PRODUCTIZED · AUDIT-READY DELIVERY

AI Compliance
Setup.

Governance framework, regulatory analysis, and audit-ready documentation for organizations deploying AI under EU AI Act, NIST AI RMF, Colorado AI Act, NYC Local Law 144, and emerging frameworks. Built to pair with your counsel, not replace them.

$25,000
6-week engagement
50% deposit · Balance on delivery
6 frameworks mapped Audit-ready documentation Pairs with your counsel
// PRODUCT SHEET
AI Compliance Setup
SKU · DLS-ACS-V1
// Duration 6 weeks
// Frameworks 6 covered
// Interviews 10–18 stakeholders
// Documentation 12+ artifacts
// Legal Pairing Counsel-friendly
// Briefing Exec + Legal
// Investment $25,000 USD

The regulatory map
your deployment crosses.

Six frameworks covered as standard scope. Applicability to your specific deployment is determined during weeks 1-2 of the engagement and drives the focus of the rest.

// EUROPEAN UNION IN FORCE

EU AI Act

Risk-tiered obligations for AI systems serving EU users. Prohibited practices, high-risk system requirements (Annex III), and transparency obligations for limited-risk systems. Extraterritorial scope — applies to non-EU companies serving EU users.

// UNITED STATES VOLUNTARY

NIST AI RMF

Voluntary framework increasingly required in US federal agency procurement, defense contracting, and enterprise vendor diligence. The four functions — Govern, Map, Measure, Manage — define the operational structure.

// COLORADO 2026

Colorado AI Act

Consumer-facing high-risk AI systems regulated at state level. Risk assessments, consumer notifications, discrimination prevention required. First major US state-level AI law in effect.

// NEW YORK CITY IN FORCE

Local Law 144

Automated employment decision tools must undergo bias audits before use. Affects any employer hiring NYC-based candidates with AI-assisted screening — surprisingly broad reach.

// SECTORAL · US FEDERAL

HIPAA · GLBA · FERPA

Healthcare (HIPAA), financial (GLBA), and education (FERPA) privacy laws all have direct implications for AI systems processing the underlying data — BAAs, breach notification, minimum necessary use.

// EMERGING · US STATES EVOLVING

State AI Laws

California, Illinois, Texas, Tennessee, Utah and others have AI-adjacent laws either in force or actively legislated. We map your deployment against the patchwork that applies to your customer base.

Is this the right starting point?

AI Compliance Setup is for organizations that have already decided to deploy AI and now need the governance and documentation layer to do it defensibly. If you're not deploying yet, start with AI Audit & Roadmap.

// THIS IS FOR YOU IF

You're deploying AI and need to prove it's safe

  • You're deploying AI to consumers, employees, or in a regulated industry, and you need the governance layer in place before going live
  • You serve EU users and need EU AI Act applicability resolved before broader deployment
  • You're being asked for AI governance documentation in enterprise customer security reviews or RFPs and lacking answers is costing deals
  • Your legal counsel has asked for operational compliance documentation they can review — not generic templates they'd have to write from scratch
  • You need an AI committee, model inventory, and approval workflow to make AI buildouts repeatable
  • You have 10-18 stakeholders available for interviews including GC/outside counsel, security/risk, and business owners
// LOOK ELSEWHERE IF

Your need is something else

  • You need a binding legal opinion or representation in regulatory proceedings — that's your counsel's work, not ours
  • You don't yet know what AI you're deploying — start with AI Audit & Roadmap first
  • You need SOC 2, ISO 27001, or general InfoSec certification — different specialty entirely
  • You're a small business with one off-the-shelf SaaS AI tool — the included framework is probably enough; you don't need this
  • You need formal regulator engagement, fines defense, or enforcement counsel — see your law firm
  • You want compliance theater for a sales process you don't actually intend to operationalize — we won't sell that

Six things you get.
Audit-ready.

Fixed scope means the deliverables are defined before you sign. Here's exactly what shows up in your environment at the end of week 6.

// INCLUDED 01

Regulatory applicability analysis

A specific written analysis mapping your AI deployment(s) against EU AI Act, NIST AI RMF, Colorado AI Act, Local Law 144, sectoral laws, and emerging state frameworks. Tells you what applies, what doesn't, and where the gray areas live.

// INCLUDED 02

AI committee charter & operating model

The governance body that owns AI decisions in your organization — composition, meeting cadence, decision authority, escalation paths, and the operating model that connects committee decisions to operational reality.

// INCLUDED 03

Risk-tier classification + approval workflow

Tiered risk framework for your AI use cases (consumer-facing vs. internal, high-stakes vs. low-stakes, regulated data vs. non-regulated) with approval gates and process flow for each tier. Stops "should we deploy this?" from becoming a one-off conversation every time.

// INCLUDED 04

Model & use-case inventory

Living inventory template tracking every AI system in your organization — model used, data accessed, business owner, risk tier, documentation links, vendor assessment status. The single document auditors and procurement reviewers always ask for.

