Resources: Practical guides to AI governance, AI compliance, and AI audit, written for CISOs, compliance leads, engineering leaders, and audit firms.
Guides
EU AI Act Compliance: How to Assess Your AI SystemsA practical approach to EU AI Act compliance: inventory your AI systems, classify their risk, map obligations, and keep evidence current.NIST AI RMF and ISO 42001: Covering Both With One AssessmentHow the NIST AI Risk Management Framework and ISO/IEC 42001 relate, and how a unified control set lets one assessment satisfy both.Automated AI System Discovery: Building an Accurate AI System InventoryWhy an AI system inventory is the foundation of AI governance, and how automated discovery keeps it accurate as systems change.What Is an AI CI/CD Governance Gate?An AI CI/CD governance gate checks every pull request for governance risk and blocks changes that fail the bar, the way a test suite blocks broken code.What Is an AI Determination Record?An AI determination record is the tamper-evident, evidence-backed document that shows what an AI system is, what governance applies, and whether it is met.How AI Is Changing Audit and AttestationHow AI audit tools automate evidence analysis, control mapping, and reporting while auditors keep professional judgment and the final opinion.OWASP Top 10 for LLM Applications: What to AssessHow to turn the OWASP Top 10 for LLM Applications into concrete checks on your AI systems, from prompt injection to excessive agency.
Practitioner guides from Assessed Intelligence
Field guides from Assessed Intelligence Advisory. Each defines a specific exposure, specifies what a defensible response requires, and closes with an assessment instrument you can apply the same week.
Compliance Guide: Third-Party RiskVendor AI RiskHow to evaluate the AI your vendors embed in products you already use, what to require contractually, and a twelve-question vendor AI assessment.Get the guideCompliance Guide: AI GovernanceAI Governance ReadinessWhat the EU AI Act, NIST AI RMF, ISO/IEC 42001, and U.S. state law require, four failure patterns to avoid, and a twelve-question readiness self-assessment.Get the guideAdvisory Guide: Security LeadershipThe First 90 Days with a vCISOWhat the virtual CISO role is and is not, the three-phase ninety-day arc with named deliverables, and a nine-question fit assessment.Get the guideCompliance Guide: AI GovernanceAgentic AI ControlsThe control set agentic deployments require, from per-agent identity through interruption and rollback, with a ten-item pre-deployment checklist.Get the guide
