AI governance assessment and transformation roadmap
AI is already inside your business. Govern it before it governs you.
Nearly half of employees now use AI on work devices, and two thirds of them do it through personal accounts your security team cannot see. The companies that get the value without the breach do one thing first: they put a framework around AI before they scale it. Our assessment measures where you stand against NIST and ISO, and the roadmap takes you from policy to a private model enclave in twelve defined steps, with your data classified, your people trained and the attackers priced in.
Where are you on the curve?
The AI train left the station. The question is whether your data is on it with no ticket.
Four stages, drawn from the transformations we have assessed. Most businesses are at stage one and believe they are at stage two. Click a stage to see what it looks like, what it exposes, and the next move.
Where most businesses are today
What it looks like
Staff use whatever AI tool answers fastest. Customer records, contracts and source code go into personal accounts. Nobody has written down what is allowed.
What it exposes
Regulated data leaves through browsers you do not manage. A breach here is also a notification event, and the 68% of companies without an AI policy discover that in the incident report.
The next move
An acceptable-use policy this month, a shadow-AI inventory from your firewall and proxy logs, and a short list of approved tools with company accounts.
The transformation roadmap
Twelve steps, three phases, one evidence set.
Policy before tools, data classification before models, testing before customers. Every step maps to a NIST AI RMF function and an ISO/IEC 42001 control, so the work you do for adoption is the same work that proves governance to a customer, an insurer or a regulator.
Phase 1 · Foundational people and process controls
- 01
AI acceptable-use policy
Define acceptable and unacceptable AI use across the company, by data type and role, and put it in front of every employee.
- 02
Governance framework and roles
Assign ownership, decision rights and risk management for AI adoption, mapped to the NIST AI RMF Govern function.
- 03
Data governance and GenAI allow-list
Classify data into regulated, confidential and internal; align the classification with your security stack and approve the tools that may touch each class.
- 04
Security and privacy awareness training
Train the workforce on AI-specific risks: prompt injection, data leakage, deepfake fraud and the rules in step one.
Phase 2 · AI feasibility, data readiness and responsibility
- 05
AI data readiness and cleansing
Scan and categorize data by type, location and sensitivity; recommend and run the cleansing needed before any model sees it.
- 06
Front-office feasibility
Evaluate readiness for customer-facing assistants: chat, voice, messaging and the customer-experience data behind them.
- 07
Back-office feasibility
Define requirements and assess readiness for a private model enclave that automates internal workflows.
- 08
Responsible-impact assessment, before and after
Audit the AI ecosystem for transparency, explainability, compliance, security and privacy, mapped to the NIST Map and Measure functions.
Phase 3 · Build, test, measure
- 09
Private model enclave, build and train
Develop and test private models in a controlled environment, with your data classification enforced at the boundary.
- 10
AI ecosystem security and privacy risk assessment
Assess the models, plugins, agents and vendors in the ecosystem against ISO/IEC 42001 controls and the CIS AI companion guides.
- 11
Chatbot and prompt-engineering penetration test
Simulate attacks on the assistant using MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications, then fix what breaks.
- 12
ROI and cost-benefit analysis
Align AI outcomes with business goals and set the KPIs the management review will track every quarter.
Foundational people and process controls
- AI acceptable-use policy. Define acceptable and unacceptable AI use across the company, by data type and role, and put it in front of every employee.
- Governance framework and roles. Assign ownership, decision rights and risk management for AI adoption, mapped to the NIST AI RMF Govern function.
- Data governance and GenAI allow-list. Classify data into regulated, confidential and internal; align the classification with your security stack and approve the tools that may touch each class.
- Security and privacy awareness training. Train the workforce on AI-specific risks: prompt injection, data leakage, deepfake fraud and the rules in step one.
AI feasibility, data readiness and responsibility
- AI data readiness and cleansing. Scan and categorize data by type, location and sensitivity; recommend and run the cleansing needed before any model sees it.
- Front-office feasibility. Evaluate readiness for customer-facing assistants: chat, voice, messaging and the customer-experience data behind them.
- Back-office feasibility. Define requirements and assess readiness for a private model enclave that automates internal workflows.
- Responsible-impact assessment, before and after. Audit the AI ecosystem for transparency, explainability, compliance, security and privacy, mapped to the NIST Map and Measure functions.
Build, test, measure
- Private model enclave, build and train. Develop and test private models in a controlled environment, with your data classification enforced at the boundary.
- AI ecosystem security and privacy risk assessment. Assess the models, plugins, agents and vendors in the ecosystem against ISO/IEC 42001 controls and the CIS AI companion guides.
- Chatbot and prompt-engineering penetration test. Simulate attacks on the assistant using MITRE ATLAS techniques and the OWASP Top 10 for LLM Applications, then fix what breaks.
- ROI and cost-benefit analysis. Align AI outcomes with business goals and set the KPIs the management review will track every quarter.
The AI threats that hit before you know
Six ways AI becomes the breach, and the control that stops each.
Prompt injection
A customer, a document or a web page tells your assistant to ignore its instructions, and it does. Still the number one risk in the OWASP 2026 list.
The control: Input and output filtering, least-privilege tool access for the model, and a penetration test that tries it before an attacker does.
Data leaving through personal accounts
Source code is the top data type leaked to AI tools, and shadow AI is now the third most common insider action in DLP data, four times last year.
The control: A GenAI allow-list enforced at the proxy, company accounts for approved tools, and DLP that watches the browser, not only email.
