
A fixed-scope, fixed-fee, two-week engagement that tells a company exactly where it stands against an AI governance standard — and hands them a prioritized, costed remediation plan they can execute against.
Auditor-grade certainty in two weeks, not a six-month program.
Included
- Kickoff + context intake (60 min) — business model, where AI touches the product, the deadline driving this
- AI system inventory — a complete catalogue of where AI/ML operates across the product and vendors. Most teams cannot produce this, and every framework starts here.
- Control-by-control gap analysis against one chosen framework (see lenses below)
- Risk & impact assessment review — is there a defensible, repeatable process, or a one-off spreadsheet?
- Evidence review — spot-check that priority controls actually operate and produce proof, not just exist on paper
- Prioritized remediation roadmap — findings ranked by risk × effort, sequenced, with rough effort/cost estimates
- Readout call (60 min) walking through the report and the recommended sequence
Explicitly excluded (these are the follow-on engagement)
- Writing policies, procedures, or the Statement of Applicability
- Running the risk or impact assessments on their behalf
- Implementing or remediating any control
- The certification audit or acting as certification body
- Penetration testing or technical security testing of the AI system (separate offer)
- More than one framework lens (multi-framework is a priced add-on)
- Revisions beyond one round of clarifications on the final report
Framework lenses (pick one)
| Lens | Best fit |
| ISO 42001 | Flagship. Teams pursuing certification or building a formal AIMS. Your strongest proof point. |
| EU AI Act | Anyone with EU users or customers; deadline-driven urgency |
| NIST AI RMF | US teams wanting a framework without a certification commitment |
| Colorado AI Act / US state | US SaaS with consumer-facing AI decisions |
Add-on: a second lens or an ISO 42001 ↔ EU AI Act crosswalk, priced at +50% of the base fee. This is a natural upsell for anyone serving both markets.
DISC InfoSec DEURA INFORMATION SECURITY CONSULTING
PAID READINESS ENGAGEMENT
AI Governance
Readiness Assessment
Know exactly where you stand — in two weeks, for a fixed fee.
Your free assessment gave you a directional score. This gives you the auditor’s-eye version: a control-by-control review of your actual AI governance against ISO 42001, the EU AI Act, NIST AI RMF, or US state law — and a prioritized, costed plan to close the gaps.
WHAT YOU GET
| → A complete inventory of where AI operates across your product | → A gap register mapped to every relevant control, with maturity ratings |
| → A remediation roadmap, sequenced by risk and effort, with cost estimates | → A 60-minute readout to walk through it, personally |
FIXED FEE / TWO WEEKS
CREDITED IN FULL TOWARD IMPLEMENTATION
IF YOU PROCEED WITHIN 90 DAYS
Led by DISC InfoSec — CISSP, CISM, ISO 42001 Lead Implementer — who took a financial data room platform through its ISO 42001 Stage 2 certification audit. Financial data rooms are the hard mode of compliance; if it holds up there, it holds up for you.
BOOK A 20-MINUTE SCOPING CALL →
Is it a fit? Built for B2B SaaS and fintech teams with AI in production and a deadline in sight. Not there yet? The free assessment is the better starting
deurainfosec.com | hd@deurainfosec.com
AI Vulnerability Scorecard: Discover Your AI Attack Surface Before Attackers Do
Your Shadow AI Problem Has a Name-And Now It Has a Score
Most AI Security Tools Won’t Pass an Audit. Here’s a 15-Minute Way to Find Out.

InfoSec services | InfoSec books | Follow our blog | DISC llc is listed on The vCISO Directory | ISO 27k Chat bot | Comprehensive vCISO Services | ISMS Services | AIMS Services | Security Risk Assessment Services | Mergers and Acquisition Securit
- GRC Engineering: From Evidence Theater to Genuine Assurance
- AI Risk Management: AIRM isn’t a Security Problem — It’s Bigger
- The adversary that treats your balance sheet as the objective
- Why Supplier Security Is Under the Spotlight — and How to Build a Vendor Management Program for the AI Era
- GDPR Isn’t a Cookie Banner: The Audit Findings That Actually Get Companies Fined
DISC InfoSec blog | DISC InfoSec Site


