AI Governance
I help SMBs put real governance around AI — policies your regulator will accept, risk assessments grounded in recognized frameworks, and clear rules your people can actually follow.
Who this is for
AI governance matters for any organization putting AI to work — but the stakes are highest where oversight is real. I work with growing SMBs, typically $10M–$100M in revenue, including firms in regulated environments:
Acceptable-use and AI governance policies written for your business and your oversight — not downloaded templates. If you already have a policy, I'll review it against what regulators and auditors actually look for.
A framework-based assessment of how AI is being used across your business — sanctioned and unsanctioned — with findings ranked by risk and a prioritized remediation path.
Practical guardrails for the AI tools your team is already using — ChatGPT, Claude, Microsoft Copilot, and whatever arrives next: data exposure, access boundaries, and usage rules that protect the business without banning the tools people want to use.
When your auditor, examiner, or a key customer asks "show me your AI controls," you'll have an answer — documented, current, and mapped to a recognized framework.
Ongoing, part-time ownership of your AI governance program — policy upkeep, new-tool review, and a standing answer to "who owns this?"
How an engagement runs
A scoped discovery of how AI is actually used in your business today, assessed against recognized frameworks.
What's exposed, what's fine, and what oversight will ask about — ranked by risk, in plain language.
A prioritized plan: which gaps to close first and what it takes.
The policies and procedures that close your specific gaps — written to satisfy your regulator or oversight body, not a generic binder.
The deliverable is the artifact that satisfies your oversight — the assessment determines exactly what that artifact has to say.
Grounded in recognized frameworks
My methodology is built on the NIST AI Risk Management Framework and NIST Cybersecurity Framework 2.0, with additional frameworks applied as your regulatory environment requires. The assessment tooling and methodology are already built and in use — this is an operating practice, not a slide deck.
Book a 30-minute call. We'll talk about how AI is showing up in your business and whether a scoped governance assessment makes sense. No pitch.