Skip to main content
TrustEdge AI

AI Governance

Your compliance platform does not know you shipped an AI feature

AI Governance

AI governance for regulated organizations — model risk, red teaming, ISO/IEC 42001, NIST AI RMF and EU AI Act readiness, from a HITRUST assessor.

Where the platforms stop

Automation follows standardisation. AI governance has not standardised yet.

Vanta and Drata are good at what they do. They watch your infrastructure, collect evidence against a settled control set, and tell you when something drifts. For SOC 2, that works.

They have nothing to say about the model your team shipped last quarter.

That is not a criticism — it is a sequencing problem. Nobody can build a connector for a control the industry has not agreed on. ISO/IEC 42001 is new. NIST AI RMF is a framework, not a certificate. The EU AI Act is still phasing in, and its timetable changed again in July 2026.

Meanwhile the requirements are already arriving. Recent HITRUST CSF versions tightened AI and ML controls, so every certified organization is now in scope for something it was not assessed on last time. And AI requirements have started appearing in commercial contracts — we have found an AI certification requirement buried in a payer security agreement that our client had not spotted. No platform surfaces that, because it is not a control. It is a clause somebody has to read.

We are the compliance assessors who do the AI work. We will tell you what is actually in scope, what an assessor will accept, and what your platform is not covering.

Your AI is inside your existing certification boundary whether you planned it or not

If a team shipped a feature that touches PHI, it is in HIPAA scope and inside the SOC 2 boundary. The connector did not notice, because it was watching infrastructure rather than product decisions. Nobody filed a change request saying "we added a model."

Nobody can automate a control that has not been standardised yet

ISO/IEC 42001 is new. NIST AI RMF is a framework, not a certification. The EU AI Act is still phasing in, and its timetable moved again in July 2026. Automation follows standardisation — and this has not standardised. That is a sequencing problem, not a failing of anyone's product.

Red-teaming is not a checkbox

Someone has to actually try to break the model: prompt injection, jailbreaks, tool misuse, data exfiltration through the retrieval layer. OWASP now publishes a separate Top 10 for agentic applications precisely because the failure modes are different. That is adversarial work performed by a person, and no integration performs it.

Our parent company is the assessor

Jacobian Engineering is a HITRUST Authorized External Assessor with CCSFP assessors in house. That means we can tell you how an assessor will actually treat your AI controls — not how a vendor hopes they will. In a market where nobody yet agrees what "compliant AI" means, that is the most useful thing anyone can tell you.

What we do

Governance services

Start with the assessment. Everything else follows from what it finds.

How governance is priced

Fixed fee, agreed up front.

Our agent work is priced against what it returns — you pay from the savings. Governance is not, and we will not pretend otherwise. A readiness assessment does not generate a savings stream to bill against, and inventing one would make the number meaningless.

So governance engagements are fixed fee, scoped and agreed before we start. No surprise fees, no hidden costs, no bait-and-switch. The price you discuss in consultation is the price you pay.

And if the assessment concludes you do not need the framework you came asking about, that is what it will say.

How outcome-based pricing works for agent builds →

Questions

Frequently asked

Do we need ISO/IEC 42001, or just a policy and a control?

Very often the latter, and we will say so. ISO/IEC 42001 certification is worth pursuing when a customer contract demands it, when you are selling into the EU and want evidence that maps to AI Act conformity, or when AI is central enough to your product that a management system genuinely helps. If you have three AI features and no customer asking, an acceptable-use policy, a documented risk assessment, and an enforced technical control will do more for less. We would rather tell you that than sell you a certification.

Is this competing with our compliance automation platform?

No — and it is not meant to. Vanta and Drata are good at what they do. They watch your infrastructure, collect evidence against a settled control set, and tell you when something drifts. For SOC 2 that works well. They simply do not have a product for AI governance, because the control sets are not settled enough to build a connector against. We cover that ground; we do not cover theirs.

What does a governance readiness assessment actually produce?

A document you can take to your board. It covers what AI you actually have (usually more than the inventory says), what falls inside your certification boundary, what your existing customer contracts already commit you to, a gap list against ISO/IEC 42001 and NIST AI RMF, and a scoping recommendation for red-teaming. It is deliberately small and concrete.

We are HITRUST certified. Does that already cover our AI?

Probably not, and this is worth checking carefully. HITRUST added AI-specific requirements in recent CSF versions, so a certified organization can be in scope for controls it was never assessed against. HITRUST also offers a dedicated AI Security Assessment layered onto an existing e1, i1 or r2. Note that only AI providers — application and platform providers — can obtain that certification; organizations that merely use someone else's AI system cannot certify it.

Has the EU AI Act deadline passed?

Partly, and the part most people were preparing for moved. On 2 August 2026 the Act reached general application: Article 50 transparency obligations apply and the Commission gained enforcement powers over general-purpose AI providers. But Regulation (EU) 2026/1744 — the Digital Omnibus, in force since 27 July 2026 — deferred the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. If your compliance calendar says high-risk landed in August 2026, it predates the amendment.

Why would we use a consultancy instead of a tool?

For the next few years, because the tooling cannot exist yet. A connector needs a stable control set to check against, and AI governance does not have one. When it does, buy the tool. Until then the work is judgement: deciding what is in scope, what an assessor will accept, and which of your systems is the one that will cause a problem.

Not sure what is already inside your certification boundary?

A governance readiness assessment tells you what is in scope, what an assessor will accept, and what your platform is not covering.