LinedIn Code Skip to main content

Whilst AI can be extremely exciting driving real efficiencies, the bigger questions most are not asking, which is, is my data sage, what guardrails are in place, what is it allowed to do autonomous and where does the human in the loop sit. For a finance or audit-sensitive business, that’s the difference between a productivity win and an incident. Governance isn’t the brake on your AI programme, it’s what makes the programme safe enough to go fast. Value comes from context, permissions and guardrails, not just a model.

about

Most AI failures aren’t model failures. They’re governance failures.

The model rarely embarrasses you by being wrong about arithmetic. It embarrasses you by confidently showing one user another user’s numbers, by inventing a figure that looks plausible, by acting on data it shouldn’t have reached, or by leaving no trail to reconstruct what happened. None of those are “AI problems” in the way people imagine they’re permission, grounding, and auditability problems, and every one of them is preventable by design. The businesses that get AI badly wrong almost always skipped this page.

Six questions to ask before you
trust an agent with anything
real
.

01 · Can it see something it shouldn't?

The AI your vendor ships inside the product. Permission-aware, context-aware, compliant by design and usually the best value, because someone else maintains it. If it already does the job well, our honest advice is: use it.

02 · Where does our data actually go?

The Model Context Protocol “USB-C for AI” lets your ERP data be safely reached from Teams, Microsoft Copilot, Claude or your own apps, with the user’s permissions travelling with the request. Sage Intacct ships a native MCP server; SAP is exposing agents over MCP and A2A.

03 · Could we reconstruct what it did?

Comprehensive audit logging captures every prompt, API call, tool invocation and decision path in real time. As the agent logs every step back to your central system of record, compliance teams can retrace exact workflows, review intermediate outputs and perform detailed forensic analysis whenever necessary.

04 · What happens when it's unsure?

When confidence thresholds drop or an action involves sensitive financial parameters, the agent halts execution and routes the task to a human via automated oversight workflows. It presents its reasoning along with clear options so an authorised user can approve, adjust or reject the proposed next step before anything executes.

05 · Is it making this up?

Agents utilise Retrieval Augmented Generation to ground every answer directly in verified enterprise databases, official documentation and live ERP records. By enforcing strict contextual constraints and requiring verifiable citations for every data point retrieved, the system prevents hallucinations and ensures accurate operational outputs.

06 · Who's already using AI we don't know about?

Shadow AI usage often spreads through unmanaged personal accounts and unauthorised browser extensions, creating data privacy and governance risks. Establishing central governance frameworks, enforcing single sign on integrations and providing secured enterprise AI environments gives organisations full visibility over all active tools.

Interested in utilising AI within your ERP?

Contact Us

ISO 42001, in plain language.

ISO/IEC 42001 is the first international management-system standard for artificial intelligence,  the AI equivalent of what ISO 27001 is for information security. It sets out how an organisation should govern AI responsibly: risk assessment, roles and accountability, lifecycle controls, transparency and continual improvement.

Look for the ISO compliancy when adopting AI into your ERP; we build and advise with ISO 42001 in mind (the permission model, audit trail, human-in-the-loop controls and lifecycle thinking are designed around its principles). To be precise about our claims: aligned with the standard’s framework is not the same as certified to it, and we’ll never blur that line. What we offer is a governance posture built on the right foundations, and honest advice about where you sit against them.

Governance, answered straight.

What is ISO 42001?

ISO/IEC 42001 is the first international management-system standard for artificial intelligence. It does for AI what ISO 27001 does for information security. The standard covers risk assessment, accountability, lifecycle controls, transparency and continual improvement for organisations that build or use AI.

Are you ISO 42001 certified?

No. We are ISO 42001-aligned, which means our frameworks and controls are designed around the standard’s principles, and we are transparent about the difference. If certification matters in your industry, we can help you scope your own path toward it. 

What is shadow AI?

Shadow AI is staff using consumer AI tools without approval, for example pasting company data into public chatbots outside any policy or control. It’s near-universal. The fix is a clear acceptable-use policy plus a sanctioned, permission-aware alternative that’s easier to use than the shadow one. 

Does governance slow an AI programme down?

Done right, it speeds you up. When permissions, approvals, audit trails and fail-closed behaviour are designed in from day one, it’s safe to move quickly and to put agents into production. Programmes without those guardrails are the ones that stall in pilot mode. 

What is an AI governance framework?

An AI governance framework is the set of controls that makes AI use safe and explainable. It covers user-level permissions and least privilege, data residency, an auditable record of every action, human approval on anything that writes, grounding answers in your records instead of training on them, and policy for vendor and shadow-AI risk. ISO/IEC 42001 is the international standard that sets this out. 

What is human-in-the-loop?

Human-in-the-loop means AI drafts and people approve. Anything that would write to a system of record is prepared by the agent, reviewed by a person, and only then posted. When the system is uncertain, or hits a permission boundary, it stops and asks. This behaviour is called failing closed, and it’s what makes agents safe to run in production. 

Do Australian businesses have to comply with AI-specific regulation?

There is no AI-specific law in force in Australia yet. The government has published a Voluntary AI Safety Standard and has consulted on mandatory guardrails for high-risk AI. Existing obligations in privacy, consumer and sector rules already apply to AI use. We track these developments as part of the Governance and Risk Review. 

Get in Touch

Want to know more about SAP Cloud ERP? Contact the SAP Cloud ERP team at Leverage Technologies on