AI Risk Workshop
Half-day session with leadership. Inventory of AI in the environment, top five risks by impact, one-page summary of next moves.
Your team is already shipping AI features. Your procurement queue is full of SaaS products that ship with an LLM bundled in. Your employees are pasting customer data into chatbots. AI risk is a security problem you can no longer defer.
Most mid-market companies do not have a single, named AI strategy. What they have is dozens of unsupervised AI footprints. A marketing team using ChatGPT to summarize customer interviews. A sales engineer pasting prospect data into Claude. A developer accepting suggestions from an AI coding assistant that was trained on someone else's code. Finance running Copilot over a workbook full of customer financials. Every one of those is a data-handling decision, made by an individual contributor, without a written rule.
At the same time, your customers are sending you AI security questionnaires. Your auditors are asking what governance you have over your AI use. Your contracts now contain AI clauses that someone signed without reading. The risk surface is real, and it is already in the environment.
You do not have an AI strategy problem. You have dozens of unsupervised AI footprints and no written rule. The first deliverable is the rule.
Where AI governance actually startsThe models already in your environment
The AI RMF is the closest thing the United States has to a shared language for AI governance, and it is the right baseline for a mid-market program. It has four functions, and a readiness engagement walks each one against the AI footprint in your environment.
Deliverable is a written AI RMF profile sized to your environment: governance charter, use case inventory, risk register, measurement plan, and response runbook.
For organizations building with LLMs (chatbots, internal copilots, retrieval-augmented assistants, agentic workflows), the OWASP Top 10 for Large Language Models is the security checklist that should be on every architecture review. We map the application architecture against each risk and write the trade-offs down.
The most leveraged AI work in a mid-market environment is not building a model. It is contracting around someone else's. Every renewal in the next twelve months will arrive with AI clauses bolted in. Most are written to favor the vendor.
We read the contracts with you, name the questions to ask before renewal, and draft the redlines that protect your data and your customers' data. The deliverable is a vendor matrix plus a contract appendix template you can reuse.
ISO/IEC 42001 is the first management system standard for AI. If you sell into regulated industries, into governments, or into large enterprise that already has an ISO 27001 program, expect 42001 to land on a procurement questionnaire within the next eighteen months.
A readiness engagement maps your existing governance against the 42001 controls, names the gaps, and authors the documentation needed to be audit-ready. It is structured the same way our SOC 2 and ISO 27001 work is structured: gap analysis, policy authoring, evidence runbook, audit support.
Half-day session with leadership. Inventory of AI in the environment, top five risks by impact, one-page summary of next moves.
One model or one production use case. End to end. Architecture, data, vendor, policy, incident playbook.
Written AI acceptable use policy, AI use case inventory, model card template, governance charter.
Full Map, Measure, Manage, Govern profile sized to your environment. Risk register, measurement plan, board readout.
Full management system buildout. Gap analysis, policies, evidence runbook, audit-ready documentation, audit support.
Named senior leadership on a retainer. AI committee facilitation, vendor reviews, board reporting, incident standby.
This is not red-team prompt-injection-of-the-week theater, and it is not a research practice. It is governance, risk, and compliance for AI, designed so that when a regulator, an auditor, or an enterprise customer asks how you manage AI risk, you have a written answer with a paper trail behind it.
When the work needs deep ML research expertise (formal model evaluation, mechanistic interpretability, model red-teaming at the weights level), we will tell you, and we will point you to a specialist who does that for a living.
If you use Microsoft Copilot, Google Gemini, ChatGPT Enterprise, Claude, an AI coding assistant, an AI meeting recorder, or any SaaS that ships with AI features bundled in, you have AI risk to govern. Most of what we cover is policy, contract, and process, not model science.
Not directly. We do not run mechanistic interpretability or formal red-teaming on model weights. We govern the program around the model: inputs, outputs, vendors, policies, monitoring, incident playbooks, and the human workflows that surround it.
Significantly. Most of what an AI program needs to add sits on top of an existing information security program. If you already run a mature 27001 ISMS, AI governance is a cost-effective extension. If you do not, we sequence the underlying ISMS work first.
If you offer products or services in the European Union, or if your products are used to evaluate EU residents, the AI Act applies. We work the obligations into the governance program alongside NIST AI RMF and 42001. The EU Act is a regulation, not a framework, so it shapes specific deliverables.
Yes. We run a half-day "AI for security teams" session and a one-day "AI governance for leadership" session. Both are scoped to the audience.
Two questions to think about before the first call. What AI footprints already exist in your environment, and who is being asked about them. Once we have those, the right shape of engagement falls out quickly.
Tell us what AI footprints you already have. We answer the same business day.