Compliance / CORE SERVICE

AI Frameworks

AI governance and risk management consulting using the NIST AI RMF and ISO 42001, with gap assessments, policies, vendor reviews, and readiness evidence.

THE WORK, IN CONTEXT

AI Frameworks, with a clear purpose.

Customers now ask how you govern AI before they will buy, insurers ask at renewal, and new laws in several states and the EU are setting real deadlines. This core builds the program that answers all of them. The risk and gap assessment measures what you run today against the NIST AI RMF and its Generative AI Profile and hands you a prioritized roadmap. Policy and governance work turns that roadmap into decision rights, an acceptable use standard, an intake process, and an inventory of approved tools. The vendor review covers the AI you buy. ISO/IEC 42001 readiness builds a management system an independent body can certify. The incident playbooks and tabletop extend your response plan to AI-specific failures. Every engagement runs the same rhythm: understand the requirement, find the gaps, build the controls, organize the evidence, and rehearse the assessment. None of it is legal advice, and none of it is a certificate.

A GOOD FIT WHEN

CISOs, compliance leads, and general counsel at companies that have adopted AI assistants and features across the business, and product owners shipping AI into regulated or high-stakes decisions. Most arrive after a customer questionnaire, an insurer question, or a new state or EU deadline lands on their desk.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Start from the question you were asked

We begin with whatever created the need: the customer questionnaire, the insurer’s renewal application, or the memo from counsel about a new AI law. From it we fix which systems, which framework, and which deadline matter. Then we write a scoping memo naming the AI systems in play, the owners we will interview, and the evidence we need.

Assess the AI you run against the framework

We build the inventory from sign-in records, procurement data, and interviews. Then we measure what you run against the NIST AI RMF, rating each area as not implemented, partial, or implemented, with the evidence cited. Generative systems get a second pass against the Generative AI Profile. Nothing is rated from a questionnaire alone; we read the settings, the contracts, and the logs.

Hand over documents a customer or auditor can read

You keep a workbook that ties every finding to the NIST AI RMF and ISO/IEC 42001, plus a roadmap naming an owner and effort for each gap. You also keep the policies, questionnaires, and playbooks the focused services produce. After you close a gap we re-check it and update the evidence index, so the next questionnaire is answered from dated evidence rather than intent.

FIND YOUR FOCUS

Specific services.
Substantive answers.

01 / AI Frameworks

AI Risk & Gap Assessment

Your current AI practice measured against the NIST AI RMF and the Generative AI Profile, with a roadmap that names an owner and effort for every gap.

  • AI inventory built from sign-in records, endpoint and browser data, procurement records, and owner interviews
  • Current-practice rating against every part of the NIST AI RMF, using its recommended actions as the evidence checklist
  • Second pass on generative systems against the risks in the Generative AI Profile

From $4,500

Scope, pricing & FAQs
02 / AI Frameworks

AI Policy & Governance Development

An AI policy and acceptable use standard, a governance charter with decision rights, a use-case intake process, and an inventory of approved tools and models.

  • Governance charter with committee membership, chair, decision rights, meeting cadence, and escalation path
  • AI policy and acceptable use standard listing approved tools by data classification and prohibited inputs to unmanaged tools
  • Use-case intake form and triage rubric that fast-tracks low-risk requests and routes high-risk ones to impact assessment

From $4,500

Scope, pricing & FAQs
03 / AI Frameworks

AI Vendor & Third-Party Risk Review

Training and retention terms, subprocessors, autonomy limits, and breach notification reviewed for the AI you buy, with a reusable questionnaire and contract language.

  • Vendor tiering by data received, autonomy, high-stakes decisions, and the model providers behind them
  • Review of whether your data trains their models, how you opt out, and how prompts, outputs, and stored data are retained and deleted
  • Separation of your data from other customers’, change notice for subprocessors and model providers, and customer-visible logging

From $4,500

Scope, pricing & FAQs
04 / AI Frameworks

ISO/IEC 42001 Readiness

Scoping your AI management system, a gap assessment against the full ISO/IEC 42001 standard, control build-out, and an internal audit before the certification audit.

  • AI management system scope statement by system, site, and whether you build, deploy, or use AI
  • Gap assessment against every requirement and control in ISO/IEC 42001, rated by severity and effort
  • AI risk assessment and treatment, with an impact review procedure for individual AI systems

From $15,000

Scope, pricing & FAQs
05 / AI Frameworks

AI Incident Response Playbooks & Tabletop

Playbooks for prompt injection, agent misuse, model compromise, and AI-assisted data theft, built into your existing incident response plan and proven in a tabletop.

  • AI incident types and a severity matrix drawn from recognized industry incident-response guidance
  • Logging review across prompts, outputs, agent actions, retrieval, and identity to confirm an incident can be reconstructed
  • Three to five playbooks covering prompt injection, agent misuse, tool poisoning, model compromise, and AI-assisted data theft

From $5,200

Scope, pricing & FAQs
WHAT YOU TAKE FORWARD

Built to support the next decision.

  • AI system inventory and a current-and-target profile workbook measured against the NIST AI RMF and its Generative AI Profile, with evidence cited for each area
  • Governance charter, AI policy and acceptable use standard, intake rubric, and approved-tool inventory written into your existing policy set
  • Reusable AI vendor questionnaire, a contract clause library, and per-vendor findings for the AI you buy
  • ISO/IEC 42001 scope statement, control applicability record, and internal audit report indexed and ready for the certification audit
  • AI incident playbooks and a tabletop after-action report built into your existing incident response plan, with closed gaps re-checked against dated evidence

The selected services, deliverables, access requirements, and any follow-up validation are agreed in your engagement scope.

INFORMED BY RECOGNIZED GUIDANCE
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security