AI Governance
Your compliance platform does not know you shipped an AI feature
AI Governance
AI governance for regulated organizations — model risk, red teaming, ISO/IEC 42001, NIST AI RMF and EU AI Act readiness, from a HITRUST assessor.
Where the platforms stop
Automation follows standardisation. AI governance has not standardised yet.
Vanta and Drata are good at what they do. They watch your infrastructure, collect evidence against a settled control set, and tell you when something drifts. For SOC 2, that works.
They have nothing to say about the model your team shipped last quarter.
That is not a criticism — it is a sequencing problem. Nobody can build a connector for a control the industry has not agreed on. ISO/IEC 42001 is new. NIST AI RMF is a framework, not a certificate. The EU AI Act is still phasing in, and its timetable changed again in July 2026.
Meanwhile the requirements are already arriving. Recent HITRUST CSF versions tightened AI and ML controls, so every certified organization is now in scope for something it was not assessed on last time. And AI requirements have started appearing in commercial contracts — we have found an AI certification requirement buried in a payer security agreement that our client had not spotted. No platform surfaces that, because it is not a control. It is a clause somebody has to read.
We are the compliance assessors who do the AI work. We will tell you what is actually in scope, what an assessor will accept, and what your platform is not covering.
Your AI is inside your existing certification boundary whether you planned it or not
If a team shipped a feature that touches PHI, it is in HIPAA scope and inside the SOC 2 boundary. The connector did not notice, because it was watching infrastructure rather than product decisions. Nobody filed a change request saying "we added a model."
Nobody can automate a control that has not been standardised yet
ISO/IEC 42001 is new. NIST AI RMF is a framework, not a certification. The EU AI Act is still phasing in, and its timetable moved again in July 2026. Automation follows standardisation — and this has not standardised. That is a sequencing problem, not a failing of anyone's product.
Red-teaming is not a checkbox
Someone has to actually try to break the model: prompt injection, jailbreaks, tool misuse, data exfiltration through the retrieval layer. OWASP now publishes a separate Top 10 for agentic applications precisely because the failure modes are different. That is adversarial work performed by a person, and no integration performs it.
Our parent company is the assessor
Jacobian Engineering is a HITRUST Authorized External Assessor with CCSFP assessors in house. That means we can tell you how an assessor will actually treat your AI controls — not how a vendor hopes they will. In a market where nobody yet agrees what "compliant AI" means, that is the most useful thing anyone can tell you.
What we do
Governance services
Start with the assessment. Everything else follows from what it finds.
AI Governance Readiness Assessment
The starting point. What AI you actually have, what sits inside your certification boundary, what your contracts already commit you to, and a gap list against ISO/IEC 42001 and NIST AI RMF.
AI Red Teaming
Someone has to actually try to break the model. Prompt injection, jailbreaks, tool misuse, and exfiltration through the retrieval layer, tested against the OWASP Top 10 for LLM Applications and the 2026 agentic list.
ISO/IEC 42001
The AI management system standard. Accredited certification became genuinely available in 2026, which changes the buy-versus-wait advice — and makes it worth asking whether you need it at all.
NIST AI RMF
Govern, Map, Measure, Manage. No US state grants a formal safe harbour for adopting it any more, but under an effect-based standard it is the difference between a defensible position and an unexplained outcome.
EU AI Act Readiness
The timetable moved on 27 July 2026. High-risk obligations were deferred to December 2027 and August 2028, while transparency and GPAI enforcement went live. Scoping now is cheaper than scoping later.
Model Governance & Audit Trails
Model registry, versioning, lineage, explainability, bias testing, and the audit trail that turns "we think it works" into evidence someone else can check.
Compliance-First AI
Designing the system to survive the assessment, rather than retrofitting evidence afterwards. HIPAA, SOC 2, PCI-DSS and framework-specific controls, built in from the first commit.
How governance is priced
Fixed fee, agreed up front.
Our agent work is priced against what it returns — you pay from the savings. Governance is not, and we will not pretend otherwise. A readiness assessment does not generate a savings stream to bill against, and inventing one would make the number meaningless.
So governance engagements are fixed fee, scoped and agreed before we start. No surprise fees, no hidden costs, no bait-and-switch. The price you discuss in consultation is the price you pay.
And if the assessment concludes you do not need the framework you came asking about, that is what it will say.
Questions
Frequently asked
Do we need ISO/IEC 42001, or just a policy and a control?
Very often the latter, and we will say so. ISO/IEC 42001 certification is worth pursuing when a customer contract demands it, when you are selling into the EU and want evidence that maps to AI Act conformity, or when AI is central enough to your product that a management system genuinely helps. If you have three AI features and no customer asking, an acceptable-use policy, a documented risk assessment, and an enforced technical control will do more for less. We would rather tell you that than sell you a certification.
Is this competing with our compliance automation platform?
No — and it is not meant to. Vanta and Drata are good at what they do. They watch your infrastructure, collect evidence against a settled control set, and tell you when something drifts. For SOC 2 that works well. They simply do not have a product for AI governance, because the control sets are not settled enough to build a connector against. We cover that ground; we do not cover theirs.
What does a governance readiness assessment actually produce?
A document you can take to your board. It covers what AI you actually have (usually more than the inventory says), what falls inside your certification boundary, what your existing customer contracts already commit you to, a gap list against ISO/IEC 42001 and NIST AI RMF, and a scoping recommendation for red-teaming. It is deliberately small and concrete.
We are HITRUST certified. Does that already cover our AI?
Probably not, and this is worth checking carefully. HITRUST added AI-specific requirements in recent CSF versions, so a certified organization can be in scope for controls it was never assessed against. HITRUST also offers a dedicated AI Security Assessment layered onto an existing e1, i1 or r2. Note that only AI providers — application and platform providers — can obtain that certification; organizations that merely use someone else's AI system cannot certify it.
Has the EU AI Act deadline passed?
Partly, and the part most people were preparing for moved. On 2 August 2026 the Act reached general application: Article 50 transparency obligations apply and the Commission gained enforcement powers over general-purpose AI providers. But Regulation (EU) 2026/1744 — the Digital Omnibus, in force since 27 July 2026 — deferred the high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. If your compliance calendar says high-risk landed in August 2026, it predates the amendment.
Why would we use a consultancy instead of a tool?
For the next few years, because the tooling cannot exist yet. A connector needs a stable control set to check against, and AI governance does not have one. When it does, buy the tool. Until then the work is judgement: deciding what is in scope, what an assessor will accept, and which of your systems is the one that will cause a problem.
Technology Partners
Not sure what is already inside your certification boundary?
A governance readiness assessment tells you what is in scope, what an assessor will accept, and what your platform is not covering.