AI Governance Assessment

Turn the AI you already rely on into the AI you can defend.

Your team already uses AI to draft, analyze, and decide. When that output is challenged, you won’t be asked why the model failed — you’ll be asked who checked it before it left the building. This assessment builds the record you can’t show today.

Fixed scope  ·  Fixed date  ·  No code  ·  Confidential

The evidence gap

The problem isn’t the model. It’s the missing record.

Somewhere in your company, AI output already carries weight. A filed document. A claim decision. A financial analysis. A hiring shortlist. When it’s right, no one asks about the AI. When it’s wrong — and it will be, because models are probabilistic, not certain — the first question is never “why did the model fail.”

“Who checked it before it went out?” That’s the question. And most companies can’t answer it, because the checking was never written down. That is the gap — not a technology gap, a record gap.

It’s already happening

The record is where these cases are lost.

In 2025, a federal court in Oregon sanctioned two lawyers for over $109,000 over fifteen AI-generated case citations that never existed. The claims were dismissed. It is the largest AI-hallucination penalty on record in the United States. The cost wasn’t really the money. It was the record — the firm couldn’t show who had verified those citations before they were filed.

The bar is moving toward the record, not just the policy. In California, two laws signed in September 2026 (SB 813 and AB 1405) create the first AI-auditor registry in the country and, from January 2029, require registration to conduct a covered AI audit. The question is shifting from “should we govern our AI?” to “can we produce the record when it’s asked for?”

This is why it’s an assessment, deliberately — not an audit. You build the record a future audit will demand, without taking on the audit’s definition, registration, or liability today.

What the assessment delivers

Five documents. Eight to ten pages. No code.

Not a binder that goes in a drawer. A record your team can actually run — written for a board to read without translation.

01
The Decision Map

Every place AI output carries weight, and exactly where it leaves the building.

You can’t verify what you can’t see.

02
The Verification Rule

Who must check each output, and how, before it’s released — a named person and a criterion, not “the team” and a mood.

Checking has to be assignable, or it doesn’t happen.

03
The Control-Point Specification

The exact moment a person stops the workflow and confirms the output, and the evidence that checkpoint requires.

A control only works if it has a named owner and a stop.

04
The Record Schema

What gets written down when it fails, in a format you can actually produce if it’s asked for.

The record has to be producible, not just intended.

05
The Quarterly Audit Checklist

How the record stays alive after the engagement, on a cadence your team can run without us.

Governance decays within a quarter without a rhythm.

Who does this work

Two people. You’ll know who does what from the first call.

This is a joint practice, and the division of work is part of the offer: the consulting is hers, the build is his. We tell you on the first call which of the two you actually need — and you’re never sold a build you didn’t ask for.

Dr. Cristina Imre
Forensic Architect for the Intelligence Age

Founder and former CEO of Aecho, an AI voice-technology company. Twenty-six years of global leadership across five continents. Strategic advisor on AI governance and EU AI Act alignment. Author of the Mirror Test Framework™ and People Debt™. She runs the discovery and the interviews, classifies the risk, and writes the five documents.

Adrian Baderca
Technical Partner

If you want phase two, he is the one who builds it: the shadow-AI inventory, the audit trail itself, human-signature and model-version capture, evidence storage that holds up, and integration into your stack. The technical half of the record, engineered.

“You cannot govern what you cannot see.” That is the standard this work is built against.

Who this is for

Built for companies where AI output already carries weight.

For
  • Legal, insurance, financial services, and health — anywhere AI reaches a filed document, a claim, an analysis, or a decision.
  • The regulated mid-market firm that needs a named owner for AI risk without hiring a full-time governance lead.
  • Any company whose clients, insurers, or partners have started asking for an AI policy — and the honest answer is “we’re working on it.”
Not for
  • This is the assessment, not the build. If you want the controls engineered into your systems, that’s phase two with our technical partner — a separate scope you choose, not an upsell.

How it works

Four to six weeks. You build nothing.

1
A free 20-minute discovery.

We map where you use AI and where that output carries weight. You keep the map either way.

2
We work from your answers and your existing documents.

No consultants in your building, no code, no platform to buy.

3
You receive the five documents.

Plus a working session to put them in front of the people who’ll actually run them.

Fixed scope. Fixed date. A clear end.

The investment

Fixed price. Fixed scope. No retainer, no hourly.

AI Governance Assessment
$15,000 flat · 4–6 weeks

The five documents (8–10 pages), no code. A record you can put in front of a board.

Framework + Implementation
$45,000 – $80,000 · separate phase

The controls engineered into your systems by our technical partner — only if you want it.

Discovery
Free · 20 minutes

You keep the map of where your AI carries weight, even if we never continue.

The market band for this scope runs $15,000 to $50,000. This is priced at the floor for the first firm in each vertical — and it’s fixed, so the price you see is the price you pay.

The commitment

Fixed scope, fixed price, fixed date. If the five documents don’t give you a record you can put in front of a board, we’re not done. And the twenty minutes is free — you keep the map even if we never continue.

Questions, answered

What people ask before they reach out.

No. The assessment provides the governance design and the record. Your counsel owns the legal opinion; this gives them the record to work from.
Deliberately not. From 1 January 2029, California requires registration to conduct a covered AI audit (SB 813, AB 1405). We don’t claim the protected title. We build the record a future audit will ask for.
The assessment is led by Dr. Cristina Imre — founder and former CEO of Aecho, an AI voice-technology company, with twenty-six years of global leadership and current advisory work in AI governance and EU AI Act alignment. If you later want the controls engineered into your systems, that build is done by our technical partner, Adrian Baderca, in a separate phase you choose.
The market band for this scope is $15,000 to $50,000. It’s priced at the floor for the first firm in each vertical — and it’s fixed, not hourly, not a retainer, not a build you have to manage.
A policy says what should happen. The record shows what did happen. When it’s challenged, you’re asked for the second.
Eight in ten employees already use AI without approval, at every company size. Smaller isn’t safer — it’s just less visible.
Twenty minutes and one honest answer: the last time an AI output was wrong and had already reached a customer — what actually happened?

Start with the 20 minutes.

No deck. No proposal to read. Twenty minutes, and you’ll know whether this is the right fit — and where your record is thin.

Fields marked * are required. We only use your details to reply — never to add you to a list.

Scroll to Top
Dr. Cristina Imre

Founder and former CEO of Aecho, an AI voice-technology company. Twenty-six years of global leadership across five continents. Strategic advisor on AI governance and EU AI Act alignment. Author of the Mirror Test Framework™ and People Debt™.

Adrian Baderca

Technical partner. Builds the audit trail in phase two: the shadow-AI inventory, human-signature and model-version capture, evidence storage, and integration into your stack.