AI governance
AI risk management
Start by finding out how much artificial intelligence your company already runs.
What this work consists of
Almost every company has more artificial intelligence running than it realizes: the tool one department signed up for on its own, the feature that came embedded in a system already under contract, the assistant someone plugged into a process. We map all of it, classify each system by risk, and build the treatment plan, following market references for AI risk.
The inventory comes from conversation, not technical scanning. We cross-reference contracts, access records, and what each team tells us about its own day to day, because that is how unapproved use surfaces. Each system found is placed in the applicable risk tier based on what it actually decides.
For that, we need access to business teams, to whoever procures software, and to the list of systems in use. You receive the full inventory, the classification of each system, and, depending on the option you choose, the risk matrix with the impact on the people affected and the algorithmic impact assessment for the highest-risk systems.
The options change where the work ends up. The inventory alone is the starting snapshot, and it is often the most revealing part. The risk assessment turns the snapshot into a prioritized plan. The full program builds the structure that keeps the inventory from going stale: a usage policy, criteria for approving new systems, training, and a recurring committee.
How we conduct it, stage by stage
The stages and deliverables below describe the Inventory and risk assessment modality. The other modalities appear when you request the proposal.
Interviews
We talk to IT, to security and to the business areas. Documents say what should happen; interviews say what does.
AI system inventory
We map what exists, including what arrived embedded in a system already under contract and what a department signed up for without telling anyone.
Risk classification
We place each system in the applicable tier from what it decides, rather than from what we would like it to be.
Risk assessment
For each system we ask what can go wrong, for whom and how badly, and we record the answer with the criteria in the open. This is where the risk matrix and the treatment order come from.
Gap assessment
We compare what exists today with what the reference requires, item by item, and classify each gap by risk and by effort to fix. The result comes out in order of attack: what to do first and why, instead of an inventory of everything that is wrong.
What is not included
- Technically blocking AI tools in your environment, which is a security operations task
- Technical audits of bias and explainability, which is a separate, deeper service
- Model development or AI vendor selection, decisions that belong to your business
- Executing the treatment plan inside the systems, which stays with each system's owner: we prioritize and follow up, but whoever changes the system is accountable for it
- Full regulatory compliance with the European regulation or the Brazilian bill, which is the regulatory compliance service
- Renegotiating or terminating contracts with AI vendors flagged as risks, which is your call together with procurement and legal
- Licenses for discovery or model monitoring tools, which you pay for
Usually comes together with
Not a bundle, and it changes nothing you have already chosen. It is what tends to come up next, in the experience of companies that have been through this.