AI governance and risk management consulting using the NIST AI RMF and ISO 42001, with gap assessments, policies, vendor reviews, and readiness evidence.
Customers now ask how you govern AI before they will buy, insurers ask at renewal, and new laws in several states and the EU are setting real deadlines. This core builds the program that answers all of them. The risk and gap assessment measures what you run today against the NIST AI RMF and its Generative AI Profile and hands you a prioritized roadmap. Policy and governance work turns that roadmap into decision rights, an acceptable use standard, an intake process, and an inventory of approved tools. The vendor review covers the AI you buy. ISO/IEC 42001 readiness builds a management system an independent body can certify. The incident playbooks and tabletop extend your response plan to AI-specific failures. Every engagement runs the same rhythm: understand the requirement, find the gaps, build the controls, organize the evidence, and rehearse the assessment. None of it is legal advice, and none of it is a certificate.
A GOOD FIT WHEN
CISOs, compliance leads, and general counsel at companies that have adopted AI assistants and features across the business, and product owners shipping AI into regulated or high-stakes decisions. Most arrive after a customer questionnaire, an insurer question, or a new state or EU deadline lands on their desk.
THE WORK BEHIND THE SERVICE
What we do. What you can use.
01
Start from the question you were asked
We begin with whatever created the need: the customer questionnaire, the insurer’s renewal application, or the memo from counsel about a new AI law. From it we fix which systems, which framework, and which deadline matter. Then we write a scoping memo naming the AI systems in play, the owners we will interview, and the evidence we need.
02
Assess the AI you run against the framework
We build the inventory from sign-in records, procurement data, and interviews. Then we measure what you run against the NIST AI RMF, rating each area as not implemented, partial, or implemented, with the evidence cited. Generative systems get a second pass against the Generative AI Profile. Nothing is rated from a questionnaire alone; we read the settings, the contracts, and the logs.
03
Hand over documents a customer or auditor can read
You keep a workbook that ties every finding to the NIST AI RMF and ISO/IEC 42001, plus a roadmap naming an owner and effort for each gap. You also keep the policies, questionnaires, and playbooks the focused services produce. After you close a gap we re-check it and update the evidence index, so the next questionnaire is answered from dated evidence rather than intent.
An AI policy and acceptable use standard, a governance charter with decision rights, a use-case intake process, and an inventory of approved tools and models.
Governance charter with committee membership, chair, decision rights, meeting cadence, and escalation path
AI policy and acceptable use standard listing approved tools by data classification and prohibited inputs to unmanaged tools
Use-case intake form and triage rubric that fast-tracks low-risk requests and routes high-risk ones to impact assessment
Training and retention terms, subprocessors, autonomy limits, and breach notification reviewed for the AI you buy, with a reusable questionnaire and contract language.
Vendor tiering by data received, autonomy, high-stakes decisions, and the model providers behind them
Review of whether your data trains their models, how you opt out, and how prompts, outputs, and stored data are retained and deleted
Separation of your data from other customers’, change notice for subprocessors and model providers, and customer-visible logging
Scoping your AI management system, a gap assessment against the full ISO/IEC 42001 standard, control build-out, and an internal audit before the certification audit.
AI management system scope statement by system, site, and whether you build, deploy, or use AI
Gap assessment against every requirement and control in ISO/IEC 42001, rated by severity and effort
AI risk assessment and treatment, with an impact review procedure for individual AI systems
Playbooks for prompt injection, agent misuse, model compromise, and AI-assisted data theft, built into your existing incident response plan and proven in a tabletop.
AI incident types and a severity matrix drawn from recognized industry incident-response guidance
Logging review across prompts, outputs, agent actions, retrieval, and identity to confirm an incident can be reconstructed
Three to five playbooks covering prompt injection, agent misuse, tool poisoning, model compromise, and AI-assisted data theft
AI system inventory and a current-and-target profile workbook measured against the NIST AI RMF and its Generative AI Profile, with evidence cited for each area
Governance charter, AI policy and acceptable use standard, intake rubric, and approved-tool inventory written into your existing policy set
Reusable AI vendor questionnaire, a contract clause library, and per-vendor findings for the AI you buy
ISO/IEC 42001 scope statement, control applicability record, and internal audit report indexed and ready for the certification audit
AI incident playbooks and a tabletop after-action report built into your existing incident response plan, with closed gaps re-checked against dated evidence
The selected services, deliverables, access requirements, and any follow-up validation are agreed in your engagement scope.