AI Frameworks / FOCUSED SERVICE

AI Risk & Gap Assessment

Your current AI practice measured against the NIST AI RMF and the Generative AI Profile, with a roadmap that names an owner and effort for every gap.

WHAT THIS SERVICE ADDRESSES

The challenge behind the engagement.

This service is for an organization that must show how it manages AI risk and has no written answer yet. We find the AI in use across the business, including the tools teams adopted on their own, and build an inventory with owner, purpose, data sensitivity, and decision impact. We measure your current practice against every part of the NIST AI RMF, using its recommended actions as the evidence checklist, and re-check generative systems against the Generative AI Profile. We set a target from leadership’s risk tolerance and overlay the state and EU AI obligations that actually bind you. You receive the inventory, a scored workbook, risk register entries, and a prioritized roadmap. No conformity program exists for these frameworks, so we never call you certified or compliant.

WHEN THIS IS THE RIGHT FIT

CISOs and compliance leads at companies that mostly buy AI, and a few that build it. The trigger is usually a customer questionnaire with an AI section, an insurer asking about AI at renewal, or counsel flagging a new state or EU deadline.

THE WORK BEHIND THE SERVICE

What we do.
What you can use.

Find every AI system, including the ones nobody registered

We start with an executive sponsor, the business units known to use AI, and read access to sign-in records, endpoint and browser data, and procurement lists. We interview legal, HR, product, data, and security owners. From that we build the inventory: owner, purpose, data sensitivity, model and provider, and whether the system touches a high-stakes decision.

Rate each area against evidence, not intent

For every part of the NIST AI RMF we ask for the artifact that proves it, inspect it, and rate it not implemented, partial, implemented, or not applicable, naming the evidence. Systems that generate text, code, or images get a second pass against the generative AI risks in the Profile. The state and EU obligations that apply to you are overlaid system by system.

Deliver the roadmap and the workbook behind it

You receive the scored workbook and risk register entries with likelihood, impact, and owner. The roadmap names an owner, an effort band, and dependencies for each gap, with high-stakes and regulated-data systems first. The executive summary answers the customer, insurer, and regulator questions you arrived with. Closed gaps are re-checked and the workbook updated with dated evidence.

IS THIS THE RIGHT ENGAGEMENT?

Who it’s for.
When you need it.

BEST SUITED FOR
  • Organizations deploying vendor AI tools with no written account of how they manage AI risk
  • Compliance and security leads who own the answer to customer AI questionnaires
  • Companies fielding SIG or AI-CAIQ sections they currently answer from intent, not evidence
  • Firms selling into Texas, the EU, or Colorado where AI obligations now carry dates
WHEN IT’S TIME TO ENGAGE
  • A customer sends a questionnaire with an AI section you cannot yet answer
  • An insurer asks about AI use during a cyber policy renewal
  • Counsel flags your exposure under a new state or EU AI law
  • Leadership approves an AI initiative and wants the risk picture first
AGREED AROUND YOUR ENVIRONMENT

What the scope can include.

  • AI inventory built from sign-in records, endpoint and browser data, procurement records, and owner interviews

  • Current-practice rating against every part of the NIST AI RMF, using its recommended actions as the evidence checklist

  • Second pass on generative systems against the risks in the Generative AI Profile

  • Target set from leadership risk tolerance, prioritizing high-stakes decisions, regulated data, and autonomous action

  • Overlay of the state and EU AI obligations that bind you, mapped to the systems they affect

  • Optional crosswalk of gaps to ISO/IEC 42001 for teams heading toward certification

TRANSPARENT PRICING

What it typically costs.
One rate: $150/hour.

Every engagement is priced by the hours it takes at one flat rate, with scoping, the work, and the final deliverables included. Find the size closest to yours.

Small
$4,500–$9,000

A handful of AI tools, mostly purchased rather than built

About 30–60 hours
Mid-size
$9,000–$16,500

Several AI uses across departments, including one built or customized in-house

About 60–110 hours
Large
$16,500–$30,000

AI built into products or used across many business units

About 110–200 hours
WHAT MOVES THE PRICE
  • Number of AI systems and use cases in scope
  • Whether AI is bought, customized, or built in-house
  • Number of teams and stakeholders to interview
  • Existing risk, privacy, and security documentation
TYPICAL TIMELINE

4–8 weeks

The NIST AI RMF has no certification; there is no separate audit fee.

Get a fixed quote for your scope

Ranges are planning estimates at $150/hour, not a quote. Your price is confirmed in writing after a scoping call, before any work begins.

TANGIBLE DELIVERABLES

What you take forward.

  • AI system inventory with owner, purpose, data classification, model and provider, and decision impact per entry
  • Scored workbook with a cited artifact or a stated gap for every part of the framework
  • Risk register entries with likelihood, impact, and owner, ready to merge into your enterprise register
  • Prioritized roadmap naming owner, effort band, and dependency per gap, with an executive summary for customers and insurers

Final coverage, deliverables, timing, and any retesting or implementation work are confirmed before the engagement begins.

SERVICE-SPECIFIC QUESTIONS

Before we get started.

We only buy AI features from vendors. Do we still need a gap assessment?

Yes, and it is usually shorter. The NIST AI RMF is written for organizations that deploy AI, not only those that build it. It still asks who approved the tool and under what rules, what data flows to it and which decisions it informs, and how you would respond if it leaked or misled. The Generative AI Profile covers exactly the risk of relying on someone else’s model. Most of your evidence will be settings, contract terms, and sign-in records rather than model testing, and the roadmap will lean toward policy, vendor review, and logging.

Does aligning with the NIST AI RMF help us with new state AI laws?

It can. Some state AI laws provide an affirmative defense for organizations that follow a recognized framework such as the NIST AI RMF, including its Generative AI Profile, and that find issues through their own testing. It is a defense your counsel argues, not a certificate anyone issues, and no conformity program exists for these frameworks. What this engagement gives you is the documentation that argument needs: a dated record of your current practice with evidence, a defined target, and a roadmap showing gaps being closed. Whether it satisfies a regulator in a given matter is a legal question we do not answer.

REFERENCE POINTS
START AT THE SOURCE

Let’s find your next move.

A focused conversation. A clear scope. A practical path to stronger security.

Let’s talk security