Excessive agency
An agent with a mailbox, a payment API and a vague instruction is an insider with no judgment. OWASP moved this to number three for 2026.
The control: Scoped credentials per agent, human approval for money and access changes, and audit logs you actually read.
AI-assisted phishing and deepfake fraud
Phishing accounts for 44% of AI-assisted initial access in the 2026 DBIR; cloned voices now approve wire transfers.
The control: Phishing-resistant MFA, callback rules for any payment change, and training that uses the real lures.
Poisoned models, plugins and packages
Model weights, prompt libraries and agent plugins are software you did not write. This year’s npm and Rust incidents showed how fast trust can be rented.
The control: A bill of materials for AI components, signature checks, and the same vendor review your other software gets.
No policy, no owner, no evidence
68% of breached organizations had no AI policy and 92% of those with AI-related breaches lacked adequate AI access controls.
The control: Steps one to four of the roadmap. They cost the least and remove the most.
Sources: OWASP Top 10 for LLM Applications 2026; Verizon 2026 DBIR; IBM Cost of a Data Breach 2026; Cyberhaven and Netskope 2026 reports. Figures verified 2 September 2026.
What the assessment measures against
NIST for the structure, ISO for the controls, OWASP and MITRE for the test.
NIST AI Risk Management Framework 1.0
The spine of the assessment: Govern, Map, Measure, Manage. Each of our scoring areas maps to one function.
NIST, January 2023; the Generative AI Profile (NIST AI 600-1, July 2024) adds the GenAI-specific risks.
ISO/IEC 42001:2023
The management-system standard for AI. We use its Annex A controls as the control catalogue so the roadmap can lead to certification if a customer or regulator asks.
Certifiable; adopted in Europe as EN ISO/IEC 42001:2026.
OWASP Top 10 for LLM Applications, 2026
The test plan for anything that takes a prompt. Prompt injection remains number one; excessive agency is now number three.
OWASP GenAI Security Project, 4 August 2026; the Agentic Applications Top 10 (December 2025) covers agents.
MITRE ATLAS
The adversary playbook for AI systems, in the same shape as ATT&CK. Our penetration test in step eleven is built from it.
Data release v5.4.0, February 2026, with agentic techniques added.
CIS Controls v8.1.2 with the AI companion guides
The security baseline the AI program sits on: asset and software inventory, data protection, access control, logging.
CIS AI and LLM Companion Guide; AI Agents Companion Guide, April 2026.
NIST Cybersecurity Framework Profile for AI (IR 8596)
How AI risk folds into the security program you already run: secure AI components, defend with AI, thwart AI-enabled attacks.
Preliminary draft, December 2025; we track it and do not present it as final.
The UAE and the frameworks regulators reference
The Emirates set the direction early. The sector rules are now arriving.
Dates verified 2 September 2026 against the primary instruments. Guidance is described as published; we do not speculate about enforcement.
Three ways to start
Assess, roadmap, or test what you already built.
Fixed fee, scoped in 15 minutes
AI Governance Framework Assessment
Companies at stage one or two that need to know where they stand before the next tool gets approved.
- Scored assessment against NIST AI RMF and ISO/IEC 42001 Annex A
- Shadow-AI inventory from 30, 60 or 90 days of your firewall and proxy logs
- Data-classification readiness and the GenAI allow-list
- Policy pack: acceptable use, governance roles, training outline
- Gap register and a 90-day plan
Fixed fee, scoped in 15 minutes
AI Transformation Roadmap
Companies ready to move from policy to production without losing control of their data.
- Everything in the assessment
- Front-office and back-office feasibility, data readiness and responsible-impact assessment
- The twelve-step roadmap with owners, dates and KPIs
- Vendor and model review for the tools you have chosen
- Quarterly management review for the first year
Fixed fee, scoped in 15 minutes
AI Security Testing and Private Enclave Readiness
Companies deploying assistants, agents or a private model that must not become the next breach.
- Chatbot and prompt-engineering penetration test (OWASP 2026, MITRE ATLAS)
- AI ecosystem security and privacy risk assessment
- Private model enclave architecture review with our enclave partner
- Continuous monitoring of AI components inside your existing program
The 3-minute AI readiness check
Six questions. Your stage on the curve, and the first thing to fix.
1. Do you have a written AI acceptable-use policy that employees have been trained on?
2. Do you know which AI tools your staff actually use, including personal accounts?
3. Is your data classified (regulated, confidential, internal) with rules for what may go into AI tools?
4. Does someone own AI risk, with decision rights and a review cadence?
5. Have your AI assistants or agents been tested for prompt injection and data disclosure?
6. Can you show a customer or regulator evidence of your AI controls today?
Answer all six to see your stage immediately; the stage report and the call come next. 0 of 6 answered.
Questions owners ask
AI policy, shadow AI and the frameworks, without the jargon.
Does my business need an AI policy?
What is shadow AI, and why is it a risk?
Is AI use a risk under the PDPL or the health data law?
What is the NIST AI RMF?
What is ISO 42001?
What should an AI acceptable-use policy include?
Will you tell us to stop using AI?
Talk about your AI transformation before it is too late.
Thirty minutes with an engineer who has assessed AI programs inside banks and hospitals. Bring the tools your staff already use; leave with your stage, your first three steps and a fixed-fee scope. Delivered from Dubai, with the read-only compliance agent keeping the picture continuous afterward.