Governance

AI Governance, Corporate Governance and Financial Oversight

Governance is no longer a matter of policy documents and annual attestations. It is a matter of evidence: what was known, when, by whom, and what was done about it.

Cobotex assists boards, CEOs, executives and executive teams in identifying governance issues across three connected areas:

  • AI governance readiness, including the governance of AI agents
  • Corporate governance, including board mechanics, committees and evaluation
  • Financial oversight, including liquidity, controls and exceptions

We assist you in identifying where the organisation may be exposed, and in recommending adjustments to strengthen its position.

Where Governance Is Heading

Governance expectations are tightening across the European Union, the United Kingdom, North America, the Gulf and the Commonwealth. Directors, executives and officers are increasingly expected to demonstrate that they exercised oversight — not merely that a policy existed.

Cobotex assists organisations in identifying where these expectations may affect them, and in recommending adjustments to meet them.

AI Governance Readiness

Cobotex assists organisations in identifying the AI systems and AI agents in use, and in reviewing the governance position around them. We help you form a clearer view of where the organisation stands, and we recommend adjustments where we see room to strengthen the position.

What We Assist With

  • Identifying AI systems and agents across the organisation — including systems introduced by departments without central visibility
  • Reviewing the governance position around each system: ownership, purpose, data touched, and the obligations that may apply
  • Reviewing AI policies, controls and evidence against the expectations that apply to your organisation
  • Reviewing how the organisation transforms with AI — strategy alignment, portfolio, benefits, operating model, workforce, model dependency, risk linkage, assurance, agentic operations, value and cost
  • Reviewing data governance and privacy in an AI context, including impact assessments and processing records
  • Reviewing HR-AI and automated decision-making in employment — recruitment, screening, promotion, performance, scheduling, termination and pay

What You Receive

A structured view of your AI governance position, with findings, observations and recommended adjustments. We recommend that any output be reviewed by your legal team before it is relied upon.

Agentic AI Governance

Which agents run in our organisation? How autonomous are they? Who delegated their authority? Can they be stopped? What did they actually do?

As of today, no major jurisdiction has issued rules that deal specifically with AI agents. But that does not leave a gap in accountability. Obligations attach to the deploying organisation through existing law — data-protection law, sector rules, directors' duties — and through emerging good-practice profiles.

Cobotex assists organisations in forming a clearer view of the agents in use and of the governance position around them.

What We Assist With

  • Agent inventory — assisting in identifying the agents running across your platforms and, where authorised, in your own code
  • Autonomy classification — assisting in classifying each agent on a five-level scale, from Suggest to Autonomous
  • Kill-switch readiness — reviewing whether each agent above the lowest tier can be stopped, and who owns the switch
  • Delegation mapping — reviewing which human delegated which authority to which agent
  • Tool and data permissions — reviewing what each agent can read, write, transact and communicate externally, and what data classes it touches
  • Agent incident workflow — assisting in defining what counts as an agent incident and what the escalation path is
  • Runtime governance review — reviewing how agent behaviour is governed at runtime

What You Receive

A structured view of your agent governance position, with findings, observations and recommended adjustments. We recommend that any output be reviewed by your legal team before it is relied upon.

Corporate Governance

Cobotex assists boards, CEOs, executives, company secretaries and executive teams in reviewing the mechanics and the evidence of corporate governance. We help you form a clearer view of where the organisation stands, and we recommend adjustments where we see room to strengthen the position.

What We Assist With

  • Board mechanics — reviewing quorum, voting, conflicts, executive sessions, minutes and decision records
  • Board packs and board papers — assisting the company secretary and executive team in assembling a board pack that reads well and holds up
  • CEO governance report — assisting the CEO in preparing the governance report ahead of board meetings with board members, shareholders, investors and other stakeholders
  • Board evaluation — assisting the board in a structured annual evaluation of composition, skills, oversight, information quality, meeting and committee effectiveness, culture and chair effectiveness
  • 360 evaluation — assisting in bringing together board, executive, employee, customer, investor, regulator and supplier views, with appropriate anonymity
  • Governance calendar and policy discipline — assisting the company secretary in maintaining a view of what is due and which policies are current, accepted and attested
  • Delegation of authority — reviewing authority limits, breaches and escalation
  • Conflicts and related-party transactions — reviewing the conflicts register, recusal and related-party arrangements
  • Group and subsidiary governance — reviewing entity governance, reserved matters and intra-group dealings

What You Receive

A structured view of your corporate governance position, with findings, observations and recommended adjustments. We recommend that any output be reviewed by your legal team before it is relied upon.

