AI Governance
Know exactly where your AI stands.
Your AI use, measured against the rules that matter: the EU AI Act, ISO/IEC 42001, NIST AI RMF, and Canada’s Quebec Law 25, PIPEDA, and AIDA. You get a prioritized gap report and a risk register you can act on. Fixed scope, delivered in 5 business days.
Frameworks covered
- EU AI Act
- ISO/IEC 42001
- NIST AI RMF
- Quebec Law 25 + PIPEDA + AIDA
5 business days, start to readout
Async intake, a scoping call, and a senior-led gap analysis mapped to your actual AI systems.
Fig. A · Assessment spec
Built for founders who can’t answer with a shrug.
Founders and technical leaders at seed to Series B companies who are adopting AI and now face a customer security review, an investor question, or a regulator asking how it’s governed.
We run this the same way we run everything else at SECURIQUE: as your fractional CISO would, not as a consultant selling you a follow-on project.
What you get.
Five deliverables, built around your actual AI footprint, not a generic checklist.
- A short async intake questionnaire plus one 45 to 60 minute scoping call.
- A gap analysis mapped to the AI systems you run and the ones you plan to ship.
- A prioritized risk register you can hand to your team.
- An executive summary and a 0-30, 30-90, 90+ day remediation roadmap.
- A 60 minute readout call to walk the findings and the plan.
How the assessment runs.
Three steps from intake to readout.
-
01IntakeA short async intake questionnaire, plus a 45 to 60 minute scoping call to understand your stack and your AI systems.
-
02Gap analysisA gap analysis mapped to your actual systems against the EU AI Act, ISO/IEC 42001, NIST AI RMF, Quebec Law 25, PIPEDA, and AIDA.
-
03Report and readoutA gap report, a prioritized risk register, and a 60 minute readout call, in 5 business days.
Fixed scope. Clear deliverables.
One assessment to start, one subscription to keep the picture current.
For teams who need a clear, senior read on where they stand before the next audit, review, or investor question.
A one-time engagement. If you move to a SECURIQUE retainer within 30 days, the full assessment fee is credited to your first month.
- Intake questionnaire and scoping call
- Gap analysis mapped to your AI systems
- Prioritized risk register
- Executive summary and remediation roadmap
- 60 minute readout call
For teams who want the picture kept current after the assessment.
A monthly or annual subscription. Your AI footprint and the rules both move; this keeps the picture true.
- Quarterly re-assessment
- Reg-change monitoring against the crosswalk
- Updated risk register
Not sure which one fits? Book a scoping call and we’ll work it out together.
What this is not.
Straight talk on the scope, before you book.
Not a compliance binder, and not legal advice. A short, direct read on where you stand and what to do first, from someone who has sat in the room when the questions get asked.
Book a scoping call.
A short call with the founder to confirm fit and scope before you start the assessment.