Skip to main content

Governance

Governance, risk, and compliance — especially for AI.

The Freedom Project does GRC. AI systems are treated with the same discipline as the rest of the stack: residual risk owned, controls designed in, evidence an auditor can read.

Governance

Who owns the decision, what the system is allowed to do, and how that is written so a board, AO, or contracting officer can stand behind it. Decision Provenance on AI-assisted recommendations when the record has to travel.

Risk

Residual risk named in language the authorizing official can accept or reject. AI systems get the same treatment as the rest of the stack — threat, likelihood, impact, and what is left after the control.

Compliance

Evidence mapped to the framework the engagement actually uses: NIST RMF, NIST AI RMF, FedRAMP-aware, FISMA, CMMC-aware, HIPAA-aware, FFIEC-aware. Not a generic checklist bolted on after design.

AI

The model is not exempt from the package.

Most AI deployments fail review because governance was a slide and risk was a paragraph. We write the decision record, the control set, and the evidence trail so an authorizing official, a board, or a contracting officer can see what the system is allowed to do — and what it is not.

Where AIM is the instrument, AI-assisted recommendations can carry Decision Provenance (U.S. Provisional App. No. 64/021,096). Consulting is scoped separately.

Pedigree

Both sides of an authorization.

The principal has performed the security-officer function — residual risk, the package, the briefing to the official who has to sign — and the security-engineer function: controls designed into the system, not inspected in after it ships.

That work was done across more than twenty national security systems, in air-gapped and classified environments, against NIST RMF, FedRAMP, FISMA, and zero-trust baselines. We do not list those as current billets. We list them because GRC advice without that seat time is theory.

What an engagement produces

  • A written governance model: roles, decision rights, and what requires human sign-off — including AI outputs.
  • Risk statements an authorizing official can accept or send back, not a heat map with no owner.
  • Control design traced to the framework the program already uses.
  • Evidence and decision records formatted for audit, IG, and board review.

Start with the system that has to survive review.

A 30-minute briefing is enough to see whether GRC, architecture, or a structured AIM assessment is the first move.