The challenge behind the engagement.
This service is for an organization whose roadmap says write the policy, and whose existing rules never anticipated an employee pasting source code into a chatbot. We write a governance charter naming the committee, its chair, decision rights, cadence, and escalation. It aligns with the NIST AI RMF and ISO/IEC 42001. We draft the AI policy and acceptable use standard: which tools are approved for which kinds of data, what must never go into unmanaged tools, and how AI-generated code and content get reviewed. Disclosure language required by new state and EU AI laws is drafted for your counsel to review. We build an intake form, a triage rubric, and an inventory of approved tools and models. We do not give legal advice.
Security, compliance, and legal leads at companies of a few hundred to a few thousand staff where AI tools arrived faster than the rules. The trigger is often a gap assessment roadmap, a scare involving customer data in a chatbot, or a board request for an AI policy.
What we do.
What you can use.
Read what you already have and who decides
We collect your current security policies, data classification scheme, governance tooling, and any AI rules already circulating. We interview the executive who will chair the committee plus legal, HR, product, and engineering leads. The output is a charter draft naming members, decision rights, and cadence, sized to your company rather than copied from an enterprise template.
Draft the policy, the intake, and the inventory
We write the AI policy and acceptable use standard in your own template. The intake form carries a rubric scoring data sensitivity, autonomy, high-stakes decisions, external users, and regulatory exposure. The inventory records approved tools with owner, provider, data flows, retention terms, and review date. High-risk requests route to a deeper impact review aligned with ISO/IEC 42001 and the generative AI risk list.
Hand over a set your committee can run
You receive the charter and RACI, the policy and acceptable use standard, the intake form and rubric, and an impact review template. The inventory is set up in your governance tool or delivered as a workbook. Procedures cover model and prompt change control and oversight. A rollout plan and a crosswalk tie each document to the NIST AI RMF and ISO/IEC 42001.
Who it’s for.
When you need it.
- Companies of a few hundred to a few thousand staff without an AI policy
- Security, legal, and HR leaders deciding which AI tools employees may use
- Organizations where AI tools spread faster than the rules governing them
- Boards and executives who need decision rights and an approved-tool inventory defined
- A gap assessment roadmap lists writing the AI policy as the first task
- Someone pastes customer data or source code into an unmanaged chatbot
- The board asks to see a written acceptable use standard for AI
- Employees keep requesting new AI tools with no intake process to route them
What the scope can include.
- 01
Governance charter with committee membership, chair, decision rights, meeting cadence, and escalation path
- 02
AI policy and acceptable use standard listing approved tools by data classification and prohibited inputs to unmanaged tools
- 03
Use-case intake form and triage rubric that fast-tracks low-risk requests and routes high-risk ones to impact assessment
- 04
Impact review template aligned with ISO/IEC 42001 and the generative AI risk list
- 05
Inventory of approved tools, models, and integrations with owner, provider, data flows, retention and training terms, and review date
- 06
Procedures for model and prompt change control, human oversight points, and prompt and output retention
What it typically costs.
One rate: $150/hour.
Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.
Under 100 employees, a few approved AI tools, one decision-maker
About 30–50 hours100–1,000 employees, several departments requesting AI tools
About 50–100 hours1,000+ employees or regulated industry, AI committee across business units
About 100–180 hours- Number of departments and AI tools to inventory
- Regulatory obligations (healthcare, finance, EU customers)
- Number of stakeholders who must approve the policy
- Existing security and acceptable use policies to extend
Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.
What you take forward.
- Governance charter and RACI aligned with the NIST AI RMF and ISO/IEC 42001
- AI policy and acceptable use standard in your policy template, with disclosure clauses flagged for counsel review
- Intake form, triage rubric, impact review template, and a configured inventory of approved tools and models
- Rollout and training plan, plus a crosswalk showing which parts of the NIST AI RMF and ISO/IEC 42001 each document satisfies
Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.
Before we get started.
How do we control shadow AI without banning everything?
Give people an approved path that is faster than the workaround. The acceptable use standard names which tools are approved for which kind of data. Public information in a consumer tool is allowed; customer records or source code are not. The intake rubric approves low-risk requests on the form itself, which removes the reason to go around it. On the technical side, the inventory feeds your access and monitoring tools so unapproved AI apps can be blocked or flagged, and sign-in records show who is still using what. Bans without an approved alternative produce exactly the shadow use you are trying to stop.
Do we need an impact assessment for every AI use case?
No. The rubric routes only high-risk requests to one: high-stakes decisions about people, regulated data, autonomous action, external users, or regulatory exposure. Low-risk requests are approved on the form. New state AI laws generally do not require a formal impact assessment for every use; they focus on documentation, notice, an explanation when a decision goes against someone, correction, and human review. Our template follows recognized guidance and the generative AI risk list, so the assessments you do run will hold up if you later pursue ISO/IEC 42001 certification.
- AI Risk Management Framework | NIST
- Artificial Intelligence Risk Management Framework: Generative Artificial Intelligence Profile (NIST AI 600-1)
- NIST AI RMF Playbook
- ISO/IEC 42001:2023 Information technology — Artificial intelligence — Management system
- NIST SP 800-61 Rev. 3, Incident Response Recommendations and Considerations for Cybersecurity Risk Management: A CSF 2.0 Community Profile
- GenAI Incident Response Guide 1.0 - OWASP Gen AI Security Project
- AI Act | Shaping Europe’s digital future
