Governance · Risk · Compliance · Audit
Governance & Compliance
Aethora Labs Inc. operates a single, integrated governance and assurance system that converts legal, contractual, security, privacy, technology, AI and operational obligations into owned risks, documented controls, testable evidence and executive decisions. This is a summary of that enterprise program; framework alignment indicates design reference and does not represent certification, attestation or regulatory approval.
Effective 28 August 2026
Program intent
The program establishes a scalable, evidence-driven governance and assurance system appropriate for an enterprise data, cybersecurity, software and operational-intelligence business that acquires, licenses-in, curates and productizes proprietary datasets. It is designed to support executive oversight, source diligence, regulated data handling, partner confidence and future external assurance.
Harmonized control model
The program uses a harmonized control model. Alignment indicates design reference; it does not imply certification, attestation or regulatory approval.
| Framework / standard | Primary use in this program |
|---|---|
| COSO Internal Control — Integrated Framework | Enterprise control environment, risk assessment, control activities, information/communication and monitoring. |
| NIST Cybersecurity Framework (CSF) 2.0 | Cybersecurity governance and operational risk across Govern, Identify, Protect, Detect, Respond and Recover. |
| ISO/IEC 27001:2022 | Information security management-system discipline and risk-based control governance. |
| NIST AI RMF 1.0 + GenAI Profile | AI governance, model/use-case risk, trustworthiness, measurement and lifecycle controls. |
| AICPA SOC 2 Trust Services Criteria | Customer assurance and controls relevant to security, availability, processing integrity, confidentiality and privacy, as applicable. |
| COBIT / Three Lines Model | Technology governance, accountability and independent assurance concepts. |
| Applicable privacy/data laws and contracts | Obligation-specific requirements captured in the Compliance Obligations Register; applicability determined by jurisdiction, data type, role and contract. |
Core GRC principles
GRC is a management discipline, not a documentation exercise. Every principle maps to required management behavior.
- Accountability. Every material risk and control has one accountable owner.
- Risk-based proportionality. Control rigor scales with data sensitivity, system criticality, financial exposure and regulatory/customer impact.
- Need-to-know and least privilege. Access is explicitly authorized, time-bounded where feasible, monitored and periodically recertified.
- Evidence over assertion. Control performance is demonstrated through durable evidence, not verbal confirmation.
- Segregation of duties. Approval, execution, custody and review are separated when concentration could enable error, fraud or misuse.
- Privacy and security by design. Data minimization, purpose limitation, de-identification, retention and security are designed into workflows.
- Independent challenge. Second-line oversight and internal audit may challenge business decisions without retaliation or operational interference.
- Continuous improvement. Findings, incidents, near misses, customer diligence and regulatory change feed the control environment.
Governance & three lines
Oversight runs from the Board through executive councils to independent assurance, with accountability separated across three lines.
| Line | Who | Responsibilities |
|---|---|---|
| 1st — Own & Operate | Business, product, data, engineering, sales/partnerships, finance, operations | Own risk; design and execute controls; maintain evidence; remediate deficiencies. |
| 2nd — Govern & Challenge | GRC, compliance, privacy, security risk, legal advisory | Set policy; interpret obligations; monitor risk; test selected controls; challenge decisions; approve exceptions within authority. |
| 3rd — Independent Assurance | Internal Audit / independent assurance provider | Assess governance, risk and controls independently; report functionally to Board/Committee; validate closure of material findings. |
Enterprise risk management
Aethora maintains enterprise and business-unit risk registers. Risks are expressed as cause-event-impact statements, linked to objectives, obligations, controls, owners and remediation. Inherent risk is assessed before controls; residual risk is assessed after control design and operating effectiveness.
| Score | Band | Default response |
|---|---|---|
| 1 – 4 | Low | Manage within normal controls; monitor through routine operations. |
| 5 – 9 | Moderate | Named owner and treatment plan where improvement is cost-effective; periodic review. |
| 10 – 16 | High | Formal treatment or documented acceptance; second-line challenge; executive visibility. |
| 17 – 25 | Critical | Immediate executive escalation; avoid, reduce or transfer unless explicitly accepted under Board-level authority. |
Risk appetite, in brief
- Zero appetite for intentional misuse, concealment, falsification or unauthorized use of acquired data outside license scope.
- Very low appetite for unencrypted sensitive data, unmanaged privileged access, unknown data provenance, or ingestion without documented authorization.
- Low appetite for privacy, security, sanctions, anti-bribery, fraud, retaliation or contractual compliance breaches.
- Moderate, controlled appetite for product, market and AI experimentation when data, security, legal and customer risks are explicitly assessed and monitored.
Control framework & lifecycle
Every key control is specific enough that a qualified reviewer can determine what occurs, who performs it, when, what population is covered, what evidence is produced, what defines success and what happens when the control fails. Controls move through a defined lifecycle:
- Design. Translate risk/obligation into a control objective and statement.
- Approve. Owner and second line confirm accountability, evidence and frequency.
- Implement. Workflow, access, configuration, training and evidence repository are established.
- Operate. Performer executes the control and resolves exceptions.
- Test. Design and operating effectiveness are independently assessed at risk-based intervals.
- Remediate. Deficiencies receive severity, root cause, owner, due date and corrective action.
- Reassess. Control/risk mapping is updated after incidents, changes, findings or regulatory developments.
Compliance management
Compliance is managed through a traceable obligation-to-control model. The authoritative record is the Compliance Obligations Register (COR), which documents applicability, owner, implementation, evidence and monitoring for each requirement.
Data governance, privacy & AI
A Data Governance & Privacy Council governs data classification, lawful use, de-identification, retention, acquisition and licensing-in controls, and data-subject/source obligations. An AI Governance Council approves material AI use cases, risk tiering, validation, monitoring and restricted uses. For the technical detail of how data is extracted, de-identified and handled, see the Technical FAQ.
Third-party & source risk
Data sources, counterparties and material vendors are tiered and diligenced for security posture, data provenance, subcontractor (fourth-party) exposure, concentration and insolvency risk. Onboarding a high-risk data source or counterparty requires GRC, security and legal consultation with council-level approval based on tier.
Internal audit & issue management
Internal Audit provides independent, risk-based assurance to the Board/Committee and validates remediation. Deficiencies flow through issue and CAPA (corrective and preventive action) management with severity, root cause, owner and due date. Exceptions to key preventive controls require documented business justification, risk assessment, compensating controls, a named risk owner, an expiration date and written approval at the designated authority level.
Incident, resilience & records
Security and technology risk is reviewed continuously, with incidents handled through a defined process covering identification, containment, investigation, remediation, documentation, escalation and required notification. Program records, testing evidence, risk decisions, findings and remediation artifacts are retained under the corporate records schedule and legal-hold requirements.
See also our Privacy Policy and Terms of Service.
