AI Tech Magic
Back home

AI Compliance Readiness

$5,0007 business days

A written readiness assessment of your AI agent against the framework your buyers, board, or examiners will actually ask about — EU AI Act, NIST AI RMF, SR-11-7, or Gartner TRiSM — plus the 90-day remediation roadmap.

You send us your repo, prompts, model cards, and any existing governance docs. In seven days we map your agent against the framework you are being held to, hand back a gap analysis in the format your buyers or examiners accept, and sequence the fixes by exam or audit exposure. Written to be forwardable to a model risk committee, an examiner, or a Series B investor's diligence lead without additional translation.

What you get

Artifacts your team will use.

  1. Framework selection call

    60 minutes on which of EU AI Act, NIST AI RMF, SR-11-7, or Gartner TRiSM actually applies to you — usually one or two, not all four. We name the one your buyers, board, or regulator will read the assessment against, and we scope to that.

  2. Risk classification against the chosen framework

    For the AI Act: whether your system is Annex III standalone high-risk (creditworthiness, insurance risk assessment, worker management, essential services access, and the other named categories), Annex I embedded high-risk, limited-risk under Article 50, or out-of-scope. Equivalent classification for NIST AI RMF, SR-11-7, or TRiSM depending on the framework selected.

  3. Gap analysis across five dimensions

    Governance (who approves what, and against what standard), documentation (model cards, system specs, data-lineage), testing (evals, bias testing, adversarial evaluation), monitoring (drift, calibration, incident logging), and human oversight (refusal paths, escalation, override rights). Each dimension gets a written finding with evidence and priority.

  4. Model card and system spec drafts

    Drafted in the format your buyers or examiners will accept: EU AI Act Article 11 technical documentation for high-risk systems, NIST AI RMF Profile, SR-11-7 model documentation, or TRiSM governance record. Enough of a starting point that your team is filling in, not designing from scratch.

  5. 90-day remediation roadmap

    Every gap scored on effort and audit or exam exposure, sequenced so the highest-exposure items land first. Written so a compliance officer, a general counsel, and an engineering lead can all work from the same document.

  6. 30-minute walkthrough call

    Findings presented live, questions answered, priorities negotiated. Recording provided so your compliance, legal, and engineering leads can watch on their own time.

  7. Two weeks of async follow-up

    Shared Slack channel for two weeks after handoff. Use it for framework questions, clarifications on findings, or sanity checks as your team starts implementing.

Frameworks we map to

Concrete, technical, in-scope.

  • EU AI Act
  • NIST AI RMF
  • SR-11-7 (model risk)
  • Gartner TRiSM
  • NAIC Model Bulletin (on request, insurance-specific)

Sample deliverable

Sample structure of the readiness assessment

Every assessment opens with a one-page executive summary a general counsel can forward, and closes with a roadmap engineering can start on Monday. Section names below are illustrative.

  1. 01Executive summary (1 page, forwardable to a board or an examiner)
  2. 02System description and framework selection rationale
  3. 03Risk classification finding (e.g. AI Act Annex III determination)
  4. 04Gap analysis — governance
  5. 05Gap analysis — documentation (with model card and spec drafts attached)
  6. 06Gap analysis — testing, evals, and adversarial evaluation
  7. 07Gap analysis — monitoring and incident logging
  8. 08Gap analysis — human oversight and refusal paths
  9. 0990-day remediation roadmap, sequenced by exam or audit exposure

Timeline

What happens when.

  1. Day 1 (Mon)
    Framework selection and kickoff

    60-min framework selection call, access handoff for repo, prompts, model cards, and any existing governance docs. Shared Slack channel opens. Scope confirmed against the selected framework.

  2. Days 2-4 (Tue-Thu)
    Risk classification and gap analysis

    Async work through the system, prompts, and documentation. Risk classification drafted first. Gap analysis across governance, documentation, testing, monitoring, and human oversight follows.

  3. Day 5 (Fri)
    Model card and spec drafts

    First-draft model card and system spec in the format the framework accepts. Sent to your team for a temperature check on tone and factual accuracy.

  4. Days 6-7 (Mon-Tue)
    Roadmap and walkthrough

    90-day remediation roadmap drafted and sequenced. Final assessment delivered as a PDF by end of Day 7, followed by the 30-min walkthrough call. Recording and Slack follow-up window start immediately after.

Not in scope

What this isn't.

Setting expectations up front so you can send us away quickly if it's the wrong fit.

  • We are not your law firm. This is a compliance readiness assessment against published frameworks, not a legal opinion. General counsel review is on you.
  • We don't implement the fixes. The roadmap tells your team what to do; this tier is diagnosis and documentation, not remediation. If you want the fixes built, the Sprint or the Retainer is the next step.
  • We don't do certification, audit, or notified-body sign-off. We prepare you for those; we are not the ones granting them.
  • We don't cover more than one framework per assessment. Multiple frameworks means sequenced assessments or a Retainer.

Questions

Specific to this engagement.

How do you pick which framework to assess against?

By what your buyers, board, or examiner is actually asking about. Fintech shipping into US banks: SR-11-7 first, NIST AI RMF second. Insurance underwriting agent: NIST AI RMF plus the NAIC Model Bulletin. EU-market medical-device software: EU AI Act plus the notified-body expectations. If none of them clearly apply, TRiSM is the safe governance vocabulary. The framework selection call settles this in the first hour.

We already have a SOC 2. Isn't that enough?

No. SOC 2 tells you the operational controls are in place; it does not tell you whether the model behind the AI agent is validated, whether its risk classification is correct, or whether the decisions it makes are documented in the way an AI-specific regulator will accept. This assessment is AI-specific and complements, but does not replace, SOC 2.

What if the AI Act doesn't apply to us yet because we're not in the EU?

Two answers. First, the AI Act applies to any AI system placed on the EU market or whose output is used in the EU, not only to EU-headquartered providers — many US teams discover late that they are in scope. Second, US regulators (FTC, CFPB, state insurance departments, OCC) are increasingly using AI Act-style categories in their own guidance, so the classification work is not wasted even where the Act itself does not bind.

Can this be used as evidence in an exam or an audit?

Yes, as internal work product that documents your framework mapping, risk classification, and remediation plan. It is not a certification and it does not substitute for the framework's own audit or conformity assessment. It is the document you would produce in advance so the audit or exam does not surface findings you could have addressed cheaper before the fact.

What happens after the two-week follow-up window?

If you want the gaps fixed, the Sprint is the natural next step: the assessment names the artifacts that are missing (specs, evals, guardrails, observability) and the Sprint builds them. If the exposure is ongoing or you want the framework mapping re-run as scope changes, the Retainer covers that. If you're set, we're set. No pressure.

Something else? info@aitechmagic.com

Turn 'how do you govern this?' into a document you can forward.

20 minutes on a call tells you if a readiness assessment is the right fit, and which framework to run it against.

Book your Pilot Fit Call

20 minutes · No slide deck · No pressure