A structured assessment against ISO 42001 and NIST AI RMF, delivered through our platform in 3–4 weeks. Not a PDF. An actionable baseline your compliance officer or GC can sign without going through IT procurement.
What you get
93 controls across 10 Annex A domains. Every control mapped, scored, and documented.
Full function mapping—Govern, Map, Measure, Manage—with gap identification.
Colorado AI Act, EU AI Act, HIPAA—mapped to your specific exposure.
Prioritized remediation roadmap with effort estimates and risk ratings.
Results live in the GLACIS platform. Filter, export, share. Not a static PDF.
Structured data that integrates with your existing governance tools.
Who this is for
Organizations figuring out their AI governance posture—and needing a structured starting point.
Compliance officers preparing for regulatory deadlines with limited internal AI expertise.
AI governance committees needing a defensible baseline to present to leadership and the board.
Health systems evaluating AI vendor compliance and managing third-party model risk.
Engagement details
Typical engagement, scoped to your AI footprint and regulatory exposure.
From kickoff to delivered results in the GLACIS platform.
Can be structured as initial assessment plus annual platform subscription.
Regulatory exposure
These are not future risks. They are current liabilities accumulating daily.
Common questions
More from GLACIS
Compliance Platform
The compliance platform purpose-built for AI systems. ISO 42001 mapping, automated evidence, standards-based export.
Request a demoZero-Egress Deployment
Zero-egress proxy with built-in controls and audit-ready evidence generation. No BAA required.
Talk to us