If organisations want to deploy thousands (or tens of thousands) of agents, today’s governance, risk assessment, and control (GRC) approaches must be materially automated, or they will become the primary bottleneck to scale.
With sufficient ambition, automation can go beyond ‘faster GRC’ to enable continuous, evidence-driven assurance, a state that is potentially extensible across the broader technology control environment.
To automate the agentic AI GRC journey it must be digitised, which relies on five key elements:
Elements 1, 2 and 3 from the above list sit at the heart of automation, with elements 4 and 5 extending automation through into deployment.
We refer to this end-to-end approach as the Agentic Development Framework (ADF), which is a repeatable lifecycle for designing, assessing, deploying and operating agentic AI with embedded governance. Each stage can be automated independently or delivered as an end-to-end journey. The key stages of the ADF are:
We note the only difference between the ADF, and any other development framework is its focus. The ADF is about changing the operating model as opposed to just building software. Agents, by their very nature, are designed to be embedded into processes and may not be readily visible to the process owners and operators. As such, a focus on the operating model is essential for maintaining understanding and avoiding a loss of control. Nevertheless, this is not a pre-requisite for automating AI GRC.
At the heart of an automated ADF is the creation and lifecycle management of a structured information repository for each agent and its use-case (aka “the Specification”). In this context, the specification differs from typical agent documentation in a number of ways, as follows:
The Specification is created early and incrementally enriched throughout
the ADF process. A key benefit of automation is that risk and control
expectations can be re-evaluated whenever the Specification changes. This
provides an always-current view of required controls and readiness-to-deploy, facilitating an agile development approach.
The Specification set out previously is at the heart of the GRC automation. It provides the backbone which all of the automated tools leverage to “understand” the AI, enabling decision making and action and writing decisions and actions back to the specification. Choosing the right tooling for the Specification that can integrate with the rest of the organisational technology stack is therefore of paramount importance. The components below can all enhance the levels of automation possible:
To start automating the ADF requires organisations to embrace two foundational concepts. First, that deploying an agent into a business process is not only a technology delivery challenge. It is also a change to the target operating model, which we will refer to here as the ‘Agentic Operating Model,’ since controls span the agent as well as the surrounding operating environment, including manual and process controls.
Secondly, organisations will need to establish mechanisms for capturing and maintaining a structured Specification for each agent that meets minimum standards. A practical success measure is that human reviewers can reach decisions from the Specification alone, without recourse to the use-case owner. If they cannot, then neither could a Risk Agent.
Once these foundational elements are in place, the automation of the ADF can truly begin. Our suggested order would be as follows:
While much of the heavy lifting can be fully automated there are key elements that will always remain manual because they ensure that humans remain accountable and in control of their agentified processes. These include:
If organisations want to safely scale their agentic deployment, they need a GRC paradigm that is data-driven and automation-first.
The essential enabler is a structured Specification for each use-case, treated as a living record and integrated into delivery workflows. With this foundation in place, specialist Risk Agents can remove assessment bottlenecks through high-confidence decisions and clear escalation paths, while automated deployment gates and monitoring controls provide continuous assurance.
This is not a simple change programme. The organisations that succeed in implementing an Agentic Development Framework (ADF) will be best able to safely agentify their organisation at pace. Those who cannot will be forced to trade between safety and speed.
References
1. CI/CD refers to Continuous Integration/Continuous Delivery and is used here to describe the software delivery pipeline that moves an AI use case from build and test into release, while enforcing governance controls along the way.
2. A Configuration Management Database (CMDB) is the central inventory used to record technology assets, ownership dependencies, and control requirements.
3. As a point of further clarification, Risk Agents contain “knowledge” about the information they need to be able to deliver their risk judgements. The Guidance Agent curates this information request from each of the risk agents and presents them to the user in a well organised and succinct (i.e., de-duplicated and amalgamated) manner. In this way the “guidance” can be maintained by the human team who are expert in each risk domain. Until such time as the risk agents are in play, the Guidance Agent can be provided with a pre-defined set of information that is needed. In this context, the Guidance Agent itself is simply seeking to fill in the required Specification information.