Flagship engagement
The Governance Teardown
Four weeks. Fixed fee. We take your AI apart against the rules that actually apply to it, tell you what's risky in priority order, and sign the assessment.
Scope
What the Teardown covers
Scope is confirmed in writing before the engagement starts. Nothing is discovered mid-project and billed as a change order.
- ✕Full AI inventory, including shadow AI discovered through interviews and system review
- ✕Two-axis classification: regulatory exposure × operational consequence
- ✕EU AI Act applicability and role determination (provider / deployer)
- ✕NIST AI RMF 1.0 mapping across Govern, Map, Measure, Manage
- ✕ISO/IEC 42001 readiness gaps
- ✕Sector obligations: HIPAA, GLBA, state privacy and AI statutes, bar rules
- ✕Vendor and model due diligence: DPAs, training-data terms, subprocessors
- ✕Human oversight, escalation, and logging design review
- ✕Enterprise diligence readiness — the questionnaire answers pre-written
- ✕Risk-ranked findings with a sequenced remediation plan
The four weeks
A defined process, not an open-ended engagement
- 01
Week 1 — Inventory
Kickoff, stakeholder interviews, systems and vendor review. We surface every AI system in use, including the tools nobody told procurement about. Output: a complete AI inventory.
- 02
Week 2 — Classification
Each system is placed on two axes: regulatory exposure (what rules attach) and operational consequence (what happens when it's wrong). This is what determines depth of assessment — not vendor marketing tiers.
- 03
Week 3 — Assessment
Testing against versioned obligations: EU AI Act, NIST AI RMF 1.0, ISO/IEC 42001, and your sector's rules. Evidence is collected and recorded so a third party could reproduce the conclusion.
- 04
Week 4 — Report and signature
Risk-ranked findings, remediation sequence, board-ready executive memo, and the signed attestation page. Delivered in a working session, not emailed as a PDF and abandoned.
The deliverable
What you hold at the end
Five artifacts, each written for a specific reader.
Signed attestation page
Named assessor, scope boundary, framework versions, evidence reviewed, date of assessment, and the conclusion reached.
Risk-ranked findings register
Every gap, its exposure axis, its severity, and the obligation it maps to.
Remediation sequence
What to fix first, what can wait a quarter, and what is an accepted risk you document rather than fix.
Executive memo
Two pages your board or audit committee can read without translation.
Diligence packet
Pre-written answers to the AI questions enterprise procurement and security reviewers keep sending.
Price
From $12,500
Fixed fee, scaling with the number of AI systems in scope and regulatory complexity. Quoted and agreed before kickoff. No hourly billing, no scope creep.
Next step
Book a Governance Teardown.
Thirty minutes to confirm scope and fit. If a Teardown isn't the right engagement for where you are, we'll say so.