AI Frameworks / FOCUSED SERVICE

AI Policy & Governance Development

An AI policy and acceptable use standard, a governance charter with decision rights, a use-case intake process, and an inventory of approved tools and models.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for an organization whose roadmap says write the policy, and whose existing rules never anticipated an employee pasting source code into a chatbot. We write a governance charter naming the committee, its chair, decision rights, cadence, and escalation. It aligns with the NIST AI RMF and ISO/IEC 42001. We draft the AI policy and acceptable use standard: which tools are approved for which kinds of data, what must never go into unmanaged tools, and how AI-generated code and content get reviewed. Disclosure language required by new state and EU AI laws is drafted for your counsel to review. We build an intake form, a triage rubric, and an inventory of approved tools and models. We do not give legal advice.

WHEN THIS IS THE RIGHT FIT

Security, compliance, and legal leads at companies of a few hundred to a few thousand staff where AI tools arrived faster than the rules. The trigger is often a gap assessment roadmap, a scare involving customer data in a chatbot, or a board request for an AI policy.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Read what you already have and who decides

We collect your current security policies, data classification scheme, governance tooling, and any AI rules already circulating. We interview the executive who will chair the committee plus legal, HR, product, and engineering leads. The output is a charter draft naming members, decision rights, and cadence, sized to your company rather than copied from an enterprise template.

Draft the policy, the intake, and the inventory

We write the AI policy and acceptable use standard in your own template. The intake form carries a rubric scoring data sensitivity, autonomy, high-stakes decisions, external users, and regulatory exposure. The inventory records approved tools with owner, provider, data flows, retention terms, and review date. High-risk requests route to a deeper impact review aligned with ISO/IEC 42001 and the generative AI risk list.

Hand over a set your committee can run

You receive the charter and RACI, the policy and acceptable use standard, the intake form and rubric, and an impact review template. The inventory is set up in your governance tool or delivered as a workbook. Procedures cover model and prompt change control and oversight. A rollout plan and a crosswalk tie each document to the NIST AI RMF and ISO/IEC 42001.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Companies of a few hundred to a few thousand staff without an AI policy
  • Security, legal, and HR leaders deciding which AI tools employees may use
  • Organizations where AI tools spread faster than the rules governing them
  • Boards and executives who need decision rights and an approved-tool inventory defined
WHEN IT’S TIME TO ENGAGE
  • A gap assessment roadmap lists writing the AI policy as the first task
  • Someone pastes customer data or source code into an unmanaged chatbot
  • The board asks to see a written acceptable use standard for AI
  • Employees keep requesting new AI tools with no intake process to route them
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • Governance charter with committee membership, chair, decision rights, meeting cadence, and escalation path

  • AI policy and acceptable use standard listing approved tools by data classification and prohibited inputs to unmanaged tools

  • Use-case intake form and triage rubric that fast-tracks low-risk requests and routes high-risk ones to impact assessment

  • Impact review template aligned with ISO/IEC 42001 and the generative AI risk list

  • Inventory of approved tools, models, and integrations with owner, provider, data flows, retention and training terms, and review date

  • Procedures for model and prompt change control, human oversight points, and prompt and output retention

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$4,500–$7,500

Under 100 employees, a few approved AI tools, one decision-maker

About 30–50 hours
Mid-size
$7,500–$15,000

100–1,000 employees, several departments requesting AI tools

About 50–100 hours
Large
$15,000–$27,000

1,000+ employees or regulated industry, AI committee across business units

About 100–180 hours
WHAT MOVES THE PRICE
  • Number of departments and AI tools to inventory
  • Regulatory obligations (healthcare, finance, EU customers)
  • Number of stakeholders who must approve the policy
  • Existing security and acceptable use policies to extend
TYPICAL TIMELINE

4–8 weeks

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • Governance charter and RACI aligned with the NIST AI RMF and ISO/IEC 42001
  • AI policy and acceptable use standard in your policy template, with disclosure clauses flagged for counsel review
  • Intake form, triage rubric, impact review template, and a configured inventory of approved tools and models
  • Rollout and training plan, plus a crosswalk showing which parts of the NIST AI RMF and ISO/IEC 42001 each document satisfies

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

How do we control shadow AI without banning everything?

Give people an approved path that is faster than the workaround. The acceptable use standard names which tools are approved for which kind of data. Public information in a consumer tool is allowed; customer records or source code are not. The intake rubric approves low-risk requests on the form itself, which removes the reason to go around it. On the technical side, the inventory feeds your access and monitoring tools so unapproved AI apps can be blocked or flagged, and sign-in records show who is still using what. Bans without an approved alternative produce exactly the shadow use you are trying to stop.

Do we need an impact assessment for every AI use case?

No. The rubric routes only high-risk requests to one: high-stakes decisions about people, regulated data, autonomous action, external users, or regulatory exposure. Low-risk requests are approved on the form. New state AI laws generally do not require a formal impact assessment for every use; they focus on documentation, notice, an explanation when a decision goes against someone, correction, and human review. Our template follows recognized guidance and the generative AI risk list, so the assessments you do run will hold up if you later pursue ISO/IEC 42001 certification.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security