// INCLUDED 05

Documentation templates

Model documentation, DPIA/bias audit templates, vendor assessment questionnaire, employee AI use policy, incident response runbook. All editable in Word, branded for your organization, ready for your counsel to red-line.

// INCLUDED 06

Executive + legal briefing

Two 90-minute presentations — one for leadership, one for legal/compliance teams. Each focused on the audience's specific questions. Recorded so absent stakeholders get the same context.

From regulatory scoping to audit-ready
in 30 working days.

Three phases of two weeks each. Stakeholder-driven, counsel-aware, no scope drift.

// WEEKS 1–2
01
// PHASE ONE · SCOPE

Regulatory scoping

Kickoff, stakeholder interviews (10-18 people across leadership, legal, security, business owners), AI deployment inventory, regulatory applicability analysis drafted and reviewed.

// END OF PHASE
Applicability analysis + deployment inventory
// WEEKS 3–4
02
// PHASE TWO · DESIGN

Governance framework

AI committee charter drafted, risk-tier classification built, approval workflow designed, model inventory template configured. Mid-phase review with sponsors before final document drafting begins.

// END OF PHASE
Governance framework approved
// WEEKS 5–6
03
// PHASE THREE · DELIVERY

Documentation + briefings

Documentation templates finalized, branded, packaged. Executive briefing delivered to leadership. Legal briefing delivered to GC/outside counsel. Q&A sessions recorded. Handoff package complete.

// END OF PHASE
Full delivery + executive & legal briefings

Twelve documents. All yours. All editable.

The concrete files you receive at the end of week 6. Branded for your organization, editable in Word/Excel/PowerPoint, designed for your counsel to red-line and your operations team to live in.

§

Applicability analysis (.docx)

Written memo mapping your deployment against 6 frameworks. Counsel-friendly format, ready for legal review.

AI committee charter (.docx)

Governance body charter — composition, authority, cadence, escalation. Editable for your specific committee structure.

Risk-tier framework (.pptx)

Visual tiered classification with decision rules and approval gates. Presentable format for stakeholder rollout.

Model inventory template (.xlsx)

Living spreadsheet tracking every AI system. Pre-populated with your current inventory; structured for ongoing maintenance.

Model documentation template (.docx)

Standardized format for documenting each AI deployment — purpose, data flows, model details, evaluation results.

DPIA / bias audit template (.docx)

Privacy impact assessment and bias audit templates aligned with EU AI Act, NIST AI RMF, and NYC Local Law 144 requirements.

?

Vendor questionnaire (.docx)

Pre-procurement AI vendor assessment questionnaire. Use it on third-party AI tools entering your stack.

Employee AI use policy (.docx)

Acceptable use policy in plain English — addressing shadow AI risks, customer data handling, approval requirements.

!

Incident response runbook (.docx)

What to do when an AI system fails, produces harmful outputs, leaks data, or triggers regulatory notification thresholds.

Approval workflow diagrams (.pdf)

Visual workflows for each risk tier — from intake through deployment. Embeddable in your internal tooling.

Executive briefing recording

Leadership-focused presentation walkthrough with Q&A. Recorded and shared with the full leadership team.

Legal briefing recording

GC and outside counsel-focused walkthrough with Q&A. Recorded for legal team review and ongoing reference.

Six inputs to make this land in 6 weeks.

AI Compliance Setup hits its timeline because stakeholder access and counsel coordination are locked on day one. Here's what we need from you.

// 01
An executive sponsor + legal point of contact

One C-level or VP sponsor (often Chief Risk Officer, COO, or CTO) plus one named legal contact (GC, outside counsel, or Privacy Officer) for counsel-side coordination.

// 02
10-18 stakeholders for interviews

Leadership, GC/outside counsel, security/risk, privacy officer, business unit owners with AI use cases, IT/data leader, HR if employee-facing AI is in scope.

// 03
Current AI deployment inventory

Best understanding of what AI you currently have deployed — your own custom systems, third-party AI tools, AI features in existing SaaS. We refine in week 1; you bring the starting list.

// 04
Customer geography & sector profile

Where your customers are (EU users? consumers? B2B?), what industry you operate in, what data flows are involved. Drives the applicability analysis.

// 05
Existing policies & frameworks

Whatever data privacy, security, vendor management, or governance documentation already exists. We integrate with what you have — we don't replace it unnecessarily.

// 06
50% deposit

$12,500 deposit on SOW signature kicks off week 1. Balance due on delivery at end of week 6.

Things buyers ask
before clicking.

The honest answers to the questions buyers ask in the intake call. If yours isn't here, ask us when we talk.

