Use a one-off assessment when the client mainly needs to understand what is running and what it can reach. Move to continuing service when the client wants ongoing oversight, access changes, revocation support, and activity reporting. That model fits environments where AI use is expanding and governance needs to stay current as identities, permissions, and responsibilities change.
When a Point-in-Time Review Is Enough
A one-off assessment works best when the decision is primarily diagnostic: what agentic ai is present, what it can access, and where the biggest exposure sits today. That is the right model for scoping, baseline risk discovery, or a procurement gate. For teams still deciding whether to treat an AI system as agentic, a snapshot can be enough to support a funding or launch decision.
It is also the right format when the operating model is stable and the client only needs an independent opinion at a fixed point in time. In that case, the deliverable should focus on inventory, privilege boundaries, data reach, and the minimum controls needed to reduce immediate exposure. If those inputs are not changing quickly, a continuing service can add cost without materially improving the answer.
One-off work is strongest when the question is “what is true right now?” rather than “how do we keep this governed as it changes?” That distinction matters because agentic systems often look acceptable on day one and become riskier as new tools, permissions, owners, and workflows are added.
Why Governance Becomes a Service Problem
A continuing service becomes more useful once the organisation needs oversight that tracks change rather than just documenting it. As agent use expands, access reviews, revocation support, activity reporting, and ownership changes stop being exceptional events and become routine governance work. That is especially true when the environment includes identity, delegation, registration and retirement decisions that must stay current.
The practical trigger is usually not the AI model itself, but the surrounding control plane. New integrations appear, credentials rotate, tasks get reassigned, and humans begin using the same agent in different business contexts. A service model gives the client an ongoing way to spot when authority has drifted beyond the original approval.
Continuing governance also fits situations where the organisation wants evidence, not just advice. Ongoing reporting can show what changed, which agents remain active, which permissions were removed, and whether the operating team is actually following the approved access model. That makes governance more defensible to security, audit, and risk stakeholders.
Choosing the Right Delivery Model
The best choice depends on whether the risk is static or dynamic. If the main question is whether to launch, pilot, or accept an isolated use case, a one-off assessment is usually sufficient. If the client already expects continuous expansion, repeated approvals, or recurring access changes, the work should be packaged as a service from the start.
A good rule is to move to service when any of the following are true:
- access is changing often enough that point-in-time findings will go stale quickly;
- revocation or offboarding needs a defined operating process rather than an ad hoc response;
- the client needs scheduled reporting on activity, permissions, or exceptions;
- different business owners are responsible for the same agent at different times;
- the agent population is growing faster than the organisation can manually review it.
That is why continuing service often pairs well with task-scoped and just-in-time authorisation and with auditing, attribution and revocation support. Those controls are much harder to sustain through periodic review alone.
Risk and Threat Considerations
Agentic AI governance becomes riskier when organisations rely on a one-time review for systems that keep acquiring access. The main failure mode is stale approval: the assessment is still on file, but the actual permissions, owners, tool connections, or data reach have already changed. That creates unnecessary exposure, weakens accountability, and makes later incidents harder to explain or contain.
Failure mechanism: new capabilities are added without a fresh governance decision, so standing access, forgotten credentials, or unreviewed integrations remain active after the original business justification has expired.
Impact: the organisation can lose control over what the agent can do, who can revoke it, and what evidence exists when something goes wrong. In the worst case, a compromised or overextended agent becomes a durable path to data access, misuse, or unauthorised action.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
OWASP Agentic AI Top 10 addresses the attack surface, NIST SP 800-53 Rev 5 and NIST AI RMF set the technical controls, and ISO/IEC 42001:2023 defines the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| OWASP Agentic AI Top 10 | ASI03 — Identity & Privilege Abuse | Continuous governance is needed when agent privileges and ownership change over time. |
| Recommendation — Enforce per-action authorization and remove standing privilege for agents. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Review, Analysis, and Reporting | Ongoing service models support recurring activity reporting and review. |
| AC-6 — Least Privilege | The answer turns on keeping agent access bounded as use expands. | |
| Recommendation — Automate audit review and reporting for agent activity and exceptions. Constrain agent permissions to the minimum needed for each task. | ||
| ISO/IEC 42001:2023 | 8.2 — AI risk treatment | A continuing service fits ongoing AI risk treatment as deployments evolve. |
| Recommendation — Operate AI risk treatment as a recurring governance process, not a one-time check. | ||
| NIST AI RMF | GOVERN — Govern | The question is about sustained AI governance oversight and accountability. |
| Recommendation — Establish ongoing oversight, roles, and monitoring for AI governance. | ||
Practitioner Guidance
What to prioritise: package the engagement as a service whenever the client needs recurring access review, exception handling, revocation support, or reporting on agent activity. That is the point where governance becomes operational, not just advisory.
Decision rule: if the client expects the agent estate, permissions, or ownership model to change during the next review cycle, do not sell only a one-off assessment. A continuing service is the safer fit because it preserves the control relationship after the first report is delivered.
What to verify: confirm whether the client has a named owner for each agent, a revocation path, and a review cadence that matches deployment speed. If any of those are missing, the assessment alone will not hold up for long.
Practitioner takeaway: use one-off assessments to establish the baseline, but use a service model when governance must stay aligned with a live and expanding agent population.