Governance framework, regulatory analysis, and audit-ready documentation for organizations deploying AI under EU AI Act, NIST AI RMF, Colorado AI Act, NYC Local Law 144, and emerging frameworks. Built to pair with your counsel, not replace them.
Six frameworks covered as standard scope. Applicability to your specific deployment is determined during weeks 1-2 of the engagement and drives the focus of the rest.
Risk-tiered obligations for AI systems serving EU users. Prohibited practices, high-risk system requirements (Annex III), and transparency obligations for limited-risk systems. Extraterritorial scope — applies to non-EU companies serving EU users.
Voluntary framework increasingly required in US federal agency procurement, defense contracting, and enterprise vendor diligence. The four functions — Govern, Map, Measure, Manage — define the operational structure.
Consumer-facing high-risk AI systems regulated at state level. Risk assessments, consumer notifications, discrimination prevention required. First major US state-level AI law in effect.
Automated employment decision tools must undergo bias audits before use. Affects any employer hiring NYC-based candidates with AI-assisted screening — surprisingly broad reach.
Healthcare (HIPAA), financial (GLBA), and education (FERPA) privacy laws all have direct implications for AI systems processing the underlying data — BAAs, breach notification, minimum necessary use.
California, Illinois, Texas, Tennessee, Utah and others have AI-adjacent laws either in force or actively legislated. We map your deployment against the patchwork that applies to your customer base.
AI Compliance Setup is for organizations that have already decided to deploy AI and now need the governance and documentation layer to do it defensibly. If you're not deploying yet, start with AI Audit & Roadmap.
Fixed scope means the deliverables are defined before you sign. Here's exactly what shows up in your environment at the end of week 6.
A specific written analysis mapping your AI deployment(s) against EU AI Act, NIST AI RMF, Colorado AI Act, Local Law 144, sectoral laws, and emerging state frameworks. Tells you what applies, what doesn't, and where the gray areas live.
The governance body that owns AI decisions in your organization — composition, meeting cadence, decision authority, escalation paths, and the operating model that connects committee decisions to operational reality.
Tiered risk framework for your AI use cases (consumer-facing vs. internal, high-stakes vs. low-stakes, regulated data vs. non-regulated) with approval gates and process flow for each tier. Stops "should we deploy this?" from becoming a one-off conversation every time.
Living inventory template tracking every AI system in your organization — model used, data accessed, business owner, risk tier, documentation links, vendor assessment status. The single document auditors and procurement reviewers always ask for.
Model documentation, DPIA/bias audit templates, vendor assessment questionnaire, employee AI use policy, incident response runbook. All editable in Word, branded for your organization, ready for your counsel to red-line.
Two 90-minute presentations — one for leadership, one for legal/compliance teams. Each focused on the audience's specific questions. Recorded so absent stakeholders get the same context.
Three phases of two weeks each. Stakeholder-driven, counsel-aware, no scope drift.
Kickoff, stakeholder interviews (10-18 people across leadership, legal, security, business owners), AI deployment inventory, regulatory applicability analysis drafted and reviewed.
AI committee charter drafted, risk-tier classification built, approval workflow designed, model inventory template configured. Mid-phase review with sponsors before final document drafting begins.
Documentation templates finalized, branded, packaged. Executive briefing delivered to leadership. Legal briefing delivered to GC/outside counsel. Q&A sessions recorded. Handoff package complete.
The concrete files you receive at the end of week 6. Branded for your organization, editable in Word/Excel/PowerPoint, designed for your counsel to red-line and your operations team to live in.
Written memo mapping your deployment against 6 frameworks. Counsel-friendly format, ready for legal review.
Governance body charter — composition, authority, cadence, escalation. Editable for your specific committee structure.
Visual tiered classification with decision rules and approval gates. Presentable format for stakeholder rollout.
Living spreadsheet tracking every AI system. Pre-populated with your current inventory; structured for ongoing maintenance.
Standardized format for documenting each AI deployment — purpose, data flows, model details, evaluation results.
Privacy impact assessment and bias audit templates aligned with EU AI Act, NIST AI RMF, and NYC Local Law 144 requirements.
Pre-procurement AI vendor assessment questionnaire. Use it on third-party AI tools entering your stack.
Acceptable use policy in plain English — addressing shadow AI risks, customer data handling, approval requirements.
What to do when an AI system fails, produces harmful outputs, leaks data, or triggers regulatory notification thresholds.
Visual workflows for each risk tier — from intake through deployment. Embeddable in your internal tooling.
Leadership-focused presentation walkthrough with Q&A. Recorded and shared with the full leadership team.
GC and outside counsel-focused walkthrough with Q&A. Recorded for legal team review and ongoing reference.
AI Compliance Setup hits its timeline because stakeholder access and counsel coordination are locked on day one. Here's what we need from you.
One C-level or VP sponsor (often Chief Risk Officer, COO, or CTO) plus one named legal contact (GC, outside counsel, or Privacy Officer) for counsel-side coordination.
Leadership, GC/outside counsel, security/risk, privacy officer, business unit owners with AI use cases, IT/data leader, HR if employee-facing AI is in scope.
Best understanding of what AI you currently have deployed — your own custom systems, third-party AI tools, AI features in existing SaaS. We refine in week 1; you bring the starting list.
Where your customers are (EU users? consumers? B2B?), what industry you operate in, what data flows are involved. Drives the applicability analysis.
Whatever data privacy, security, vendor management, or governance documentation already exists. We integrate with what you have — we don't replace it unnecessarily.
$12,500 deposit on SOW signature kicks off week 1. Balance due on delivery at end of week 6.
The honest answers to the questions buyers ask in the intake call. If yours isn't here, ask us when we talk.
Book a 30-minute intake call. We'll confirm fit, identify stakeholders, and send an SOW within 48 hours if it's a match.