
Phase 1: Capability and Risk Audit (Weeks 1-2)
We assess where AI is actually being used before any policy is written.
Formal tools, informal tools, tools staff are using without anyone knowing. We map the risk exposure for each. We identify the regulatory obligations that apply. We do not write policy for a landscape we have not mapped.
Deliverables:
- AI use inventory across the organization
- Risk classification by tool and use case
- Regulatory obligation map
- Governance gap analysis






