Services
From "what applies to us?" to a working program.
Four engagements, in the order that makes sense. Implementation stays with you: we build capability, not dependency.
AI Compliance Readiness Assessment
We inventory every AI touchpoint, including the AI inside your vendor SaaS. For each system, we run a trigger analysis against each statute's definitions: which role the law would likely assign you (deployer or, sometimes accidentally, provider), which duties that triggers, and the citations behind both — packaged for review with your counsel. You get a gap assessment and a prioritized remediation roadmap that bolts onto the compliance machinery you already run (SOC 2, HIPAA, ISO 27001, NIST 800-53/171). If you have no program yet, the roadmap stands one up.
90-Day Governance Program Build
The roadmap, executed: governance structure and accountability, the AI policy set, risk process aligned to NIST AI RMF (which doubles as Texas's statutory safe harbor and Colorado defensibility), the per-system artifacts (impact assessments, human-review procedures, consumer notices, vendor diligence), and staff training. Bi-weekly working sessions; your team runs the program on day 91.
Regulatory Watch
AI law kept moving after your program shipped. We track the instruments that bind you (pending AG rules, effective dates, litigation that pauses or revives duties) and send you a delta briefing when something you rely on changes, with exactly which of your controls and artifacts are affected.
All four run on the Applied Oversight obligation registry: a hub-and-spoke crosswalk mapping every legal obligation onto one ISO/IEC 42001 control spine, verified against primary legal texts.