No, and no — and this is critically important to be clear about. We're AI implementation strategists, not attorneys. AI Compliance Setup produces operational governance documentation, regulatory applicability analysis, and templates that pair with your legal counsel — they're not a substitute for it. For binding legal opinions, regulatory filings, or representation in enforcement actions, you need your own attorneys. About 80% of our compliance engagements involve direct working sessions with the client's GC or outside counsel — we expect to work alongside them, not around them.
Possibly — extraterritorial scope is one of the most important EU AI Act provisions. If your AI system's outputs are used in the EU (including by EU users accessing your US-hosted product), the Act may apply. We can't give you a one-line yes/no — it depends on whether you place AI systems on the EU market, deploy them in the EU, or have outputs used in the EU. The applicability analysis in this engagement gives you a written, counsel-reviewable answer. If you have zero EU exposure (no EU customers, no EU employees, no EU partners), we can confirm that quickly and the rest of the engagement can deprioritize the EU AI Act in favor of US frameworks.
Three differences. (1) Scope and price — our engagement is $25K and runs 6 weeks. The Big Four equivalent is typically $150K-$500K over 4-6 months. (2) Practitioner depth on AI specifically — most Big Four AI risk practices are staffed by traditional risk/audit professionals expanding into AI; we're AI practitioners who learned compliance. (3) Operational orientation — our deliverables are written to be used by your team for ongoing operations, not packaged as a one-time advisory report. Where you do need Big Four scale (multi-jurisdiction regulator engagement, board-level transformation, audit attestation), we'll tell you and recommend going there instead.
"Audit-ready" means the documentation is structured for audit review — proper traceability, mapped to framework requirements, version-controlled, and accompanied by evidence. But two important caveats: (1) "passing an audit" depends on whether your operational reality matches what the documentation says — we build the templates, you live them; (2) we don't conduct the audit. For formal third-party audit attestation against specific frameworks (ISO 42001 AI Management Systems, SOC 2 with AI controls), you'd engage a certified auditing body — our work makes their work efficient, but it isn't a substitute for it.
Expected and welcomed. All deliverables come in editable Word format precisely because they're starting points your counsel will refine. We schedule explicit working sessions with your GC or outside counsel during weeks 2-3 (governance framework review) and week 6 (legal briefing). Counsel red-lines flow back into the templates before final delivery. If your counsel wants language we wouldn't have included by default, we adapt — within scope. The end product belongs to your organization and reflects your counsel's posture, not ours.
Standard scope includes HIPAA, GLBA, and FERPA at a strategic level — applicability analysis, key obligations, AI-specific implications. For deep sectoral compliance work (full HIPAA BAA negotiation playbooks, FedRAMP-adjacent controls, FINRA/SEC AI guidance specifics), we typically scope an additional 2-3 weeks at custom rates. We confirm during the intake call whether standard scope covers your sectoral needs or whether expanded scope is warranted. Most clients in healthcare and finance need expanded scope; most clients in education are well-covered by standard scope.
We design the documentation to be GRC-platform friendly — model inventory exports cleanly to most platforms, risk tiers map to standard GRC risk frameworks, approval workflows integrate with most platforms' workflow engines. We're not a GRC platform replacement; we're the AI-specific layer that sits on top of (or alongside) your existing GRC. If you don't have a GRC platform yet and want a recommendation, we can advise during scoping but we don't resell GRC tools.
Three options post-engagement. (1) Your team operates the framework with periodic touchpoints — most common path. (2) Quarterly review retainer ($5K-$10K/quarter) — we review framework operation, update regulatory developments, refresh templates as laws change. (3) Fractional AI CTO retainer ($10K-$25K/month, 6-month minimum) for organizations wanting embedded strategic and compliance leadership. Regulatory landscape changes — Colorado AI Act amendments, EU AI Act technical specifications, new state laws — so the documentation needs periodic refresh whether through us or your internal team.
Standard scope includes tracking and applicability analysis for the active state law patchwork (California, Illinois, Texas, Tennessee, Utah, others) as of engagement start. New laws that pass during the engagement get incorporated into the analysis. For ongoing monitoring after delivery, the quarterly review retainer covers regulatory updates. We deliberately don't speculate about pending federal legislation in templates — we cover what's actually in force, since speculation in compliance documentation is a liability.
The 50% deposit is non-refundable once week 1 stakeholder interviews are scheduled. If we materially fail to deliver against the scope agreed in the SOW, we work to fix it under our limited services warranty (re-perform or correct) — Terms §11. If you terminate without cause mid-engagement, you owe for work performed through termination. Specifically for compliance work: we do not guarantee specific regulatory outcomes (passing a specific audit, avoiding a specific enforcement action) — those depend on operational reality, counsel decisions, and factors outside our control. We do guarantee delivery of all scoped artifacts and our professional best effort in producing them.

From regulatory uncertainty
to audit-ready in 42 days.

Book a 30-minute intake call. We'll confirm fit, identify stakeholders, and send an SOW within 48 hours if it's a match.

Fixed price · 12 artifacts delivered · Counsel-friendly format