AI governance for organizations that actually use AI
AI governance stopped being optional the moment customers started asking about it in security questionnaires and regulators started writing rules. We help you build a program around ISO 42001 and the NIST AI RMF, then map the sector-specific rules that stack on top.
Who this applies to
Any organization that builds AI products, embeds third-party AI into its own product, or uses AI tools internally for work that touches customer data, regulated decisions, or client deliverables. That covers most software companies today, and it increasingly covers professional services firms whose regulators (like bar associations) have started writing AI-specific rules of their own.
The three layers of AI governance
NIST AI RMF
A voluntary US risk-management framework built around four functions: Govern, Map, Measure, and Manage. It's the fastest starting point and the most widely referenced baseline for "what does a reasonable AI program look like."
ISO 42001
The first international standard for a certifiable AI Management System (AIMS). Where the NIST RMF gives you a method, ISO 42001 gives you something an auditor can certify, useful when a customer or partner wants third-party proof.
EU AI Act
Binding EU law with a risk-tiered structure. General-purpose AI obligations have applied since August 2025, and European Commission enforcement of those obligations begins August 2, 2026. It only applies directly if you have EU exposure, but it's increasingly the reference point other regulators copy from.
Most US organizations get the best return starting with the NIST AI RMF for risk management, then layering ISO 42001 if certification matters to a customer or market, then adding EU AI Act controls only if they actually have EU exposure. Build in that order and each layer reuses the work of the one before it.
Sector rules are stacking on top
General frameworks set the floor. Regulators and professional bodies for specific industries are now adding their own AI-specific requirements, and legal practice is one of the clearest examples.
The American Bar Association's Formal Opinion 512 (July 2024) mapped existing Model Rules onto generative AI use, covering competence, confidentiality, communication, candor to the court, reasonable fees, and supervision of AI-assisted work. Since then, over 35 state bar associations have issued their own guidance interpreting those duties in the AI context, and the rules keep moving: New York's court system adopted a system-wide AI disclosure and certification policy for filings effective June 2026, and California's ethics committee has been working through amendments covering agentic AI tools that act on their own.
If your organization serves law firms, or if AI-assisted work product from your own team ends up in a regulated filing or professional deliverable, these sector rules matter as much as the general frameworks. We track them as part of the same governance program rather than as a separate compliance project.
How we help
Snapshot Assessment
An AI system inventory, risk tiering, and gap analysis against the NIST AI RMF or ISO 42001, with a prioritized remediation plan. $9,500, 2 to 3 weeks.
AIMS program build-out
Policy, risk assessment, and control design for an ISO 42001 certification effort, or a lighter NIST RMF-based program if certification isn't the immediate goal.
Vendor & sector review
AI vendor risk questionnaires, model documentation review, and a check against the specific sector rules your customers or regulators care about.
Frequently asked questions
Do we need ISO 42001 certification, or is the NIST framework enough?
If no one is asking you to prove it externally, a documented NIST AI RMF program is usually sufficient. Move to ISO 42001 certification when a customer, partner, or market requires third-party proof, the same way many companies add ISO 27001 alongside SOC 2.
Does the EU AI Act apply to us if we're a US company?
Only if you offer an AI system to people in the EU or your system's output is used there. If you have no EU exposure, it doesn't apply directly, though its risk-tiering approach is worth understanding since other jurisdictions are drawing on it.
We're not a law firm. Why would bar association rules matter to us?
They matter directly if you sell AI tools to law firms or legal departments, since your product becomes part of their compliance obligation. They're also a useful preview: professional bodies in other regulated fields are watching how bar associations handle AI and building similar rules.
How does this connect to our SOC 2 or ISO 27001 work?
AI governance and information security overlap heavily: access control, data handling, and incident response controls you've already built for SOC 2 or ISO 27001 cover a meaningful share of AI governance requirements too. We build on what exists rather than starting a parallel program.
Find out what your AI footprint actually requires
A short conversation covers what AI you're running, who's asking about it, and the right framework to start with.