Audit and Assurance Support

Cobotex supports internal audit functions and audit committees with structured governance assistance. We do not perform audits, and we do not issue audit opinions. Our role is to assist you in preparing, organising and reviewing the evidence that an audit or an assurance review may require.

What We Assist With

  • Audit planning — assisting in assembling the audit universe and a risk-ranked plan from your registers, incidents and indicators
  • Population testing — running structured tests over your data and reporting exceptions
  • Document review — assisting in extracting and matching documents to records, and flagging missing evidence
  • Control testing — re-performing tests on data you provide, and tracking results
  • Working papers — assisting in assembling evidence links and drafting neutral descriptions
  • Findings tracking — tracking findings and remediation evidence through to closure
  • Audit committee pack — assisting in preparing a one-page pack with plan progress, findings, remediation and external-auditor points

What Stays With You

Some things must stay with your people, and we will not cross that line:

  • Approving the audit plan and judging the scope
  • Deciding whether an exception matters
  • Interpreting ambiguous or conflicting documents
  • Concluding on control effectiveness
  • Reviewing and signing working papers
  • Issuing findings and ratings
  • Forming any audit opinion or conclusion
  • Judging and safeguarding independence
  • Conducting inquiry and judging answers

A Clear Statement of Scope

Every output we produce in this area is clearly labelled as assistance, not as an audit or an assurance opinion. A finding becomes official only when a named competent person at your organisation — your chief audit executive, or an accredited partner auditor — issues it.

Financial Oversight

Cobotex supports CFOs and audit committees with structured assistance on the financial indicators that matter to a board. We do not prepare, audit or certify financial statements. All financial figures are client-supplied, and we treat them as such.

What We Assist With

  • Liquidity and runway — reviewing liquidity headroom, runway and forecast accuracy
  • Budget and variance — reviewing budget versus actual, with variance analysis
  • Working capital and leverage — reviewing DSO, DPO and net debt to EBITDA
  • Control and exception review — reviewing segregation-of-duties conflicts, journal anomalies and control exceptions
  • Covenant headroom — reviewing the covenant position against facility agreements
  • Audit committee financial pack — assisting in preparing a one-page financial oversight pack

What We Do Not Do

  • We do not prepare financial statements
  • We do not audit or certify financial information
  • We do not consolidate financial information across entities as a statutory consolidation
  • We do not provide investment advice
  • We do not forecast revenue or earnings

Governance Domains

We assist across a broad map of governance domains, covering:

AI Governance and Agentic AI

DomainWhat We Cover
AI GovernanceInventory, classification and review of AI systems across jurisdictions
AI TransformationStrategy, portfolio, benefits, operating model, workforce, model dependency, risk linkage, assurance, agentic operations, value and cost
Data Governance and PrivacyGDPR-for-AI, impact assessments, processing records, data-subject requests
Agentic AI GovernanceAgent inventory, autonomy tiers, kill-switch readiness, delegation chains, runtime evidence, incident workflow
HR-AI and Automated Decision-MakingRecruitment, screening, promotion, performance, scheduling, termination and employment-law and works-council requirements

