Discover
Identify use cases, systems, vendors, data flows, and owners.
MAISSP framework
Discover, Classify, Assess, Control, Monitor, and Improve connects AI decisions to an ongoing enterprise operating process.
Lifecycle
Identify use cases, systems, vendors, data flows, and owners.
Group AI by purpose, impact, data sensitivity, autonomy, and exposure.
Evaluate material risk, control maturity, and decision context.
Select proportionate governance, security, and operational safeguards.
Track change, performance, incidents, exceptions, and control operation.
Use evidence and lessons learned to strengthen the program.
The same technical capability can carry very different risk depending on purpose, affected people, data, access, autonomy, exposure, and reversibility. The lifecycle preserves that context before selecting controls.
Useful governance produces traceable ownership, review records, decisions, exceptions, actions, and learning—not documentation for its own sake.
Our methodology is informed by the NIST AI Risk Management Framework, NIST AI 600-1 Generative AI Profile, relevant OWASP guidance for generative AI and LLM applications, and management-system principles found in ISO/IEC 42001.
MAISSP is independent. These references do not imply certification, formal conformance, endorsement, partnership, or affiliation. Applicability depends on organizational context, sector, jurisdiction, and risk posture.
Start with clarity
Start with a clear view of current use, ownership, exposure, and priorities.