Motion Consulting Group · AI Governance

Prepared for Amplify Energy.

A proposal for an AI-governance baseline. Enter the access key you were provided.

Invalid key
Motion Consulting Group · a Kelly Services company Confidential · Draft for discussion · June 2026
Proposal · AI Governance Baseline · AMPY

Govern the AI your operations, your board, and your regulators will ask about.

Amplify Energy runs AI across operations, subsurface and production analytics, and reporting — exactly the surface insurers, capital partners, and regulators now expect to see governed. We propose a fixed-scope baseline that inventories your AI estate, scores it honestly across three lenses, and hands you a prioritized path — in weeks, not quarters.

01 · The moment

Why now.

Operators are now explicitly on the hook: the SEC's cybersecurity disclosure rule (Item 1.05 of Form 8-K) pulls AI-touched systems into material-incident reporting, and OT/ICS guidance (IEC 62443, CISA ICS advisories) treats AI in production and safety systems as critical infrastructure. Boards, insurers, and capital partners increasingly treat documented AI governance as part of audit-, underwriting-, and transaction-readiness.

To be clear about what we are not saying: nothing in our preliminary review suggests Amplify Energy's AI behaves improperly. Working from public materials only (June 2026), what we observe is that a published basis — model disclosure, accuracy basis, or human-oversight description for AI in decision-sensitive workflows — is not readily locatable. The remedy for a control gap is fast: document, add the right human-in-the-loop gates, and review — which is exactly what the baseline delivers.

02 · The proposal

A fixed-scope AI Inventory & Risk Baseline.

Inventory. Every AI feature, model dependency, and data access across your products and internal tooling — including shadow AI your teams may already be using.
Three-lens posture. One score each for technology rationalization, security, and AI governance — evidence-based, mapped to recognized standards.
Operational-AI control review. A documented oversight basis for AI touching production, drilling, HSE, and reserve/financial reporting — model disclosure, accuracy basis, human-in-the-loop gates, and an escalation path for safety-critical decisions.
Cost & efficiency read. Where AI spend concentrates and what's recoverable through model right-sizing and caching discipline — governance that pays for itself.

You receive a prioritized remediation roadmap and a posture readout your leadership, owners, and counsel can act on. Where independent attestation is the goal, we prepare the evidence — we never self-certify; formal certification runs through accredited third-party bodies, and the baseline is the on-ramp to ISO/IEC 42001 readiness.

Indicative fee — Mid enterprise

$150K–$250K

Indicative range for an organization your size; fixed once we confirm the AI-system count together in the first working session. Standards mapped: NIST AI RMF · NIST CSF 2.0 · ISO/IEC 42001 · IEC 62443 (OT) · MITRE ATLAS.

03 · How it runs

Three to four weeks, human-led, low-friction.

WeekWhat happensFrom your side
1Working session; access scoping; AI-feature and data-flow inventory begins.One technical contact; product/ops walkthroughs.
2–3Evidence collection; three-lens scoring; sector control review; cost read.Short interviews with product, security, and compliance owners.
4Readout: posture, prioritized roadmap, remediation plan, attestation path.A leadership readout session.

Every step has a human decision gate — nothing is assessed, scored, or reported without your context.

04 · Why us

We build and run — not just assess.

  • Standards-mapped method. Every control we check traces to NIST AI RMF, NIST CSF 2.0, ISO/IEC 42001, OWASP, or MITRE ATLAS — no invented checklists.
  • Honesty as policy. We mark what's real: monitoring isn't claimed live until it's connected; findings are control gaps, never unsubstantiated verdicts.
  • Delivery muscle behind the advice. When the roadmap says build, we stand up the registry, controls, and monitoring and run them — on a deterministic governance engine, independent of the body that attests.
  • Independence respected. Attestation and certification stay structurally separate from remediation — what you show your auditors holds up.
05 · Next step

One working session.

We bring the baseline instrument and a draft inventory built from your public footprint; you bring the people who know the work. Ninety minutes confirms scope, fee, and timeline — and you leave with our preliminary observations either way.

Prepared for Martyn Willsher, CEO. To schedule, reply through your Motion Consulting Group contact. This document is a draft for discussion — nothing here is a finding about your operations; it is the case for documenting what's already true.