AI Governance Assessment
Turn the AI you already rely on into the AI you can defend.
Your team already uses AI to draft, analyze, and decide. When that output is challenged, you won’t be asked why the model failed — you’ll be asked who checked it before it left the building. This assessment builds the record you can’t show today.
Fixed scope · Fixed date · No code · Confidential
The evidence gap
The problem isn’t the model. It’s the missing record.
Somewhere in your company, AI output already carries weight. A filed document. A claim decision. A financial analysis. A hiring shortlist. When it’s right, no one asks about the AI. When it’s wrong — and it will be, because models are probabilistic, not certain — the first question is never “why did the model fail.”
“Who checked it before it went out?” That’s the question. And most companies can’t answer it, because the checking was never written down. That is the gap — not a technology gap, a record gap.
It’s already happening
The record is where these cases are lost.
In 2025, a federal court in Oregon sanctioned two lawyers for over $109,000 over fifteen AI-generated case citations that never existed. The claims were dismissed. It is the largest AI-hallucination penalty on record in the United States. The cost wasn’t really the money. It was the record — the firm couldn’t show who had verified those citations before they were filed.
The bar is moving toward the record, not just the policy. In California, two laws signed in September 2026 (SB 813 and AB 1405) create the first AI-auditor registry in the country and, from January 2029, require registration to conduct a covered AI audit. The question is shifting from “should we govern our AI?” to “can we produce the record when it’s asked for?”
This is why it’s an assessment, deliberately — not an audit. You build the record a future audit will demand, without taking on the audit’s definition, registration, or liability today.
What the assessment delivers
Five documents. Eight to ten pages. No code.
Not a binder that goes in a drawer. A record your team can actually run — written for a board to read without translation.
Every place AI output carries weight, and exactly where it leaves the building.
You can’t verify what you can’t see.
Who must check each output, and how, before it’s released — a named person and a criterion, not “the team” and a mood.
Checking has to be assignable, or it doesn’t happen.
The exact moment a person stops the workflow and confirms the output, and the evidence that checkpoint requires.
A control only works if it has a named owner and a stop.
What gets written down when it fails, in a format you can actually produce if it’s asked for.
The record has to be producible, not just intended.
How the record stays alive after the engagement, on a cadence your team can run without us.
Governance decays within a quarter without a rhythm.
Who does this work
Two people. You’ll know who does what from the first call.
This is a joint practice, and the division of work is part of the offer: the consulting is hers, the build is his. We tell you on the first call which of the two you actually need — and you’re never sold a build you didn’t ask for.
Founder and former CEO of Aecho, an AI voice-technology company. Twenty-six years of global leadership across five continents. Strategic advisor on AI governance and EU AI Act alignment. Author of the Mirror Test Framework™ and People Debt™. She runs the discovery and the interviews, classifies the risk, and writes the five documents.
If you want phase two, he is the one who builds it: the shadow-AI inventory, the audit trail itself, human-signature and model-version capture, evidence storage that holds up, and integration into your stack. The technical half of the record, engineered.
“You cannot govern what you cannot see.” That is the standard this work is built against.
Who this is for
Built for companies where AI output already carries weight.
- Legal, insurance, financial services, and health — anywhere AI reaches a filed document, a claim, an analysis, or a decision.
- The regulated mid-market firm that needs a named owner for AI risk without hiring a full-time governance lead.
- Any company whose clients, insurers, or partners have started asking for an AI policy — and the honest answer is “we’re working on it.”
- This is the assessment, not the build. If you want the controls engineered into your systems, that’s phase two with our technical partner — a separate scope you choose, not an upsell.
How it works
Four to six weeks. You build nothing.
We map where you use AI and where that output carries weight. You keep the map either way.
No consultants in your building, no code, no platform to buy.
Plus a working session to put them in front of the people who’ll actually run them.
Fixed scope. Fixed date. A clear end.
The investment
Fixed price. Fixed scope. No retainer, no hourly.
The five documents (8–10 pages), no code. A record you can put in front of a board.
The controls engineered into your systems by our technical partner — only if you want it.
You keep the map of where your AI carries weight, even if we never continue.
The market band for this scope runs $15,000 to $50,000. This is priced at the floor for the first firm in each vertical — and it’s fixed, so the price you see is the price you pay.
The commitment
Fixed scope, fixed price, fixed date. If the five documents don’t give you a record you can put in front of a board, we’re not done. And the twenty minutes is free — you keep the map even if we never continue.
Questions, answered
What people ask before they reach out.
Start with the 20 minutes.
No deck. No proposal to read. Twenty minutes, and you’ll know whether this is the right fit — and where your record is thin.
