Skip to content

AI Governance Readiness Assessment

Know exactly where your AI program stands against NIST AI RMF — in six weeks, at a fixed fee.

Your organization is already using AI. Vendors have embedded it in your tools, teams are experimenting with it, and leadership is being asked to certify that all of it is governed. Meanwhile the compliance floor is rising: NIST AI RMF alignment, Executive Order requirements, GSAR 552.239-7001’s 30-day post-award window, and ISO/IEC 42001. Most organizations cannot answer the first question an auditor, board, or contracting officer will ask: what AI is in use, and who is accountable for it?

A fixed-scope, fixed-fee assessment that produces a defensible answer. Not a slide deck of recommendations — a scored baseline, a gap register, and a costed remediation roadmap your team can execute or hand to any implementer, including us.

What you receive

  • AI System Inventory — every AI use case in scope, cataloged with owner, purpose, data sensitivity, and vendor dependency: the artifact every framework starts with and most organizations lack.
  • Maturity Scorecard — your posture scored against the four NIST AI RMF functions (Govern, Map, Measure, Manage) and mapped to our six-level AI Autonomy Framework (L0–L5), so leadership sees one number per function and what the next level costs.
  • Gap Register — every gap ranked by risk and regulatory exposure, each with a named owner recommendation and remediation effort estimate. Board-ready and auditor-legible.
  • 12-Month Remediation Roadmap — sequenced, costed, and mapped to the frameworks that apply to you.
  • Executive Readout — a 60-minute briefing for leadership with the three decisions that matter most and what each costs to defer.

How it works — six weeks

Weeks Phase What happens
1 Scope & Intake Kickoff, document request, stakeholder list, inventory template issued
2–3 Discover Stakeholder interviews, AI use-case inventory, vendor and data-flow review
4 Assess Scoring against NIST AI RMF functions; evaluation-practice review (bias, accuracy, monitoring)
5 Roadmap Gap register ranked; remediation roadmap sequenced and costed
6 Readout Executive briefing; full deliverable package handed over

Your team’s total time commitment: approximately 12–15 hours of interviews and document access across six weeks. We do the work; you make the decisions.

Investment

  • Standard (up to 15 AI use cases): $45,000 fixed fee.
  • Enterprise (unlimited use cases, multi-division): $85,000 fixed fee.
  • Federal add-on: GSAR 552.239-7001 and EO compliance mapping, ATO-support documentation: +$15,000.

Fees are fixed and quoted before work begins. If we conclude by the end of week one that the assessment cannot produce a defensible baseline for your environment, we say so and you pay nothing.

Why Align Forte

  • Hands-on, not theoretical. We implement the NIST AI RMF end to end for clients — intake gates, risk registers, measured evaluations — and the assessment is built from that delivery playbook, not from a framework poster.
  • Delivery-scale credibility. Led by a practitioner who directed engineering transformation across a 3,000-engineer global organization and holds PMP, CSPO, and doctoral research credentials in AI/ML (DEng ABD, George Washington University).
  • No lock-in by design. Deliverables are written so any qualified team can execute the roadmap; the assessment fee is credited toward any implementation engagement within 90 days.

Questions we hear

What exactly do we get at the end?

Five artifacts: an AI system inventory, a maturity scorecard against the four NIST AI RMF functions, a ranked gap register, a costed 12-month remediation roadmap, and a 60-minute executive readout. Deliverables are written so any qualified team can execute the roadmap - including yours.

How much of our team's time does it take?

Approximately 12 to 15 hours total across six weeks: a kickoff, six to ten stakeholder interviews, document access, and the readout. We do the work; you make the decisions.

Is the fee really fixed?

Yes. $45,000 standard (up to 15 AI use cases), $85,000 enterprise (unlimited, multi-division), and a $15,000 federal add-on for GSAR 552.239-7001 and EO compliance mapping. Quoted before work begins; no change orders unless you change the scope.

What if our environment can't support an assessment?

If we conclude by the end of week one that we cannot produce a defensible baseline - no sponsor access, no document access, active reorganization - we say so and you pay nothing.

Do we have to hire you for the remediation?

No. The deliverables are deliberately written to be executable by any qualified implementer. If you do want us to implement, the assessment fee is credited toward any implementation engagement within 90 days.

Which frameworks does the assessment map to?

NIST AI RMF is the backbone (Govern, Map, Measure, Manage), mapped to ISO/IEC 42001, ISO/IEC 23894, Executive Order requirements, and - for federal engagements - GSAR 552.239-7001.

Ready to see where you stand?

Book a 30-minute scoping call