Two days on one product — then you decide which of the three rungs you need. Assess first, then implement.
Most advisors hand you a policy document nobody can act on. Most technical people can act but don't speak compliance. I do both.
Most AI governance stops at what people report — and people report what they remember. After eight years building software in regulated environments, I know where AI quietly accumulates, and what questions actually surface it.
AI Inventory & Data-Flow Governance
Engineering depth, not a policy PDF: I find the systems nobody declared, govern what data reaches them, and build the evidence chain you can put in front of an auditor. I assess it, then I implement it.
Eight-plus years building production software, much of it in regulated environments — insurance, finance, enterprise — where reliability and traceability were never optional. The last years went into applied AI: LLMs in production, and the governance that lets you prove what data reaches them.
The person who assesses it is the person who builds it — nobody should buy an implementation before the gaps have names.
Three doors: the offer in detail, the decisions behind it, and the field guides in preparation.
Start with two days on one product or one department: what AI is in use, what data it reaches, and what you'd need to put in front of an auditor. Then decide whether the full readiness assessment is worth it. Or just send a note.