AI Use
Tools, models, applications, APIs, and agents in use across the organization.
AI Governance & Security Assessment
Establish what AI is in use, what information it touches, who owns it, where material gaps exist, and what leadership should address first.
What we evaluate
Tools, models, applications, APIs, and agents in use across the organization.
The company, customer, regulated, and sensitive information processed by AI systems.
Systems, permissions, integrations, identities, and actions available to AI applications.
Who approves, owns, reviews, documents, and oversees AI use.
Third parties, embedded capabilities, and upstream dependencies that introduce AI risk.
Architecture, application, data, model, and control gaps that affect the environment.
How employees use public and internal AI tools in day-to-day work.
Whether the organization can identify, escalate, and respond to an AI-related incident.
Assessment process
Align on scope and establish a baseline of known AI use, policies, vendors, and evidence.
Understand adoption, ownership, workflows, concerns, and control practices across functions.
Examine relevant systems, data flows, access paths, vendor relationships, and governance processes.
Evaluate material exposure, control maturity, and priorities in business context.
Deliver findings, a prioritized remediation plan, and an executive working session.
Deliverables are tailored to scope and maturity, with clear distinctions between observations, risk judgments, and recommendations.