govrn · prepared for Ring Energy

AI Governance Baseline.

A proposal prepared for Ring Energy through Al Petrie Advisors. Enter the access key you were provided.

Invalid key

Confidential Confidential · draft for discussion

govrn · Motion Consulting Group · a Kelly Services company

Govern the AI your board, your insurers and your regulators will ask about.

Ring Energy runs AI across operations, subsurface and production analytics, and reporting — exactly the surface capital partners and carriers now expect to see governed. This is a fixed-scope baseline that inventories it, scores it honestly, and hands you a prioritized path. In weeks, not quarters.

Engagement3–4 weeks
Your liftOne contact
OutputBoard-ready
FeeScoped to you

01 · The moment

Everyone is integrating AI. Almost no one is governing it.

The pressure is not arriving from regulators first. It is arriving from the people who write your cheques, underwrite your risk, and sit on your board.

Disclosure

The 8-K surface

The SEC's cybersecurity disclosure rule (Item 1.05 of Form 8-K) pulls AI-touched systems into material-incident reporting. What you can document, you can disclose.

Operations

Field AI is critical infrastructure

OT and ICS guidance — IEC 62443, CISA advisories — treats AI in production and safety systems as exactly that. Drilling, HSE and production carry a different bar than the back office.

Capital

Diligence has a new line

Boards, insurers and capital partners increasingly treat documented AI governance as part of audit-, underwriting- and transaction-readiness.

02 · What we can see from outside

Nothing suggests your AI behaves improperly. The basis just isn't findable.

Working from public materials only, the observation is narrow and specific: a published basis — model disclosure, accuracy basis, or a human-oversight description for AI in decision-sensitive workflows — is not readily locatable. That is a documentation gap, not a conduct finding, and the remedy is fast: document it, add the right human-in-the-loop gates, review. Which is exactly what the baseline delivers.

What this is

An outside-in read

The same vantage point an investor, an insurer or a major customer occupies when they look at you. Public sources only — no access, and no assumptions about your internals.

What this is not

An accusation

We are not saying your models are wrong. We are saying the evidence a third party looks for is not published — and that is a solvable, weeks-long problem.

03 · The instrument

One estate. Three lenses. One honest score each.

Evidence-based and mapped to recognized standards — so the readout survives a board meeting, an underwriter's question and a diligence room.

Technology rationalization

What AI you actually run — every feature, model dependency and data access across products and internal tooling, including the shadow AI your teams already use.

Security

The attack surface AI adds — identity, data handling, model and dependency exposure — read against NIST CSF 2.0 and MITRE ATLAS rather than instinct.

AI governance

Ownership, intake, oversight and escalation — who approves an AI system, who can stop one, and what evidence exists that either happened.

NIST AI RMFNIST CSF 2.0ISO/IEC 42001IEC 62443 (OT)MITRE ATLAS

04 · The part no one else puts on the table

AI touching production, drilling and HSE gets its own review.

Back-office AI and safety-critical AI do not carry the same risk, and they should not carry the same controls. For every operational system we document a defensible oversight basis.

01

Model disclosure

What the system is, what it was built on, and where its judgement is load-bearing.

02

Accuracy basis

How performance is established and re-established — not asserted once at purchase.

03

Human-in-the-loop gates

Where a person must decide, and proof the gate is real rather than nominal.

04

Escalation path

Who is called when a safety-critical decision looks wrong, and how fast it stops.

Reserve and financial reporting sit on the same footing — the AI that touches numbers your owners rely on is documented to the same standard as the AI that touches the field.

05 · The deliverable

A readout your leadership, owners and counsel can act on.

Inventory

The AI bill of materials

A complete register of AI in use across the business — the thing almost no operator can produce today, and the first thing a diligence process asks for.

Posture

Three scores, evidenced

Where you stand on each lens, with the evidence behind every score, mapped to standards a third party already recognizes.

Path

Prioritized remediation roadmap

What to fix, in what order, at what effort — sequenced so the first moves also buy the most credibility.

Where independent attestation is the goal, we prepare the evidence — we never self-certify. Formal certification runs through accredited third-party bodies, and this baseline is the on-ramp to ISO/IEC 42001 readiness.

06 · How it runs

Three to four weeks. Human-led. Low friction on your side.

Week 1

Working session & inventory

Access scoping, then the AI-feature and data-flow inventory begins across products, operations and internal tooling.

From your side — one technical contact, plus product and operations walkthroughs.
Weeks 2–3

Evidence, scoring, sector review

Evidence collection, three-lens scoring, the operational-AI control review, and the cost-and-efficiency read.

From your side — short interviews with product, security and compliance owners.
Week 4

Readout

Posture, prioritized roadmap and remediation plan — delivered in a session built to be forwarded, not translated.

From your side — the room, and an hour.

07 · Where it goes

See it. Build it. Run it.

The baseline is the door. What follows is scoped from exactly what it finds — never before.

Phase 1 · See

Assess

The fixed-fee baseline. Inventory, three-lens posture, operational-AI review, prioritized roadmap.

You are here · scoped up front
Phase 2 · Build

Design & implement

Stand up the controls, the registry and the guardrails — scoped from exactly what Phase 1 finds.

Scoped to your estate
Phase 3 · Run

Operate

Continuous monitoring and updates — the living evidence layer that keeps you governed as you grow.

Recurring

08 · The fee

A fixed-fee baseline. Priced to your estate.

Scoped to you
fixed fee · fixed scope · set before we start
How it's priced

The instrument and the method already exist — what changes is the size and complexity of your estate. A short conversation and a brief discovery tell us both what the scope actually is, and the number is fixed before any work starts. No open meter, no surprises.

What sets the number

The count of AI systems in scope, how much of it touches operations and safety-critical decisions, and whether reserve and financial reporting sit inside the perimeter. We confirm all three together in the first working session.

09 · Next steps

Four moves — and the first one takes thirty minutes.

A thirty-minute conversation

We walk you through what we can already see from the outside, and you tell us what we cannot. No preparation needed on your side.

Brief discovery

Enough to establish the AI-system count and how much of it touches operations. This is what sets the scope — and therefore the fixed fee.

Scope and fee confirmed in writing

Fixed before any work starts. You approve it or you don't, with nothing spent either way.

Four weeks to a board-ready posture

Then the roadmap decides whether Phase 2 is worth doing — on evidence, not on a pitch.

Start the conversation →

Prepared for Ring Energy through Al Petrie Advisors. Working from public materials only, June 2026 — every observation here is re-verified with you before it informs scope.