Solutions · Governance and ongoing care

Systems and AI with rules, with someone watching, and with a trail you can check afterwards

PDPA and ISO kept current, rules that govern the AI, and someone watching the system every month — every item has an owner, a review cycle and a trail you can go back through

Every system under the same rules, with people reviewing on a cycle

Who this bundle is for

  • Companies that have to file PDPA paperwork or face an ISO audit every year, and spend weeks collecting the documents each time
  • Organisations already running AI or agents (from any vendor) with nobody watching when they go quiet, answer wrongly, or run the costs up
  • Owners whose books have been in the red for months and who want a plan measured week by week, not a thick report

We usually start with

We usually start with the Security & Access Review, because it takes only 2 weeks and its findings tell you whether Compliance Copilot or Managed AI Ops should come next. If the business is losing money, start with Turnaround 60 Days before anything else. All of it begins with a small audit of this bundle, and a free 30-minute call with no obligation.

Control register

Everything that must not slip sits in one register

Each item has a named owner and its own review cycle — pick a category to see who holds what, and what is running late

  • Record of processing activities (RoPA)Your DPOUpdated when a new system appearsPassed latest round
  • Data subject request queue (DSAR)Legal teamDeadline counted on every requestReview due
  • ISO document versions and review datesThe owner of each documentOn its review datePassed latest round
  • Evidence pack ready for an auditWe compile itMonthlyPassed latest round
Every document is a draft — your legal counsel or DPO reviews and signs itCompliance Copilot

Without this review cycle

Every document request or audit round stops the team for a week of hunting files down, still unsure which version is the latest

A sample register (the names and statuses are made up) — the real one is built around your systems and your owners

Monthly care cycle

Someone watches every month not handed over and gone

The cycle runs itself every month — tap to see what happens to your systems each week

Monthly cycle

Check

Week 1

Week 1

What we check for you this month

  • A watch agent goes through every one: is it running on time, has answer quality slipped
  • Controls due this month come up with the name of whoever owns them
  • Model spend against the month before

Our team does the watching — your own owners see the same screen

What you end up holding

At month end you get documents that stand up to a check

Governance status summarySent at month start
Controls in total13 items
Passed this month's review9 items
Due for review2 items
Overdue2 items
Passed latest round69%
In this month's queue31%
Usage and access logCheckable afterwards
AI requests today1,284
Refused on permissions37
Sensitive-tier dataruns in-house only
Report to the DPOmonthly, automatic

Every approval leaves a trace of who pressed it and when · the policy is enforced by the system, not left to users' discipline

Findings that need a decisionWaiting on the owner
  • Close 2 accounts for staff who have left

    Who acts: Department head + IT

  • Register the agent that has just gone live

    Who acts: System owner

  • Sign the draft reply to 1 DSAR request

    Who acts: Your DPO

We do not close access or sign documents for anyone — we make sure each item reaches the person who has to act, on time

Mock sample — names and numbers are made up. The real one follows your business.

What is in this bundle

Pick them one at a time you do not have to take the whole bundle

01 · Compliance Copilot

PDPA and ISO paperwork ready to submit at any time

  • A RoPA draft that updates automatically, with a change history
  • A DSAR queue: take the request, find the data, draft the reply, count the days to the deadline
  • Version control for ISO documents, with review-date reminders
Google Drive / SharePointHR and CRM systemsEmail / request forms

from 2 weeks to 2 days

Time to prepare documents for an audit

RoPA and the DSAR queue in use in 4 weeks; ISO depends on how many documents there are

02 · AI Governance & Policy

AI usage rules that are actually enforced

  • A one-page AI usage policy, with a version written for general staff
  • A register of every AI and agent in the company: what it does, what data it uses, who owns it
  • A filter for personal and confidential data before anything reaches a model
Private LLM or the API you useSSO / user accountsOther vendors' agents

caught before sending in 100% of the cases the rules cover

Sensitive data sent into AI by accident

Policy and register done in 2 weeks; the filter and the reporting in use in 4–6 weeks

03 · Managed AI Ops

Someone watching your agents daily, charged monthly

  • An onboarding audit of the existing setup before we take it on (required for agents someone else built)
  • A status screen for every agent: when it last ran, what percentage succeeded, what it cost
  • Alerts and fixes within the agreed time (SLA), with every incident logged
Every agent you runModel providers / Private LLMYour team's LINE or email

from days to under 1 hour

Time an agent is down without anyone knowing

Onboarding audit 1–2 weeks, then monthly care; cancel at any time

04 · Turnaround 60 Days

A loss-making business back under control in 60 days

  • A map of where the money leaks: margin per product, costs that can be cut, overdue debtors, ranked by impact
  • An 8-week plan with a target number for every week
  • An agent tracking spending and cash flow, alerting you when it goes off plan
Accounting softwarePOS / sales systemBank (statements)

within 7 days

Time to see every leak

60 days: 1 week of diagnosis and 8 weeks of following the plan

05 · Security & Access Review

Know who can get into what, and close the access that should not be there

  • A register of accounts and permissions across every system, with an owner named
  • A ranked risk report: dormant accounts, excess permissions, no 2FA, shared passwords
  • A quarterly access review that department heads confirm on one page
Google Workspace / Microsoft 365HR systemERP / CRM / accounting software

down to 0 within 30 days

Dormant accounts of people who have left

First review done in 2 weeks; the quarterly cycle can start immediately

We are not a law firm and we do not certify anyone against any standard — we keep the documents and the evidence ready; the interpretation and the signature stay with your own advisers

FAQ

The questions we hear most about this bundle

Is keelz a legal advisor, or can you certify us for PDPA/ISO?

No. keelz builds the systems and agents that keep the documents and the evidence ready at all times. Interpreting the law, certifying and signing are the job of your legal counsel, DPO or certification auditor. We work alongside them, and we cut the time they need considerably.

Our agents were built by another vendor. Can Managed AI Ops look after them?

Yes, but only after a 1–2 week onboarding audit, so we know what the system does, what it connects to, and where the risks sit. If we find the existing setup cannot be maintained, we will tell you straight, with the options, before any monthly fee starts.

How is the Managed AI Ops monthly fee calculated, and how long is the contract?

It is charged monthly, based on the number of agents and the SLA level you need. For a small business it is typically around the cost of one part-time member of staff. You can cancel at any time with notice in the monthly cycle; there is no annual lock-in.

Does Turnaround 60 Days guarantee we will be profitable again?

It does not guarantee a profit — that rests with your decisions and the market. What is guaranteed is that within 7 days you see the full picture of where the money leaks, and that for all 8 weeks you get the real numbers against the plan every Monday morning. If week 4 shows no sign of improvement, we adjust the plan or stop, with no charge for the rest.

Will our access data and PDPA documents leave the company?

No. The agents in this bundle run in your own cloud account or on a server you choose, and can reach only the systems you grant access to. Every access is logged and can be checked afterwards, and we sign a confidentiality agreement and a data processing agreement before every engagement.

Data leaks, approvals and rolling back are covered on the data security page

Start with a small audit of the governance bundle

A free 30-minute call. Tell us what documents you have to file, what AI you are running, or where the numbers stand. We will tell you which one to start with — and there is no obligation of any kind.

Free consultation

Book a free call 30 minutes