NEW

Start with the pressure: sales, launch, abuse, agents, data, or guardrails

Governance program

AI Governance & Program Build Packet

An AI security operating model with ownership, controls, evidence, and a roadmap.

The first deliverable is a decision package: what is in scope, what is required, what is blocked, and what can proceed.

No production testing, adversarial activity, access to secrets, or customer-data processing happens without explicit authorization and the right agreement path. Do not enter secrets or credentials here.

What to gather for this packet

Needed: Current policies/controls · AI system landscape · Ownership/org context · Target frameworks

Helpful: Prior audits · Vendor register · Tooling inventory

Bring names and high-level descriptions only — exact targets, accounts, and credentials are shared later through a secure channel.

Engagement

Readiness inputs

Deliverables you want

Packet modules

  • Scope BriefWhat is in scope, what decision is being made, and what success looks like.
  • Evidence Handling PlanWhere evidence is stored, redaction, retention, and deletion.
  • Contract RequirementsThe required and conditional agreements for this engagement.
  • Draft SOW InputsScope, window, deliverables, and acceptance inputs for the SOW.
  • Open QuestionsWhat is still required before a scoping call or private offer.
  • Follow-On RecommendationsNatural next services once this engagement completes.
  • Deliverables PlanThe artifacts the buyer will receive and in what format.

AI Governance & Program Build Packet — preview

Governance program

Scope Brief

  • Organization: To be specified during scoping
  • Decision: An AI security operating model with ownership, controls, evidence, and a roadmap.
  • Driver: AI security is scattered policy with no operating model, ownership, controls, evidence, or cadence.

Evidence Handling Plan

  • Evidence stored in an access-controlled encrypted store; redaction; agreed retention + deletion.

Contract Requirements

  • Mutual NDA — Required for this engagement.
  • Evidence Handling Policy — Required for this engagement.
  • Statement of Work Template — Required for this engagement.
  • No-Cost Scoping Retainer (conditional) — Scope before any paid work or active testing.

Draft SOW Inputs

  • Engagement: AI Governance & Program Build Packet
  • Deliverables: 8 selected
  • Budget category: Security program / governance / GRC

Open Questions

  • None — ready for a scoping call.

Follow-On Recommendations

  • secure ai sdlc
  • ai security sales evidence
  • ai product security assessment

Deliverables Plan

  • AI System Inventory
  • Ownership Map
  • Risk Tiering Model
  • Policy Gap Review
  • SDLC Integration Plan
  • Evidence Requirements
  • Model / Vendor Register
  • Roadmap and Operating Model

Onboarding

Move four tracks in parallel

We put legal, finance, procurement, and technical scoping on parallel rails so the work can start without waiting on every internal process sequentially.

Technical Scoping

Output: Draft Launch Review Plan

  • architecture
  • demo/staging
  • prompts
  • RAG
  • agents/tools
  • authz
  • logs/evals
  • test boundaries

Legal

Output: NDA + Scoping Authorization

  • mutual NDA
  • data handling
  • authorized testing boundaries
  • confidentiality
  • work-product terms

Finance / Procurement

Output: Procurement Packet

  • vendor profile
  • tax/payment details
  • budget category
  • fixed-fee quote path
  • invoice terms
  • onboarding answers

Internal Approval

Output: Approval Memo

  • why now
  • business pressure
  • risk if delayed
  • expected deliverables
  • timeline
  • decision needed

Output

Your output: a clear, measurable prescription.

SCOPE delivers a one-page engagement plan you can share and act on immediately.

  • Situation & core problem
  • Desired outcome & success criteria
  • Key risks & assumptions
  • Recommended path(s)
  • Effort, timing & impact
  • Open questions & next step

SCOPE Prescription

Situation

Criteria

Recommended path

Next step

Export as markdown ↗