A working AI governance operating model,
in 90 days.
Hands-on implementation delivered alongside your team to stand up the program properly. We bring the expertise, structure, and momentum; your people contribute the internal context, make decisions, and carry the work into day-to-day operations -resulting in a program tailored to your sector, regulatory exposure, and organizational reality, not a template pack and good intentions.
Priced by scope - a small fraction of large consulting firm fees. Scope and fee are confirmed after a free fit call.
Built for some teams. Not for others.
- Organizations with material AI exposure and real regulatory scrutiny.
- GRC practitioners, Directors, CISOs, CROs, and executive sponsors accountable for AI risk.
- Teams that need to establish a program quickly, with the right architecture in place
- Programs that grow with your organization and stay ahead of emerging regulations
- -You want a self-directed system you run yourself - start with the Premium Toolkit ($497).
- -You are not able to commit executive and working-team time over 90 consecutive days.
- -You are looking for a compliance certification or a legal opinion.
Concrete program artifacts. No vague frameworks.
The Sprint establishes your governance foundation in the first 30 days, then builds, tests, and hands over the operating model across the following 60 days.
Phase 1 - Assess and align (Days 1–30)
Current-state assessment across all 18 governance domains, AI inventory and shadow-AI discovery initiated, regulatory exposure mapping, stakeholder alignment, and a proposed target state for your leadership to validate. This establishes your governance foundation.
Phase 2 - Build the operating model (Days 31–60)
AI Council charter drafted and decision rights defined, core policies and standards tailored to your sector and risk profile, risk register initiated, and vendor and intake process designs prepared for your governance authority to review and approve.
Phase 3 - Enable and hand over (Days 61–90)
Monitoring and reporting model designed, AI incident response plan drafted with a recommended test scenario, board reporting pack prepared, and internal ownership transferred with a Year 1 operating calendar for your team to run and refine.
Founder-led, team-delivered
Dennis Ah-King leads the engagement directly, working throughout with a small senior team of governance, risk, privacy, and security specialists who handle preparation, analysis, artifact tailoring, and quality review between sessions. We accompany, guide, and coach your team; your people make decisions, run tests, and carry the work into day-to-day operations.
AI governance is a continuous enterprise program. After 90 days you get a solid program architecture with key artifacts that your team continues to update and scale. Some artifacts will take more than 90 days to operationalize.
From start to finish.
Fit call
A free conversation to confirm scope, exposure, and whether the Sprint is the right instrument.
Assess and align
Assessment, inventory, regulatory mapping, stakeholder alignment, agreed target state.
Build
Council, policies, risk register, vendor and intake processes, tailored artifacts.
Enable and hand over
Monitoring and reporting model, incident response plan, board pack, internal ownership transfer.
Everything in the box.
- Current-state assessment across all 18 governance components
- AI inventory and shadow-AI discovery
- Regulatory exposure mapping for your sector and jurisdictions
- AI Council stood up with signed charter, RACI, and decision rights
- Core policies and standards tailored, reviewed, and approved
- Populated AI risk register and operating vendor and intake processes
- Monitoring, reporting cadence, and tested incident response
- Board reporting pack and Year 1 operating calendar
- All 39 artifacts included and tailored to your organization during the engagement
- Direct access to Dennis Ah-King (AIGP, CISSP, CDPSE) and the delivery team
- A small senior team supporting analysis, artifact tailoring, and quality review between sessions
- Everything delivered editable - no SaaS lock-in
AISGRC helps you design the operating model, create the key artifacts, and guide adoption. Your organization retains ownership for approvals, testing, and day-to-day operation.
Before you commit.
What is the fit call for?
A short, free conversation to understand your exposure, confirm scope, and decide together whether the Sprint is the right instrument. There is no pitch and no obligation.
How is pricing determined?
Pricing depends on scope, at a small fraction of what large consulting firms charge for comparable work. Final scope depends on organizational size, number of AI systems in scope, regulatory jurisdictions, and the degree of stakeholder facilitation required. The fit call establishes the scope, and the fee is confirmed before any commitment.
How much of our time does this take?
Plan for a few hours per week from the working team, plus scheduled time for executives at each phase gate. The heavy lifting sits with AISGRC.
Is the Premium Toolkit included?
Yes. All 39 artifacts are included and tailored to your organization as part of the engagement.
Do you sign an NDA?
Yes. A mutual NDA can be signed before the fit call, and is standard before kickoff.
Do you guarantee compliance?
No. The Sprint builds a defensible, framework-aligned operating model. It is not legal advice, a certification service, or a guarantee of regulatory compliance.