AI RISK ASSESSMENT | NIST AI RMF & ISO 42001 ALIGNED
AI Risk Assessment:
Find Out What Your Team Is Already Doing With AI
An independent AI risk assessment that tells you where AI is being used in your business, what data is going into it, and which of those uses creates real contract, regulatory or operational exposure. Built on the NIST AI Risk Management Framework and ISO/IEC 42001. Delivered remotely, anywhere in the US.
THE SHADOW AI PROBLEM
Shadow AI: Most Companies Can't Answer Basic Questions About Their Own AI Use
More often than not, AI doesn’t arrive through a leadership decision. It shows up switched on by default inside tools you already license, and/or in free accounts you and your employees signed up for individually. Which is how you end up unable to say where AI is being used in your business, or how far it goes.
WHAT THIS COVERS
What an AI Risk Assessment Actually Covers
The assessment runs in two passes, because there are two different questions to answer and most reviews only answer one.
Pass 1: Your organization
Do you have the governance in place
- Who owns AI decisions
- What’s in your inventory
- How impact gets assessed
- What data is allowed near which tools
- Where human review is required
- What your contracts and disclosures say
- What happens when something goes wrong.
Pass 2: Your AI systems
Are the systems themselves behaving acceptably
Every AI use gets tiered at intake, and the ones that influence a decision about a person or produce output that reaches a customer, a regulator or a court get scored individually on reliability, security, transparency, explainability, privacy and bias.
A company can pass one and fail the other. Strong policies on paper and a system quietly producing output nobody has validated is the most common result I see. Assessing only one half is how that gets missed.
THE FRAMEWORKS
The Frameworks Behind It: NIST AI RMF and ISO/IEC 42001
The assessment is structured on the NIST AI Risk Management Framework, which organizes AI risk into four functions:
- Govern
- Map
- Measure
- Manage.
Your report is written in that order, so it reads as a risk narrative instead of a checklist.
ISO/IEC 42001, the international standard for AI management systems, provides the coverage map. Its control domains are what confirm nothing got skipped:
- Policy
- Accountability
- Resources
- Impact assessment
- Data handling
- Transparency
- Use practices
- Third-party relationships.
WHAT YOU RECEIVE
What You Receive: The AI Risk Assessment Report
The deliverable is a written report you can hand to a customer, a carrier, a lender or a board without translating it first.
Executive summary
Governance findings
AI system inventory and tiering
Per-system scoring
Risk treatment and residual risk acceptance
30, 60 and 180 day roadmap
Coverage appendix
Questionnaire response pack
That last one is the piece clients use most. The next time a customer’s security questionnaire asks how you govern AI, you have documented answers instead of a scramble.
WHO THIS IS FOR
Who Needs an AI Risk Assessment
Industry matters less than posture. If one of these describes you, this assessment is built for your situation.
Your team is already using AI, and you don't have a policy.
People are pasting client data, financials and contracts into tools nobody approved. The exposure is live right now, and a policy written without an inventory first will miss most of it.
You handle data that carries obligations.
Client financials, health information, personal data, or anything covered by a confidentiality clause. The obligation follows the data into whatever tool it lands in.
A customer or partner has started asking.
Vendor questionnaires, contract addenda, insurance applications. Once the question is in writing, “we’re not sure” becomes a commercial problem.
You're putting AI into your own product or service.
Building, fine-tuning or embedding AI in what you sell adds an entire second layer of obligation around lifecycle and training data. The assessment expands to cover it.
INDEPENDENCE BY DESIGN
No Software to Sell You. No Certification to Upsell.
I don’t resell AI tools, I hold no vendor commissions, and I’m not a certification body. There is no product at the end of this assessment that I get paid on. That’s the entire point of hiring an independent advisor instead of asking the vendor selling you the tool whether the tool is safe.
The assessment is also designed to leave your confidential data where it is. I record the state of a control, not its contents. Sensitive documents get reviewed on a screen share and logged as a one-line attestation of what I saw and when. Full data handling and retention terms are published on the Trust Center.
HOW IT WORKS
How the AI Risk Assessment Works
Clarity call, 30 minutes, free.
We establish whether you’re a deployer or a builder, and roughly how many AI uses are in play. That determines scope and price before you commit to anything.
Discovery and interviews.
System review and scoring.
Report and walkthrough.
COMMON QUESTIONS
AI Risk Assessment: Common Questions
What is an AI risk assessment?
A structured review of where and how your organization uses AI, what could go wrong, and what governance exists to catch it. This one is built on the NIST AI Risk Management Framework with ISO/IEC 42001 as the coverage map, and produces a written report with findings, scored systems and a remediation roadmap.
Do we need this if we only use ChatGPT and Copilot?
Those are exactly the cases that create exposure, because they touch your real data and no procurement process reviewed them. Small tool footprint usually means a shorter assessment, not a skippable one.
Is this the same as ISO 42001 certification?
No. Certification is issued by an accredited certification body after a formal audit, and no consultant can issue it. This is an independent assessment aligned to published frameworks. If you later decide to pursue certification, the report gives you a head start and I can refer you to a certification body.
We don't have an AI policy yet. Should we write one first?
Write it second. A policy drafted before you know what your team is actually using ends up governing tools you don’t have and missing the ones you do. The assessment gives you the inventory the policy needs.
How long does it take?
Most engagements run 3 to 4 weeks from kickoff to report walkthrough, depending on how many AI systems need individual scoring.
Do you work with companies outside Oregon?
Yes. The assessment is delivered remotely and I work with clients nationally.
What does it cost?
Pricing is fixed and quoted after the clarity call, because scope depends on whether you deploy AI or build it, and how many systems carry real weight. You get the number before you commit.
GET STARTED
Find Out Where You Stand Before Someone Else Asks
A 30 minute clarity call, no cost and no pitch. We’ll figure out whether an AI risk assessment is the right move for you right now, and if it isn’t, I’ll tell you that.