Corporate Governance

DomainWhat We Cover
Board Mechanics, Committees, Board Evaluation, ConflictsMeetings, quorum, conflicts register, committee effectiveness, annual board evaluation
Financial OversightLiquidity, budget discipline, covenant headroom, forecast accuracy
Enterprise Risk ManagementNon-financial risk taxonomy, risk appetite, key-risk indicators, risk actions
Compliance ManagementObligations with owner and evidence, overdue items, across all applicable laws
Internal ControlMaterial controls, test results, deficiencies, remediation
Audit and AssuranceAudit universe and plan, engagement management, findings and remediation, committee pack
Cybersecurity and Operational ResilienceIncident clocks, recovery tests, board training, resilience framework
Ethics, Conduct, Anti-Bribery, WhistleblowingSpeak-up reports, training, conflicts, third-party due diligence
ESG and SustainabilityMateriality, climate and social reporting governance, supply-chain due diligence, emissions data linkage
Board Composition, Nomination, Remuneration, SuccessionSkills coverage, independence, succession cover, remuneration policy review
Shareholder and Disclosure GovernanceDisclosure meetings, insider lists, market-abuse compliance
Treasury, Capital Allocation, Tax GovernanceTreasury-policy exceptions, hedging within limits, tax-risk items
Third-Party and Supply-Chain GovernanceCritical suppliers assessed, concentration, supplier incidents
Business Continuity and Crisis ManagementRecovery tests, crisis exercises, tested plans
Legal, Litigation, Regulatory Inquiries, IPOpen claims, regulator responses, IP renewals
Sanctions, Export Controls, AMLScreening alerts, training, filings
Competition-Law ComplianceStaff training, trade-association contacts, open investigations
Health, Safety and EnvironmentLost-time incidents, corrective actions, permits
Quality and Product SafetyNonconformities, recalls, supplier audit completion
IT and Digital GovernanceCritical systems with owners, change failures, end-of-life systems
Group and Subsidiary GovernanceEntities with current directors and filings, reserved matters, intra-group dealings
Policy Management and Delegation of AuthorityPolicies current, accepted, attested; authority-limit breaches
Governance CalendarWhat is due in the next 90 days
Public-Sector GovernanceCompliant procurements, audit findings, disclosures
Related-Party TransactionsTransactions approved before execution, undisclosed items

Service Levels

Every service is delivered at one of three levels, depending on the depth you need and the maturity of your current governance.

LevelWhat It Means
ReviewA structured assessment of the current position, with findings and observations
BuildWorking with your teams to assist in putting in place the governance structure and evidence
AssureA periodic re-review, to assist in confirming that the governance structure is being maintained

What Every Engagement Includes

  • A named Cobotex adviser, accountable for the engagement
  • A written scope and timeline, agreed before we start
  • A structured methodology, applied consistently
  • Findings with sources, dates and confidence levels where applicable
  • Options with trade-offs, never instructions
  • A recommended action plan with owners and dates
  • A recommendation that any output be reviewed by your legal team before it is relied upon
  • A clear statement of what is outside our scope

Standards and Trust

Cobotex is a governance advisory firm. We assist organisations in identifying governance issues and in recommending adjustments. Our role is to assist, not to certify, guarantee or assume responsibility for any outcome.

We assist in identifying governance issues. We help you form a clearer view of where the organisation stands against the expectations that may apply to it.

We recommend adjustments. Where we see room to strengthen the governance position, we recommend adjustments for your consideration.

We work alongside your existing advisers. We recommend that any governance output be reviewed by your legal team before it is relied upon, acted upon or shared.

We do not certify compliance. We do not state that an organisation is compliant, and we do not issue audit opinions, legal advice, financial advice or investment advice.

How We Protect Your Information

  • Confidentiality. Everything you share with us is treated as confidential. We do not disclose your information to third parties without your instruction, except where the law requires it.
  • Data minimisation. We ask for the information we need and no more.
  • Privilege. Where you instruct us to work under legal privilege, we work within that instruction.
  • Retention. We retain engagement records for the period required by law and by our professional obligations.
  • Security. We apply appropriate technical and organisational measures to protect the information you entrust to us.

The Basis of Our Relationship

Every engagement is governed by a signed contract, which sets out the scope, the basis of the relationship and the responsibilities of each party. Nothing on this website constitutes an offer, a professional engagement, or a binding commitment. No information on this website should be relied upon as legal, audit, financial or investment advice.

A Clear Statement on Certifications

Cobotex does not describe itself as "certified" in any standard unless a certificate has been issued by the relevant accredited body. Where we hold certifications, we state the standard, the issuing body and the date. Where we do not, we say so.

Discuss Your Governance Priorities

If governance is on your board's agenda, we would welcome a conversation.