govrn · prepared for Ring Energy
A proposal prepared for Ring Energy through Al Petrie Advisors. Enter the access key you were provided.
Invalid key
govrn · Motion Consulting Group · a Kelly Services company
Ring Energy runs AI across operations, subsurface and production analytics, and reporting — exactly the surface capital partners and carriers now expect to see governed. This is a fixed-scope baseline that inventories it, scores it honestly, and hands you a prioritized path. In weeks, not quarters.
01 · The moment
The pressure is not arriving from regulators first. It is arriving from the people who write your cheques, underwrite your risk, and sit on your board.
The SEC's cybersecurity disclosure rule (Item 1.05 of Form 8-K) pulls AI-touched systems into material-incident reporting. What you can document, you can disclose.
OT and ICS guidance — IEC 62443, CISA advisories — treats AI in production and safety systems as exactly that. Drilling, HSE and production carry a different bar than the back office.
Boards, insurers and capital partners increasingly treat documented AI governance as part of audit-, underwriting- and transaction-readiness.
02 · What we can see from outside
Working from public materials only, the observation is narrow and specific: a published basis — model disclosure, accuracy basis, or a human-oversight description for AI in decision-sensitive workflows — is not readily locatable. That is a documentation gap, not a conduct finding, and the remedy is fast: document it, add the right human-in-the-loop gates, review. Which is exactly what the baseline delivers.
The same vantage point an investor, an insurer or a major customer occupies when they look at you. Public sources only — no access, and no assumptions about your internals.
We are not saying your models are wrong. We are saying the evidence a third party looks for is not published — and that is a solvable, weeks-long problem.
03 · The instrument
Evidence-based and mapped to recognized standards — so the readout survives a board meeting, an underwriter's question and a diligence room.
What AI you actually run — every feature, model dependency and data access across products and internal tooling, including the shadow AI your teams already use.
The attack surface AI adds — identity, data handling, model and dependency exposure — read against NIST CSF 2.0 and MITRE ATLAS rather than instinct.
Ownership, intake, oversight and escalation — who approves an AI system, who can stop one, and what evidence exists that either happened.
04 · The part no one else puts on the table
Back-office AI and safety-critical AI do not carry the same risk, and they should not carry the same controls. For every operational system we document a defensible oversight basis.
What the system is, what it was built on, and where its judgement is load-bearing.
How performance is established and re-established — not asserted once at purchase.
Where a person must decide, and proof the gate is real rather than nominal.
Who is called when a safety-critical decision looks wrong, and how fast it stops.
Reserve and financial reporting sit on the same footing — the AI that touches numbers your owners rely on is documented to the same standard as the AI that touches the field.
05 · The deliverable
A complete register of AI in use across the business — the thing almost no operator can produce today, and the first thing a diligence process asks for.
Where you stand on each lens, with the evidence behind every score, mapped to standards a third party already recognizes.
What to fix, in what order, at what effort — sequenced so the first moves also buy the most credibility.
Where independent attestation is the goal, we prepare the evidence — we never self-certify. Formal certification runs through accredited third-party bodies, and this baseline is the on-ramp to ISO/IEC 42001 readiness.
06 · How it runs
Access scoping, then the AI-feature and data-flow inventory begins across products, operations and internal tooling.
Evidence collection, three-lens scoring, the operational-AI control review, and the cost-and-efficiency read.
Posture, prioritized roadmap and remediation plan — delivered in a session built to be forwarded, not translated.
07 · Where it goes
The baseline is the door. What follows is scoped from exactly what it finds — never before.
The fixed-fee baseline. Inventory, three-lens posture, operational-AI review, prioritized roadmap.
Stand up the controls, the registry and the guardrails — scoped from exactly what Phase 1 finds.
Continuous monitoring and updates — the living evidence layer that keeps you governed as you grow.
08 · The fee
The instrument and the method already exist — what changes is the size and complexity of your estate. A short conversation and a brief discovery tell us both what the scope actually is, and the number is fixed before any work starts. No open meter, no surprises.
The count of AI systems in scope, how much of it touches operations and safety-critical decisions, and whether reserve and financial reporting sit inside the perimeter. We confirm all three together in the first working session.
09 · Next steps
We walk you through what we can already see from the outside, and you tell us what we cannot. No preparation needed on your side.
Enough to establish the AI-system count and how much of it touches operations. This is what sets the scope — and therefore the fixed fee.
Fixed before any work starts. You approve it or you don't, with nothing spent either way.
Then the roadmap decides whether Phase 2 is worth doing — on evidence, not on a pitch.
Prepared for Ring Energy through Al Petrie Advisors. Working from public materials only, June 2026 — every observation here is re-verified with you before it informs scope.