AI governance
We find where AI runs in your business, including models your vendors ship inside their products. Each system gets an owner, a risk assessment, and a place in the policy set. You leave with the records an ISO/IEC 42001 auditor asks for and a list of what is still missing.
Engagement brief
Fixed scope
AccountableYour named owner
ResponsibleA Truvara practitioner
Drafts and citesCASK
Phases
We confirm scope and timing after a first call.
When teams call us
A customer contract now asks how you govern AI
Teams adopted AI tools faster than anyone wrote them down
Leadership put ISO/IEC 42001 certification on the roadmap
You sell into the EU and need to know where the AI Act touches you
What you receive
Drag the divider. On the left, where the work usually starts. On the right, the files you receive.
What you receive
The files from this engagement
Gap assessment
Implementation
Before the engagement
What we usually find on day one
The findings still need a complete inventory, named owners, and supporting records.
What it works against
CASK maps every requirement to evidence in the workspace, so scoping starts from what already exists and what is missing.
Key areas covered
How it runs
One sequence, from the records you already have to the outcome in your hands.
Find the AI in use
Interviews product, engineering, and procurement leads to list every AI system, including features inside vendor tools.
Assess risk and impact
Runs a risk workshop with each system owner and sets the ratings with them.
Write the policy set
Decides which Annex A controls apply and edits the policy to fit how your teams ship.
Check readiness
Walks the evidence against each clause and presents the findings to leadership.
What we need from you
Questions