AI Readiness Assessment

Know Exactly Where Your AI Stands

An expert review of the AI you’re running and the AI you’re planning, against the security, privacy, governance, and compliance requirements that apply to you.

  • Every AI system in use, who owns it, and what data it reaches
  • Gaps against ISO/IEC 42001, NIST AI RMF, and the EU AI Act
  • Mapped onto the compliance program you already run






    We reply within one business day, from a person. Nothing you send here goes into a marketing sequence.

    What you get

    Four Deliverables, in Plain Language

    01

    AI Inventory

    Every AI system in use or planned, who owns it, what data it reaches, and whether anyone approved it.

    02

    Risk Snapshot

    Each use case tiered by the risk it actually carries, so controls are proportionate to potential harm.

    03

    Gap Analysis

    Where you stand against the frameworks that apply to you, in the language an auditor will use.

    04

    Prioritized Roadmap

    Quick wins and bigger moves, sequenced, with the effort named, readable by a non-technical director.

    Where you land

    Five Stages, and Most Organizations Are on the First Two

    01 AD-HOC

    In Use, Unmanaged

    People are using AI. Nobody approved it, nobody is tracking it, and nobody could tell you what data it touches.

    02 STRUCTURED PILOTS

    Experiments with Owners

    Named pilots, but no consistent rules across teams and no inventory of what escaped the pilot.

    03 DEFINED

    Written and Known

    Policy, an approved tool list, and an intake path for new tools that people actually use.

    04 MANAGED

    Operating with Evidence

    Controls with owners: terms get re-read, settings get checked, the inventory stays current.

    05 SCALED

    Normal Business

    Governed as part of how the company runs, with reporting a board or auditor accepts without a special project.

    The assessment tells you which stage you are actually at, not which one you would like to be at. Both answers are useful; only one of them is true.

    How it runs

    Typically Two to Three Weeks, Once We Have Your Documentation

    WEEK 1

    Kickoff and Discovery

    A 60-minute session with the people who own AI, security, and compliance. We send a short documentation request the same day.

    WEEK 1–2

    Review and Interviews

    We work through what you sent, interview system owners, and map what is running against what is documented. The gap between the two is usually the finding.

    WEEK 2–3

    Readout

    A working session with your leadership team, the written assessment, and the roadmap. Yours to keep and act on, with us or without us.

    Duration depends on how quickly documentation arrives. That’s the one variable we can’t compress.

    A good fit if
    • You’re in a regulated industry, or your customers behave as though you are
    • AI is already in use somewhere, whether or not it was approved
    • Someone has started asking, a board, an auditor, a carrier, a customer
    • You need a defensible answer in weeks, not quarters
    Not a fit if
    • You want a certificate without changing anything
    • You need a tool license rather than judgment and a plan
    • Nobody internally can give three hours to the process
    Why us

    Fourteen Years of Assessments in Rooms Where the Rules Are Strict

    100%breach-free record across active vCISO and preventative consulting engagements
    1,000+engagements at 99.6% satisfaction since 2012
    Both worldsfluent in AI frameworks and in SOC 2, HITRUST CSF, and HIPAA

    Assessment engagements start in the five figures. We confirm scope and price in writing before you commit to a call.

    Find out Where You Actually Stand