OCI DOMAIN FOUR
SaaS and AI governance
This is the fastest moving domain in the index and usually the least controlled. Individual tools are inexpensive, adopted locally, and approved by someone acting reasonably. The exposure is not created by any single decision. It accumulates from a large number of small ones that nobody is aggregating.
Does any of this sound familiar?
You could not produce a complete list of the SaaS applications currently in use across the organisation.
Staff are using AI tools with company data. Which tools, and which data, is not something anyone tracks.
People who left months ago still have active accounts on systems that were never part of the leaver process.
Departments buy tools on expense cards. IT finds out at renewal, or when something goes wrong.
You have a policy on approved software. It was written before the tools people are actually using existed.
What this domain examines
Application inventory
Whether a current and complete record of SaaS applications in use exists and is maintained.
Procurement route
Whether new tools enter through a defined process or through individual expense claims.
Identity and access coverage
Whether applications sit behind central identity, or hold their own separate credentials.
Offboarding
Whether leaver processes reach every system, including those procured outside IT.
AI tool usage and data handling
Whether it is known which AI services are in use, what data is submitted to them, and how that data is retained.
Licence reconciliation
Whether what you pay for matches what is used, and whether anyone reviews the difference.
Why this goes unnoticed
No individual SaaS purchase is large enough to trigger scrutiny. A team lead signs up for something at a modest monthly cost to solve a real problem, and does so entirely in good faith. Multiply that across departments and years, and the organisation is running an estate that nobody specified, nobody inventoried, and nobody can fully describe.
AI has accelerated this considerably. Tools that process company information are now available instantly, often free at the point of use, and adopted by individuals rather than departments. The governance question is not whether people should use them. It is whether anyone can state what has already been submitted to them, where that data now resides, and under whose terms.
Offboarding is where the accumulated cost becomes concrete. A leaver process built around your core systems will remove access to those systems, and will silently miss every application procured outside that process. The result is active credentials belonging to people who left the organisation, on systems that IT was never told about.
How SaaS and AI Governance is scored
Every domain in the Operational Confidence Index is scored 6 to 18. A higher score means lower operational confidence, so the highest scoring domain in your result is the one to start with.
What we usually hear
“We have an approved applications list.”
Most organisations do. The index asks when it was last reconciled against actual usage, and whether the tools adopted in the last twelve months appear on it.
“IT provisions everything centrally.”
That is the intent in most organisations. It is worth confirming against expense data, because departmental purchasing rarely announces itself and is usually invisible until renewal.
“We blocked the public AI tools.”
Blocking at the network edge addresses managed devices on the corporate network. It does not address personal devices, home working, or the AI features now built into software you already licence.
“This feels like a compliance exercise.”
It is closer to a cost and exposure exercise. Unused licences, orphaned accounts and unreviewed data processing are commercial problems before they are compliance ones, and they are usually easier to justify fixing on that basis.
Questions about this domain
How is SaaS and AI governance scored in the OCI?
The Operational Confidence Index uses six questions, each scored 0 to 3, giving a domain range of 6 to 18. A higher score means lower operational confidence, so a high score here indicates this is where to start.
Does this cover AI tools specifically?
Yes. The domain covers which AI services are in use, what data is submitted to them, and whether that usage sits inside any governance framework.
We do not think we have a shadow IT problem.
That may be correct, and the index will show it quickly. In most organisations the gap between the expected inventory and the actual one is larger than anyone predicts before they check.
Does Rullan Scott resell SaaS or AI products?
No. There are no manufacturer relationships and no commission behind any recommendation.
What happens after I complete it?
You receive a score, a breakdown by domain, and a report. If you want to talk it through, you can book thirty minutes with a cofounder. There is no follow up unless you ask for one.
The other three domains
Find out what is running that you have not counted.
Twenty four questions across four domains, five minutes, and a scored view of where your governance has fallen behind your adoption.
Run the OCI Diagnostic