AI Governance Maturity Audit

Know Exactly Where Your AI Governance Gaps Are

A structured 30/60/90-day audit that scores your organization across 8 governance domains, identifies gaps before regulators do, and delivers a prioritized roadmap to close them.

Built on the Frameworks That Matter

The assessment maps findings directly to the governance standards your board, legal team, and regulators recognize.

Aligned to: NIST AI RMF ISO/IEC 42001 EU AI Act OECD AI Principles OWASP AI Security

The AI Governance Gap Is Growing

Organizations are deploying AI systems faster than they can govern them. The result: regulatory exposure, compliance gaps, and systems nobody fully understands operating in production.

No Visibility

You don't have a complete picture of which AI systems are running, who owns them, or how they impact customers and employees.

Accountability Gaps

Nobody formally owns AI governance. When something breaks—a biased model, a data breach, a regulatory inquiry—it's unclear who's responsible.

Regulatory Exposure

The EU AI Act, NIST AI RMF, and sector-specific regulations are tightening. Operating without documented governance is an increasing liability.

From Baseline to Roadmap in 90 Days

Each phase builds on the last. Start with the 30-day discovery—expand based on findings. Every phase ends with a clear deliverable, not a slide deck that gathers dust.

Phase 1 · Days 1–30

Discovery & Baseline

$8,500
Fixed fee · Remote delivery

Surface-level assessment to understand current AI use, existing policies, and quick-win opportunities.

  • AI system inventory across all departments
  • 8-domain governance maturity scorecard
  • Executive summary with RAG status
  • Top-5 immediate action items
  • Stakeholder interview guide
Get Started
Phases 1 + 2 · Days 1–60

Deep Dive & Gap Analysis

$22,500
Fixed fee · Includes Phase 1

Process mapping, risk analysis, and detailed gap identification with document review and stakeholder interviews.

  • Everything in 30-Day Discovery
  • Detailed gap analysis report
  • AI Risk Register (systems × risks)
  • Data lineage & model lifecycle review
  • Regulatory compliance checklist
  • Vendor/third-party AI risk assessment
Schedule a Call →
Phases 1 + 2 + 3 · Days 1–90

Full Audit & Roadmap

$45,000
Fixed fee · All phases included

Control testing, compliance validation, and a board-ready strategic roadmap for achieving target maturity.

  • Everything in 60-Day Deep Dive
  • Full governance audit report
  • 12-month AI governance roadmap
  • Board presentation deck
  • ISO/IEC 42001 gap assessment
  • Policy & charter templates
  • 30-day post-delivery support
Contact for Scope

Pricing is indicative. Final scope confirmed after a free 30-minute discovery call. Regulated industries may have adjusted rates.

8 Domains. One Complete Picture.

The audit evaluates every dimension of AI governance that matters—from strategy and ethics to security and regulatory compliance.

🎯
Strategy & Leadership
AI vision, executive accountability, governance structure, and investment prioritization frameworks.
🛡️
Risk Management
AI risk identification, classification, mitigation controls, monitoring, and incident response protocols.
🗄️
Data Governance
Training data quality, lineage tracking, access controls, privacy obligations, and retention policies.
🤖
Model Lifecycle & MLOps
Development standards, validation gates, deployment controls, drift monitoring, and model retirement.
⚖️
Ethics & Responsible AI
Fairness testing, bias mitigation, explainability requirements, human oversight, and appeals processes.
🔐
AI Security & Privacy
Adversarial robustness, prompt injection defense, data poisoning controls, and output safety guardrails.
📜
Compliance & Regulatory
NIST AI RMF, EU AI Act, ISO 42001, and sector-specific regulatory obligations mapped to your AI systems.
🌱
Culture & Enablement
AI literacy baseline, role-based training, change management, and workforce adoption measurement.

How We Classify AI Risk

Not all AI systems require the same level of governance. We use a risk-based approach aligned to EU AI Act tiers to focus effort where it matters most.

High Risk
High-Impact Decisions

AI systems affecting customer safety, rights, employment, or regulatory compliance require maximum governance and control.

