Skip to main content
TrustEdge AI

AI Governance

Find out what you actually have before anyone sells you a framework

What AI you actually have, what sits inside your certification boundary, what your contracts commit you to, and where the real gaps are.

Most AI governance engagements start in the wrong place — with a framework someone decided to adopt, rather than with an inventory of what is already running.

That gets the sequence backwards. You cannot scope a control set against systems nobody has listed, and in our experience the list is always longer than the one procurement holds. AI arrives through purchasing, not engineering: a feature toggled on in a tool you already licensed, a vendor's model quietly added to a product you resell.

The readiness assessment is deliberately small. It produces a document you can take to a board, and it is designed to open into work you may or may not need — including the conclusion that you need less than you thought.

What it covers

Five questions, answered with evidence

Two to three weeks for most mid-market organizations, depending on how much AI turns out to be running.

What AI do you actually have?

A real inventory, including the systems nobody classified as AI when they bought them — applicant tracking screeners, scheduling optimizers, transcription and summarization, vendor features enabled by default. This is usually the part that surprises people.

What sits inside your certification boundary?

If a team shipped something touching PHI, it is in HIPAA scope and inside your SOC 2 boundary whether or not it appeared in your last assessment. Recent HITRUST CSF versions tightened AI and ML requirements, so certified organizations can be in scope for controls they were never assessed against.

What have your contracts already committed you to?

AI requirements have started appearing in commercial agreements. We have found an AI certification requirement buried in a payer's security agreement that the client had not spotted. No platform surfaces that, because it is not a control — it is a clause somebody has to read.

Where are the gaps against ISO/IEC 42001 and NIST AI RMF?

A gap list, not a maturity score. Written so you can tell which items are genuine exposure and which are documentation debt, because conflating those two is how governance budgets get wasted.

What should be red-teamed, and in what order?

A scoping recommendation rather than a sales pitch. Some systems warrant adversarial testing; most do not yet. Knowing which is which is most of the value.

Questions

Frequently asked

What does it cost?

We will give you a fixed price in consultation, scoped to your environment, before any work begins. We are not publishing a number on this page yet, and we would rather leave it blank than post a figure we might have to renegotiate — the site's promise is that the price you discuss in consultation is the price you pay. For context, our parent company's entry engagements typically run in the low five figures.

What if the answer is that we do not need much?

Then that is what the report says, and it is a legitimate outcome. Erik once declined a $60,000 HITRUST engagement with the words \"I'm not in the business of selling anything I don't think you need and frankly, I don't think you need HITRUST right now.\" The assessment is worth buying precisely because it can conclude that.

Who needs to be involved on our side?

Less time than you would expect. Whoever owns compliance, whoever owns IT procurement, and about an hour each from the teams actually using AI. The procurement conversation is usually the highest-yield hour, because that is where the undocumented deployments surface.

Is this just a sales process for a bigger engagement?

It opens into other work when the findings warrant it, and we will not pretend otherwise. But the deliverable stands alone: an inventory, a boundary analysis, a contract review and a gap list are useful whether or not you engage anyone to close the gaps — including if you take the document to a different firm.

Want to know where you actually stand?

We will tell you what is in scope, what an assessor will accept, and what you do not need.