How it works
Four weeks, then a signature.
Every engagement follows the same sequence, uses the same versioned methodology, and ends the same way: with a named person attesting to what was assessed and what was found.
The sequence
Week by week
Week 1
Inventory
Kickoff call, document request, and stakeholder interviews across engineering, product, legal, and operations. Shadow AI is found here — the tools individual teams adopted without a procurement review. You get the inventory even if you go no further.
Week 2
Classification
Two axes. Regulatory exposure: which statutes, frameworks and contractual obligations attach to this system. Operational consequence: what a wrong output costs — a bad ad, a denied claim, a privileged disclosure. The intersection sets assessment depth.
Week 3
Assessment
Systems are tested against versioned obligations, and every conclusion is tied to recorded evidence: configuration, contracts, logs, policies, interview notes. Interim findings are shared mid-week so nothing in the final report is a surprise.
Week 4
Report and attestation
Findings are ranked, remediation is sequenced, and the report is walked through live with your team. The attestation page is signed and dated at delivery.
The signature
What it means when we sign.
An attestation is not a guarantee that nothing will go wrong. It is a record that a qualified, named person examined defined systems against defined standards on a defined date, and reached a conclusion they will stand behind.
Who assessed it
A named practitioner with stated credentials — not an anonymous engagement team.
What was in scope
The exact systems, versions, and boundaries examined, and explicitly what was not.
Against which standards
Framework names and version numbers, because 'NIST-aligned' with no version is not a claim anyone can check.
On what evidence
The artifact set reviewed, indexed so a third party could re-perform the assessment.
With what conclusion
Findings, severities, and the risks the organization is accepting rather than remediating.
As of when
A date. Governance posture decays; the attestation says exactly what it covers and when it was true.
Next step
Find out what your AI exposure actually looks like.
A Governance Teardown is a fixed-fee, four-week assessment ending in a signed, audit-ready report. Start with a 30-minute call and we'll tell you honestly whether it fits.