™ technology diligence, where the S dimension flagged AI exposure the deal team needs quantified before close. A GP treating this as a hold-period value lever and an LP-facing demonstration of AI oversight across the portfolio.

How It's Delivered

The program runs in CCA's client platform, the same secure engagement room used for diligence work. The inventory, the findings, and the remediation plan are kept in one place and updated as the estate changes. A PDF would describe the position at kickoff and then go out of date. The client works with one lead, supported by a vetted bench, and receives every deliverable in the same room.

Where It Connects

Start with the AI Governance Readiness Assessment: the free, 65-question diagnostic this program is built to act on. The target state is the Enterprise AI Control Plane: the architecture Control and Comply are building toward. This program covers the work between the two.

Apply the AI Governance Program to a specific portfolio company.

Bring the asset and the thesis. We will apply the framework to the technology estate as it stands and show which findings affect valuation.