AI RISK ASSESSMENT | NIST AI RMF & ISO 42001 ALIGNED

AI Risk Assessment:

Find Out What Your Team Is Already Doing With AI

An independent AI risk assessment that tells you where AI is being used in your business, what data is going into it, and which of those uses creates real contract, regulatory or operational exposure. Built on the NIST AI Risk Management Framework and ISO/IEC 42001. Delivered remotely, anywhere in the US.

THE SHADOW AI PROBLEM

Shadow AI: Most Companies Can't Answer Basic Questions About Their Own AI Use

More often than not, AI doesn’t arrive through a leadership decision. It shows up switched on by default inside tools you already license, and/or in free accounts you and your employees signed up for individually. Which is how you end up unable to say where AI is being used in your business, or how far it goes.

WHAT THIS COVERS

What an AI Risk Assessment Actually Covers

The assessment runs in two passes, because there are two different questions to answer and most reviews only answer one.

Pass 1: Your organization
Do you have the governance in place
  • Who owns AI decisions
  • What’s in your inventory
  • How impact gets assessed
  • What data is allowed near which tools
  • Where human review is required
  • What your contracts and disclosures say
  • What happens when something goes wrong.
Are the systems themselves behaving acceptably

Every AI use gets tiered at intake, and the ones that influence a decision about a person or produce output that reaches a customer, a regulator or a court get scored individually on reliability, security, transparency, explainability, privacy and bias.

A company can pass one and fail the other. Strong policies on paper and a system quietly producing output nobody has validated is the most common result I see. Assessing only one half is how that gets missed.

THE FRAMEWORKS

The Frameworks Behind It: NIST AI RMF and ISO/IEC 42001

The assessment is structured on the NIST AI Risk Management Framework, which organizes AI risk into four functions: 

  1. Govern
  2. Map
  3. Measure
  4. Manage. 

Your report is written in that order, so it reads as a risk narrative instead of a checklist.

ISO/IEC 42001, the international standard for AI management systems, provides the coverage map. Its control domains are what confirm nothing got skipped: 

  • Policy
  • Accountability
  • Resources
  • Impact assessment
  • Data handling
  • Transparency
  • Use practices
  • Third-party relationships.
Two things this is not. It’s not certification. Only an accredited certification body can certify an AI management system, and no consultant can issue that certificate. It’s also not an audit. This is an independent assessment against published frameworks, with findings and a roadmap you own.

WHAT YOU RECEIVE

What You Receive: The AI Risk Assessment Report

The deliverable is a written report you can hand to a customer, a carrier, a lender or a board without translating it first.

Executive summary

(Click Here)
One page, your top exposures, in business language.

Governance findings

(Click Here)
Where accountability, inventory, data handling and contract terms stand today.

AI system inventory and tiering

(Click Here)
What you're actually running and which uses carry weight.

Per-system scoring

(Click Here)
Reliability, security, transparency, explainability, privacy and bias, scored and evidenced.

Risk treatment and residual risk acceptance

(Click Here)
What gets fixed, what gets accepted, and who signed off by name.

30, 60 and 180 day roadmap

(Click Here)
Sequenced by exposure, not by score.

Coverage appendix

(Click Here)
The framework crosswalk, including what didn't apply and why.

Questionnaire response pack

(Click Here)
Pre-written answers for the AI section of a customer or carrier questionnaire.

That last one is the piece clients use most. The next time a customer’s security questionnaire asks how you govern AI, you have documented answers instead of a scramble.

WHO THIS IS FOR

Who Needs an AI Risk Assessment

Industry matters less than posture. If one of these describes you, this assessment is built for your situation.

Your team is already using AI, and you don't have a policy.

People are pasting client data, financials and contracts into tools nobody approved. The exposure is live right now, and a policy written without an inventory first will miss most of it.

Client financials, health information, personal data, or anything covered by a confidentiality clause. The obligation follows the data into whatever tool it lands in.

Vendor questionnaires, contract addenda, insurance applications. Once the question is in writing, “we’re not sure” becomes a commercial problem.

Building, fine-tuning or embedding AI in what you sell adds an entire second layer of obligation around lifecycle and training data. The assessment expands to cover it.

INDEPENDENCE BY DESIGN

No Software to Sell You. No Certification to Upsell.

I don’t resell AI tools, I hold no vendor commissions, and I’m not a certification body. There is no product at the end of this assessment that I get paid on. That’s the entire point of hiring an independent advisor instead of asking the vendor selling you the tool whether the tool is safe.

The assessment is also designed to leave your confidential data where it is. I record the state of a control, not its contents. Sensitive documents get reviewed on a screen share and logged as a one-line attestation of what I saw and when. Full data handling and retention terms are published on the Trust Center.

HOW IT WORKS

How the AI Risk Assessment Works

Clarity call, 30 minutes, free.

We establish whether you’re a deployer or a builder, and roughly how many AI uses are in play. That determines scope and price before you commit to anything.

Discovery and interviews.

(Click Here)
Structured sessions covering governance, data, contracts and use practices. Conducted remotely.

System review and scoring.

(Click Here)
Your material AI systems get individually assessed and scored, with evidence recorded.

Report and walkthrough.

(Click Here)
You get the written report plus a live session walking your leadership team through the findings and the roadmap.

COMMON QUESTIONS

AI Risk Assessment: Common Questions

What is an AI risk assessment?

A structured review of where and how your organization uses AI, what could go wrong, and what governance exists to catch it. This one is built on the NIST AI Risk Management Framework with ISO/IEC 42001 as the coverage map, and produces a written report with findings, scored systems and a remediation roadmap.

Those are exactly the cases that create exposure, because they touch your real data and no procurement process reviewed them. Small tool footprint usually means a shorter assessment, not a skippable one.

No. Certification is issued by an accredited certification body after a formal audit, and no consultant can issue it. This is an independent assessment aligned to published frameworks. If you later decide to pursue certification, the report gives you a head start and I can refer you to a certification body.

Write it second. A policy drafted before you know what your team is actually using ends up governing tools you don’t have and missing the ones you do. The assessment gives you the inventory the policy needs.

Most engagements run 3 to 4 weeks from kickoff to report walkthrough, depending on how many AI systems need individual scoring.

Yes. The assessment is delivered remotely and I work with clients nationally.

Pricing is fixed and quoted after the clarity call, because scope depends on whether you deploy AI or build it, and how many systems carry real weight. You get the number before you commit.

GET STARTED

Find Out Where You Stand Before Someone Else Asks

A 30 minute clarity call, no cost and no pitch. We’ll figure out whether an AI risk assessment is the right move for you right now, and if it isn’t, I’ll tell you that.