Readiness Assessment
Scored gap analysis against all of Annex A, AI system inventory and risk register, draft Statement of Applicability, and a roadmap you can take to a budget conversation.
Practice areas
Engagements are scoped from a conversation, not a catalogue. Most combine two or three of these, because the problems do.
01 · AI Risk Management
The first job is always inventory. Which systems use AI, whose data they touch, what decisions they influence, and which of them a customer or regulator would call high risk. Very few have that full list when we start, and the ones who think they do are usually missing some vendor-embedded features.
From there it is risk and impact assessment against a real methodology, not a spreadsheet of adjectives. We use ISO/IEC 42001 as the spine and cross-map to the EU AI Act and NIST AI RMF, so one body of evidence answers several audiences.
02 · ISO/IEC 42001 Leadership
42001 is the first certifiable standard for managing AI, and it is becoming the shorthand answer to the question your customers keep asking. As a certified Lead Implementer, we run the build the way we build high performing security programs: with the people who have to live inside it.
If your organization already holds ISO 9001 or 27001, a good chunk of the machinery is reusable and the timeline shortens.
Scored gap analysis against all of Annex A, AI system inventory and risk register, draft Statement of Applicability, and a roadmap you can take to a budget conversation.
Policy and scope, risk and impact methodology, Annex A control build-out, control-owner enablement, internal audit, and management review. I stay through the certification audit.
Quarterly reviews, annual internal audit and management review, surveillance-audit prep, and new AI systems brought into scope as they ship.
03 · Cybersecurity
Twenty-five years of this, most of it accountable for the outcome rather than advising on it. Program assessment, architecture review, and the unglamorous work of deciding what to fix first when everything is on fire.
The newer part is what agentic systems did to the perimeter. An agent with tool access and a credential may be useful, or may pose what we call a Lethal Trifecta of risk. APIs are how it reaches everything else, and our background in API Security comes in very handy in tracing this all out.
04 · vCISO / CAISO / CIO
Some companies need the seat filled between hires. Some have a capable team that needs somebody who has already made the expensive mistakes. Either way you get a practitioner in the chair, not a junior consultant with a template and a partner who shows up for the QBR.
The Chief AI Security Officer version of this is new and increasingly what gets asked for: one person to wrap their head around AI risk across security, legal, data, and the product teams shipping the models.
05 · Technology Governance
Most governance failures I see are not control failures. They are decision-rights failures: three groups each believed another one owned the call, and the AI vendor got signed by whoever had a corporate card.
This work sets the operating model. Which decisions go to a committee and which do not, what a business case has to contain before it gets funded, and how the technology portfolio gets reviewed so that spend and risk are visible in the same conversation.
06 · Board Advisory
Boards are being asked to oversee AI risk with materials written by the people whose programs they are overseeing. I sit on the other side of that: an independent read, in language a director can act on, with no product to sell you afterward.
I am an NACD certified director and I have presented to boards and audit committees for twenty years, including the meetings that followed an incident. I know what the questions sound like and what an honest answer costs.
That is a normal place to start. Describe the situation and I will tell you what the work actually is, including when it is smaller than you feared.
Book a 30-Minute Consult