Examples: Credit decisions · Hiring screening · Medical triage · Content moderation at scale
Medium Risk
Important Operations

Systems that materially impact business operations but carry lower external risk. Still require defined controls and monitoring.

Examples: Demand forecasting · Pricing optimization · Internal automation · Customer service AI
Low Risk
Experimentation

Proof-of-concept, internal pilot, and experimental systems with limited scope. Lightweight oversight with clear escalation paths.

Examples: Internal productivity tools · Prototype models · Shadow IT AI tools · GenAI pilots

Structured. Evidence-Based. No Filler.

The assessment combines structured interviews, document review, and direct observation—not a checkbox survey emailed to your team.

01
Kickoff & Scoping

Define scope, identify key stakeholders, and customize the assessment to your industry, size, and regulatory environment. No generic frameworks.

02
Evidence Collection

Gather AI policies, model documentation, data catalogs, and vendor contracts. Conduct structured stakeholder interviews across functions.

03
Scoring & Benchmarking

Score each domain against a 5-level maturity model. Benchmark against industry peers and NIST AI RMF maturity expectations.

04
Report & Readout

Deliver scored report with prioritized findings, then walk through results in a live session with your leadership team.

05
Roadmap & Handoff

Co-develop a sequenced governance roadmap with owners, effort estimates, timelines, and measurable success criteria.

06
Optional: Implementation

Fractional engagement to lead roadmap execution—standing up governance structures, drafting policies, and building accountability systems.

Tangible Deliverables, Not Just a Score

Every engagement ends with a set of concrete outputs your team can act on immediately.

📊
Maturity Scorecard

Domain-by-domain scores against a 5-level maturity model, benchmarked to NIST AI RMF and ISO 42001.

⚠️
AI Risk Register

Every AI system mapped to identified risks, existing controls, gaps, and named remediation owners.

🗺️
12-Month Roadmap

Prioritized, sequenced governance improvements with effort estimates, owners, and business justification.

📁
Policy Templates

Draft AI policy, ethics guidelines, and governance charter templates ready to adapt to your organization.

🎤
Board Presentation

Executive-ready deck communicating risk exposure, maturity gaps, and the investment case for governance.

Compliance Checklist

Mapped obligations against EU AI Act, NIST AI RMF, and applicable sector-specific regulations.

8
Governance Domains Assessed
40+
Evidence-Based Control Questions
5
Maturity Levels Scored
4
Major Frameworks Aligned

Frequently Asked Questions

What size organizations is this designed for?

Mid-market to enterprise organizations (100+ employees) that are actively using AI in operations or products. I also work with startups that want to build governance foundations early—before scale makes it expensive to fix.

How disruptive is the assessment process?

Minimal. Most engagements require 2–4 hours of time from key stakeholders (CTO, legal, data teams) spread over the engagement period. Document requests are batched and coordinated to avoid back-and-forth.

We're just starting with AI. Is this still relevant?

That's actually the best time to assess. Building governance foundations early costs a fraction of remediating gaps after systems are in production. The 30-Day Discovery is specifically designed for organizations at early maturity stages.

Does the assessment cover generative AI and LLMs specifically?

Yes. GenAI and LLM-specific risks—prompt injection, sensitive data leakage, hallucination, shadow AI usage, and vendor model governance—are explicitly covered across the Security, Ethics, and Risk domains.

Can we start with one phase without committing to all three?

Yes. Each phase is a standalone engagement. Most clients start with the 30-Day Discovery and expand based on findings and organizational readiness. There's no obligation to continue beyond the initial phase.

What makes this different from a generic governance framework consultation?

I co-authored the enterprise AI governance framework at Equifax—a $2.4B+ revenue organization with active AI deployments across regulated business lines. This isn't theoretical. The assessment reflects what actually works in production environments, not what looks good in a whitepaper.

Ready to Know Your AI Governance Score?

Schedule a free 30-minute conversation. I'll give you an honest read on your biggest gaps—at no cost and no obligation.

Response within 24 hours · National & remote engagements · Currently accepting 1–2 new clients