Flagship engagement

The Governance Teardown

Four weeks. Fixed fee. We take your AI apart against the rules that actually apply to it, tell you what's risky in priority order, and sign the assessment.

Scope

What the Teardown covers

Scope is confirmed in writing before the engagement starts. Nothing is discovered mid-project and billed as a change order.

  • Full AI inventory, including shadow AI discovered through interviews and system review
  • Two-axis classification: regulatory exposure × operational consequence
  • EU AI Act applicability and role determination (provider / deployer)
  • NIST AI RMF 1.0 mapping across Govern, Map, Measure, Manage
  • ISO/IEC 42001 readiness gaps
  • Sector obligations: HIPAA, GLBA, state privacy and AI statutes, bar rules
  • Vendor and model due diligence: DPAs, training-data terms, subprocessors
  • Human oversight, escalation, and logging design review
  • Enterprise diligence readiness — the questionnaire answers pre-written
  • Risk-ranked findings with a sequenced remediation plan

The four weeks

A defined process, not an open-ended engagement

  1. 01

    Week 1 — Inventory

    Kickoff, stakeholder interviews, systems and vendor review. We surface every AI system in use, including the tools nobody told procurement about. Output: a complete AI inventory.

  2. 02

    Week 2 — Classification

    Each system is placed on two axes: regulatory exposure (what rules attach) and operational consequence (what happens when it's wrong). This is what determines depth of assessment — not vendor marketing tiers.

  3. 03

    Week 3 — Assessment

    Testing against versioned obligations: EU AI Act, NIST AI RMF 1.0, ISO/IEC 42001, and your sector's rules. Evidence is collected and recorded so a third party could reproduce the conclusion.

  4. 04

    Week 4 — Report and signature

    Risk-ranked findings, remediation sequence, board-ready executive memo, and the signed attestation page. Delivered in a working session, not emailed as a PDF and abandoned.

The deliverable

What you hold at the end

Five artifacts, each written for a specific reader.

Signed attestation page

Named assessor, scope boundary, framework versions, evidence reviewed, date of assessment, and the conclusion reached.

Risk-ranked findings register

Every gap, its exposure axis, its severity, and the obligation it maps to.

Remediation sequence

What to fix first, what can wait a quarter, and what is an accepted risk you document rather than fix.

Executive memo

Two pages your board or audit committee can read without translation.

Diligence packet

Pre-written answers to the AI questions enterprise procurement and security reviewers keep sending.

Price

From $12,500

Fixed fee, scaling with the number of AI systems in scope and regulatory complexity. Quoted and agreed before kickoff. No hourly billing, no scope creep.

Next step

Book a Governance Teardown.

Thirty minutes to confirm scope and fit. If a Teardown isn't the right engagement for where you are, we'll say so.