Governance Guides
Practical, framework-grounded guides to the governance work buyers, boards, and auditors actually ask about — written to be useful before any tooling enters the picture.
AI Risk Management Program Guide
A practical guide to standing up an AI risk management program: what it covers, how it maps to the NIST AI Risk Management Framework, and the working artifacts — the AI risk register, fairness testing records, and human oversight design — that auditors and boards ask to see first.
EU AI Act Readiness Guide
A working guide to preparing for the EU AI Act: who it reaches, how its risk tiers work, what high-risk obligations actually require in artifacts, and a readiness sequence that starts where every assessment starts — with the AI model inventory.
Agentic Readiness Assessment Guide
What agentic readiness means, why AI agents change the governance picture faster than any prior AI adoption wave, and the dimensions an agentic readiness assessment examines before an organization lets autonomous systems act on its behalf.
Control Mapping, Policy Exception Management, and Segregation of Duties Guide
A practical guide to three governance disciplines that determine whether a control program can be trusted at its edges: control mapping (how one control framework's requirements translate to another's), policy exception management (what happens when a control cannot be met), and segregation of duties (how incompatible responsibilities are kept apart). Each produces artifacts an auditor asks for by name.
Vendor Risk and Digital Operational Resilience (DORA) Readiness Guide
A practical guide to third-party risk management in the era of the Digital Operational Resilience Act (DORA): what the regulation requires of financial entities, what those entities now ask of every technology vendor they rely on, and how a vendor risk program produces the artifacts both sides need.
ISO 27001, ISO 42001, and SOC 2 Readiness Guide
A practical guide to the three assurance frameworks buyers most commonly raise with technology vendors — ISO 27001 for information security management, ISO 42001 for AI management, and SOC 2 for service-organization controls — what each actually attests, how the three differ as instruments, and what "ready" looks like for an organization that holds none of them yet.
GDPR Data Protection and Data Retention Governance Guide
A practical guide to data retention under the GDPR: what the regulation actually requires (and the fixed retention periods it deliberately does not set), how to build a retention schedule that survives scrutiny, and where retention connects to records of processing, erasure, impact assessments, and AI training data.
Incident Response, Model Risk, and Governance Maturity Levels Guide
A practical guide to three disciplines that decide whether an AI governance program holds up under stress: incident response (what happens when something breaks), model risk management (how model failures are anticipated and bounded), and maturity levels (how honestly the organization locates itself and chooses its next step).