AI Governance · Security Governance · Technology Risk

Turn ambiguous issues into something you can decide and act on.

Fixing what to decide, who is responsible, how far work is delegated and where people review it — through to the conditions under which implementation and operation can continue.

For IT, information security, risk, and corporate-planning teams

  • Rules for generative AI use, and the criteria for approval and exceptions
  • Security guidelines and internal rules, revised so they can be checked in practice
  • Requirements for vendors, and how their proposals will be compared
  • Risks and options organised ahead of a management meeting
  • An independent review of a policy or vendor proposal you already have

Fragment Practice is an independent advisory practice. Where AI, security, and technology risk meet, it separates the issues and turns them into requirements, decision criteria, role splits, and briefing material. No finished brief required.

Founder Yasuhiro Shinsho worked across systems development, IT risk, security, and cloud and AI risk assessment at BIPROGY, KPMG Consulting, and Nomura Research Institute / NRI Secure Technologies before going independent.

What you can bring

Three scenes you can bring to us.

Start from the one closest to where you are. Each links to what gets organised and what material remains.

AI governance

Rules and decision criteria for AI use

How far generative AI may be used, and on whose approval. The checks and records for each use, and the criteria for approval and exceptions, organised.

  • People have started using generative AI, but what can be entered, how output is used, and who checks it are still unclear
  • The PoC went well, but the roles, review points, and conditions for stopping that real operation needs are not set

Security governance

Security requirements and internal rules

Security guidelines and internal rules, and what customers or a parent company ask of you, organised into requirements and review points that can be checked in practice.

  • Company-wide security governance is the aim, but there is no internal agreement on how to revise the rules and guidelines
  • A customer's security questionnaire, or a query from a regulator or parent company — and how far to respond is not settled

Also within this scene: How to respond, as a company, to an external scheme or standard / Decisions and roles when an incident or outage stops systems (IT continuity)

Technology risk

Evaluating concepts, requirements, and proposals

A platform or service concept, the requirements you give vendors, or a proposal or policy you already have — put into a form you can compare and decide on. Independent review is part of this: it returns findings and open questions, not a verdict, a score, or a maturity level, and it does not stand in for audit, assurance, or certification.

  • There is a platform or service concept, but no agreement on what to require or what to compare
  • Vendor proposals have arrived, and there is no agreed way to evaluate them

Explaining the work to management and stakeholders runs through every scene; where it is needed, the work includes that brief.

Examples

What the practice has done, and what came before.

Shown by sector or former employer, without client names or confidential detail.

Done as Fragment Practice

Financial institution

Governance for expanding generative AI use

Organised, use by use, the information handled, how output is used, human review, and approval and records — and combined system controls with rule-based operation into one approach to control.

  • Draft AI governance policy
  • Control model by use scenario
  • Roadmap for widening use in stages
  • Issues framed for management reporting

Systems integrator

Viability conditions for an AI-enabled security monitoring service

Compared product-led, platform-extension and AI-SOC models, evaluated on cost acceptability, operational transparency, speed to launch, staged scalability, and low dependence on any one vendor.

  • Must / should / could requirements
  • Cost structure
  • Delivery-model comparison
  • Phased introduction and role split

The founder's prior roles

KPMG Consulting (the founder's prior role)

IT continuity and incident response, mainly in heavy industry and manufacturing

Worked on IT business-continuity planning, incident-response readiness with the design and running of exercises, and the standardisation of supplier security assessment.

  • Risk scenarios and recovery steps
  • Role split and exercise scenarios
  • Supplier assessment items and flow

Nomura Research Institute / NRI Secure Technologies (the founder's prior role)

Risk assessment and requirements for cloud and AI use at large enterprises

In third-party and risk assessment of a cloud AI platform, organised the evaluation points — permissions, logging, data protection, whether data is used for external training. In a device-platform renewal, structured requirements that connected the technical design to security needs.

  • Risk-assessment points
  • Security requirements

Ways to work together

Three shapes, priced by scope.

Structuring requirements, comparing options, reviewing independently, and designing who decides and who approves — including where implementation is already under way. Start small: you do not need to pick the final shape before the first conversation.

Focused first step

Initial structuring session

From ¥300,000

Excl. tax · 1–2 sessions

When the issue is real but you cannot yet say what to decide.

One or two sessions to separate the situation, name the decisions, set priorities, and choose the next move.

Bounded sprint

Decision-material sprint

From ¥1,200,000

Excl. tax · 2–6 weeks

When a meeting, report, rule update, or handoff needs material soon.

Research, structuring, review, and drafting that leave decisions, options, risks, open questions, and responsibility ready to use.

Scoped advisory

Scoped advisory support

From ¥600,000 / month

Excl. tax · Monthly or biweekly cadence

When important decisions keep coming and you want an expert at the key points.

A defined cadence with agreed themes, review scope, and response expectations — without a resident PMO or daily operations.

Founder

From development and assessment to risk and governance work.

Yasuhiro Shinsho worked on systems development, vulnerability assessment, and CSIRT at BIPROGY; IT risk, IT continuity, and incident response at KPMG Consulting; and security advisory with cloud and AI risk assessment at Nomura Research Institute / NRI Secure Technologies. He became independent in October 2025. Having worked on both the technical side and the risk and governance side, he handles technology questions and control questions together rather than apart.

Practice notes

Before a decision: what has not been decided yet.

Notes written from practice and generalised. They are the quickest way to see how a problem gets structured here, and they can be read and forwarded without a conversation.

Jul 2026

Design AI Governance as a Review Cycle

AI governance should not be treated as a fixed policy document. As AI products, usage patterns, and organizational conditions change, organizations need a review cycle that updates decision criteria, review points, responsibility boundaries, and handoff material.

Jul 2026

Security Products Are Not Chosen on Performance and Price Alone

Security product decisions depend on more than technical performance and price. This Practice Note examines how existing product environments, licensing structures, the ability to explain the selection, operating burden, and responsibility boundaries shape the decision friction around integrated and specialized security products.

Jun 2026

Define the Outcome Conditions Before the Meeting

A meeting can look productive while the work itself has not moved to its next state. This Practice Note explains how to define outcome conditions before a meeting so decisions, review points, responsibility boundaries, and handoff material remain after the conversation.

Next step

The consultation does not need to be settled yet.

Your current situation, and what has to be decided by when, is enough. The first reply covers which shape is likely to fit. To structure it yourselves first, Products holds reusable working material.