Governance · Risk · Compliance · Audit

Governance & Compliance

Aethora Labs Inc. operates a single, integrated governance and assurance system that converts legal, contractual, security, privacy, technology, AI and operational obligations into owned risks, documented controls, testable evidence and executive decisions. This is a summary of that enterprise program; framework alignment indicates design reference and does not represent certification, attestation or regulatory approval.

Effective 28 August 2026

Program intent

The program establishes a scalable, evidence-driven governance and assurance system appropriate for an enterprise data, cybersecurity, software and operational-intelligence business that acquires, licenses-in, curates and productizes proprietary datasets. It is designed to support executive oversight, source diligence, regulated data handling, partner confidence and future external assurance.

Enterprise standard. No material data asset, source or licensing-in engagement, counterparty relationship, AI use case, production system or critical vendor operates without an identified business owner, risk classification, applicable obligations, minimum controls and an evidence trail sufficient for independent review.

Harmonized control model

The program uses a harmonized control model. Alignment indicates design reference; it does not imply certification, attestation or regulatory approval.

Framework alignment
Framework / standardPrimary use in this program
COSO Internal Control — Integrated FrameworkEnterprise control environment, risk assessment, control activities, information/communication and monitoring.
NIST Cybersecurity Framework (CSF) 2.0Cybersecurity governance and operational risk across Govern, Identify, Protect, Detect, Respond and Recover.
ISO/IEC 27001:2022Information security management-system discipline and risk-based control governance.
NIST AI RMF 1.0 + GenAI ProfileAI governance, model/use-case risk, trustworthiness, measurement and lifecycle controls.
AICPA SOC 2 Trust Services CriteriaCustomer assurance and controls relevant to security, availability, processing integrity, confidentiality and privacy, as applicable.
COBIT / Three Lines ModelTechnology governance, accountability and independent assurance concepts.
Applicable privacy/data laws and contractsObligation-specific requirements captured in the Compliance Obligations Register; applicability determined by jurisdiction, data type, role and contract.

Core GRC principles

GRC is a management discipline, not a documentation exercise. Every principle maps to required management behavior.

  • Accountability. Every material risk and control has one accountable owner.
  • Risk-based proportionality. Control rigor scales with data sensitivity, system criticality, financial exposure and regulatory/customer impact.
  • Need-to-know and least privilege. Access is explicitly authorized, time-bounded where feasible, monitored and periodically recertified.
  • Evidence over assertion. Control performance is demonstrated through durable evidence, not verbal confirmation.
  • Segregation of duties. Approval, execution, custody and review are separated when concentration could enable error, fraud or misuse.
  • Privacy and security by design. Data minimization, purpose limitation, de-identification, retention and security are designed into workflows.
  • Independent challenge. Second-line oversight and internal audit may challenge business decisions without retaliation or operational interference.
  • Continuous improvement. Findings, incidents, near misses, customer diligence and regulatory change feed the control environment.

Governance & three lines

Oversight runs from the Board through executive councils to independent assurance, with accountability separated across three lines.

Three lines accountability
LineWhoResponsibilities
1st — Own & OperateBusiness, product, data, engineering, sales/partnerships, finance, operationsOwn risk; design and execute controls; maintain evidence; remediate deficiencies.
2nd — Govern & ChallengeGRC, compliance, privacy, security risk, legal advisorySet policy; interpret obligations; monitor risk; test selected controls; challenge decisions; approve exceptions within authority.
3rd — Independent AssuranceInternal Audit / independent assurance providerAssess governance, risk and controls independently; report functionally to Board/Committee; validate closure of material findings.

Enterprise risk management

Aethora maintains enterprise and business-unit risk registers. Risks are expressed as cause-event-impact statements, linked to objectives, obligations, controls, owners and remediation. Inherent risk is assessed before controls; residual risk is assessed after control design and operating effectiveness.

Risk bands and default response
ScoreBandDefault response
1 – 4LowManage within normal controls; monitor through routine operations.
5 – 9ModerateNamed owner and treatment plan where improvement is cost-effective; periodic review.
10 – 16HighFormal treatment or documented acceptance; second-line challenge; executive visibility.
17 – 25CriticalImmediate executive escalation; avoid, reduce or transfer unless explicitly accepted under Board-level authority.

Risk appetite, in brief

  • Zero appetite for intentional misuse, concealment, falsification or unauthorized use of acquired data outside license scope.
  • Very low appetite for unencrypted sensitive data, unmanaged privileged access, unknown data provenance, or ingestion without documented authorization.
  • Low appetite for privacy, security, sanctions, anti-bribery, fraud, retaliation or contractual compliance breaches.
  • Moderate, controlled appetite for product, market and AI experimentation when data, security, legal and customer risks are explicitly assessed and monitored.

Control framework & lifecycle

Every key control is specific enough that a qualified reviewer can determine what occurs, who performs it, when, what population is covered, what evidence is produced, what defines success and what happens when the control fails. Controls move through a defined lifecycle:

  • Design. Translate risk/obligation into a control objective and statement.
  • Approve. Owner and second line confirm accountability, evidence and frequency.
  • Implement. Workflow, access, configuration, training and evidence repository are established.
  • Operate. Performer executes the control and resolves exceptions.
  • Test. Design and operating effectiveness are independently assessed at risk-based intervals.
  • Remediate. Deficiencies receive severity, root cause, owner, due date and corrective action.
  • Reassess. Control/risk mapping is updated after incidents, changes, findings or regulatory developments.

Compliance management

Compliance is managed through a traceable obligation-to-control model. The authoritative record is the Compliance Obligations Register (COR), which documents applicability, owner, implementation, evidence and monitoring for each requirement.

Legal applicability. The program does not assume every privacy or sector rule applies to every activity. Legal/GRC documents applicability by data type, jurisdiction, role, counterparty and use case before representing compliance.

Data governance, privacy & AI

A Data Governance & Privacy Council governs data classification, lawful use, de-identification, retention, acquisition and licensing-in controls, and data-subject/source obligations. An AI Governance Council approves material AI use cases, risk tiering, validation, monitoring and restricted uses. For the technical detail of how data is extracted, de-identified and handled, see the Technical FAQ.

Third-party & source risk

Data sources, counterparties and material vendors are tiered and diligenced for security posture, data provenance, subcontractor (fourth-party) exposure, concentration and insolvency risk. Onboarding a high-risk data source or counterparty requires GRC, security and legal consultation with council-level approval based on tier.

Internal audit & issue management

Internal Audit provides independent, risk-based assurance to the Board/Committee and validates remediation. Deficiencies flow through issue and CAPA (corrective and preventive action) management with severity, root cause, owner and due date. Exceptions to key preventive controls require documented business justification, risk assessment, compensating controls, a named risk owner, an expiration date and written approval at the designated authority level.

Incident, resilience & records

Security and technology risk is reviewed continuously, with incidents handled through a defined process covering identification, containment, investigation, remediation, documentation, escalation and required notification. Program records, testing evidence, risk decisions, findings and remediation artifacts are retained under the corporate records schedule and legal-hold requirements.

See also our Privacy Policy and Terms of Service.