AI Governance

Your team is already using AI. Is anyone governing it?

I help SMBs put real governance around AI — policies your regulator will accept, risk assessments grounded in recognized frameworks, and clear rules your people can actually follow.

Who this is for

Highest stakes where oversight is real.

AI governance matters for any organization putting AI to work — but the stakes are highest where oversight is real. I work with growing SMBs, typically $10M–$100M in revenue, including firms in regulated environments:

  • Financial services and RIAs (SEC / FINRA oversight)
  • Healthcare organizations (HIPAA)
  • Companies with SOX or audit-committee obligations
  • Any business where "we should probably have an AI policy" has come up in a leadership meeting

What I deliver

AI Policy Development & Review

Acceptable-use and AI governance policies written for your business and your oversight — not downloaded templates. If you already have a policy, I'll review it against what regulators and auditors actually look for.

AI Risk Assessment

A framework-based assessment of how AI is being used across your business — sanctioned and unsanctioned — with findings ranked by risk and a prioritized remediation path.

Generative-AI Tool Governance

Practical guardrails for the AI tools your team is already using — ChatGPT, Claude, Microsoft Copilot, and whatever arrives next: data exposure, access boundaries, and usage rules that protect the business without banning the tools people want to use.

AI Audit Readiness

When your auditor, examiner, or a key customer asks "show me your AI controls," you'll have an answer — documented, current, and mapped to a recognized framework.

Fractional AI Governance Officer

Ongoing, part-time ownership of your AI governance program — policy upkeep, new-tool review, and a standing answer to "who owns this?"

How an engagement runs

A clear path to artifacts your oversight will accept.

1

Assessment

A scoped discovery of how AI is actually used in your business today, assessed against recognized frameworks.

2

Findings

What's exposed, what's fine, and what oversight will ask about — ranked by risk, in plain language.

3

Roadmap

A prioritized plan: which gaps to close first and what it takes.

4

Governance artifacts

The policies and procedures that close your specific gaps — written to satisfy your regulator or oversight body, not a generic binder.

The deliverable is the artifact that satisfies your oversight — the assessment determines exactly what that artifact has to say.

Grounded in recognized frameworks

My methodology is built on the NIST AI Risk Management Framework and NIST Cybersecurity Framework 2.0, with additional frameworks applied as your regulatory environment requires. The assessment tooling and methodology are already built and in use — this is an operating practice, not a slide deck.

Start with a conversation, not a contract.

Book a 30-minute call. We'll talk about how AI is showing up in your business and whether a scoped governance assessment makes sense. No pitch.