How it works

Four weeks, then a signature.

Every engagement follows the same sequence, uses the same versioned methodology, and ends the same way: with a named person attesting to what was assessed and what was found.

The sequence

Week by week

Week 1

Inventory

Kickoff call, document request, and stakeholder interviews across engineering, product, legal, and operations. Shadow AI is found here — the tools individual teams adopted without a procurement review. You get the inventory even if you go no further.

Week 2

Classification

Two axes. Regulatory exposure: which statutes, frameworks and contractual obligations attach to this system. Operational consequence: what a wrong output costs — a bad ad, a denied claim, a privileged disclosure. The intersection sets assessment depth.

Week 3

Assessment

Systems are tested against versioned obligations, and every conclusion is tied to recorded evidence: configuration, contracts, logs, policies, interview notes. Interim findings are shared mid-week so nothing in the final report is a surprise.

Week 4

Report and attestation

Findings are ranked, remediation is sequenced, and the report is walked through live with your team. The attestation page is signed and dated at delivery.

The signature

What it means when we sign.

An attestation is not a guarantee that nothing will go wrong. It is a record that a qualified, named person examined defined systems against defined standards on a defined date, and reached a conclusion they will stand behind.

Who assessed it

A named practitioner with stated credentials — not an anonymous engagement team.

What was in scope

The exact systems, versions, and boundaries examined, and explicitly what was not.

Against which standards

Framework names and version numbers, because 'NIST-aligned' with no version is not a claim anyone can check.

On what evidence

The artifact set reviewed, indexed so a third party could re-perform the assessment.

With what conclusion

Findings, severities, and the risks the organization is accepting rather than remediating.

As of when

A date. Governance posture decays; the attestation says exactly what it covers and when it was true.

Next step

Find out what your AI exposure actually looks like.

A Governance Teardown is a fixed-fee, four-week assessment ending in a signed, audit-ready report. Start with a 30-minute call and we'll tell you honestly whether it fits.