RAI = ROI Responsible AI is how you get a return on AI

The pressure is to ship AI. The job is to ship it defensibly.

For most companies, AI showed up through a dozen doors at once: SaaS features, vendor copilots you never asked for, and AI pilot projects that just sort of morphed into production. Now first and third party agents are everywhere, none of them have been threat-modeled, and the push is to scale to get that elusive ROI. But you can't safely scale what you haven't governed, and the deadlines are no longer yours to set.

The EU AI Act is live; your board, your biggest customers, and your regulators all want written evidence of AI risk management and governance aligned with recognized frameworks.

Getting your business ready for this new operating model is where we come in. We work with your teams to map, measure, manage, and govern your AI systems so they're ready to scale, ready for adversaries, and ready for audit.

Book a 30-Minute Consult See the practice areas
25+
Years in the practice
20+
Years as a CISO
65+
Keynotes delivered

CSA TAISE  ·  ISO/IEC 42001 Lead Implementer  ·  NACD.DC   |   AIG  ·  Athene  ·  Texas Capital Bank  ·  F5

RAI = ROI
Responsible AI = Return on AI

Governance is not a tax on your AI program; it's the only way your program pays off.

Most AI programs have the same issues right now; difficulty proving what the models do, where the training data came from, who is monitoring what, and who signed off on putting it in front of a customer. The governance work is what gets the thing into production, and more importantly, generates a return to make it worth keeping there.

While many teams didn't put tight governance in place during the race to build, businesses are figuring out that AI governance isn't actually a tax on achieving an AI ROI; it's the precondition for it.

In other words — if you think AI governance is expensive, try running your business on ungoverned AI. Now the regulators are watching, and while regulators aren't always right, they do tend to be undefeated.

Why leaders call

Four conversations arriving at once.

Any one of them is serious, and they almost never show up alone.

The deal desk

Your customer's procurement team added AI questions to the security review. They do business in the EU, your answers live across four teams, and the renewal is on the clock.

The board

A director concerned about Director liability asked how AI is governed and the answer was a list of tools. Didn't go well, and if it hasn't happened yet, it will. Everyone in the room can guess how that lands.

The regulator

EU AI Act obligations are in force with more sections coming in 2027, and your Risk team and regulators are asking the same questions. You need to know which systems are in scope, why, and what that entails before someone else decides for you.

The estate - your tools and your supply chain

Nobody can say how many AI systems the company is running. Building that inventory and keeping it current is the first piece of governance, and it changes as your teams and vendors continue to try and "AI All The Things", whether you asked for it or not.

The practice

Six areas. One firm. Blended rates for budgets.

In 2026, AI work and our security work are the same work now, so I stopped separating them. Engagements combine these as the situation requires.

AI Risk Management

Inventory, risk and impact assessment, model and agent risk, third-party AI. Mapped to ISO/IEC 42001, the EU AI Act, and NIST AI RMF.

Read more →

ISO/IEC 42001 Leadership

Readiness assessment through certification-ready AI management system, then the surveillance cycle after. Lead Implementer certified.

Read more →

Cybersecurity

Program assessment, API and application security, identity, and the attack surface that agentic systems just added to yours.

Read more →

vCISO / CAISO / CIO

Senior leadership on a fraction of a headcount: security, AI, or technology, between hires or alongside a team that needs depth.

Read more →

Technology Governance

Decision rights, spend discipline, and the operating model that decides which technology bets get made and who owns the outcome.

Read more →

Board Advisory

Independent counsel to boards and audit committees on cyber and AI risk, in language a director can act on. NACD.DC trained and certified Board Director.

Read more →

The ISO/IEC 42001 track

Three engagements, in sequence or on their own.

Most clients start with the assessment. It turns an open-ended worry into a plan, a budget, a schedule, and a named owner for each gap.

01

AI Governance Readiness Assessment

Where you stand against ISO/IEC 42001, cross-mapped to the EU AI Act and NIST AI RMF. You get a scored gap analysis, an AI system inventory and risk register, a draft Statement of Applicability, and a roadmap with owners and sequencing.

Fixed fee or retainer-based, scoped up front
3–6 weeks
02

ISO/IEC 42001 Implementation

I build the management system with your team and hand you to the audit ready to pass. Policy and scope, AI risk and impact assessment methodology, Annex A controls, control-owner enablement, internal audit, management review. Tailored to how you actually run AI.

Fixed fee or retainer-based, scoped up front
3–9 months
03

Managed AIMS Retainer

The ISO42001 certification lasts three years and the auditor comes back for a surveillance audit every single one. Avoid surprises with quarterly reviews, annual internal audit support and management review, surveillance prep, and new AI systems absorbed into scope as they ship.

Fixed fee or retainer-based, scoped up front
12-month term, reviewed annually

Where we fit in

The architect, not the building inspector.

Herrin Advisory is independent. I prepare your organization for certification, and work with your team and an accredited certification body; consulting, auditing, and certification must be separated, and I cannot guarantee an outcome.

Budget for the audit itself and for whatever GRC tooling you use or choose. I will size both with you before you sign anything, so the number you approve is the number you spend.

Chuck Herrin
Chuck Herrin Founder, Herrin Advisory. Former CISO at AIG, Athene, and Texas Capital Bank. Field CISO at F5.

Who you would be working with

A security practitioner doing governance, not a governance shop learning security.

I spent twenty-five years in security, more than twenty of them in the CISO chair, at the world's largest insurer, an annuities carrier (IPO of the Year 2016), and a bank (Most Trusted Bank in America, 2022). Regulated environments, real audits, real consequences when the answer was wrong.

Then I became a founder, built API and AI security as a CTO at Wib (acquired by F5) and Field CISO at F5. That is where I started seeing the AI questions arrive faster than anybody could answer them, which is what this practice is now for.

Plenty of 42001 shops can write you a policy set. Fewer know how to perform AI threat modeling, can tell you what your model's attack surface looks like, what your AI agents can be tricked into doing, or which vendor claim will not survive contact with a real assessment.

CSA TAISE Certified ISO/IEC 42001 Lead Implementer NACD Directorship Certified 25+ Years in Security
More about Chuck →

Let's figure out what you are running.

Tell me what you have deployed and what is making you nervous. You will leave with a clearer view of your exposure whether or not we partner. If Herrin Advisory is not the right partner, I will say so and can usually tell you who is.

Book a 30-Minute Consult