NIST AI RMF
Internal risk-management methodology
Govern, Map, Measure, Manage — the operating model most US programmes expect.
Capability
Retrieval, agents and evaluation engineered into software people actually operate — with the governance evidence your risk function is going to ask for.
An AI feature is a systems problem wearing a model's clothes. Retrieval quality, latency budget, token economics, what happens when the model is wrong, and an evaluation harness that tells you whether last week's change helped — that is where projects succeed or quietly fail.
Ship AI features your customers trust and your competitors cannot copy in a sprint.
The hard part of an AI feature is rarely the model call. It is retrieval quality, latency budget, token economics, graceful degradation when the model is wrong, and an evaluation harness that tells you whether last week's prompt change made the product better or worse.
Automate the work your staff actually do, without losing the audit trail.
Internal AI fails on sprawl: several RAG stacks, several model providers, overlapping copilots and no shared guardrails. We consolidate onto one governed platform, with identity, permissions and logging inherited from the systems you already run.
Accessible, accountable systems that can pass the assessment they will face.
Public-sector delivery is a control problem before it is a design problem. We design to the impact level a programme is authorised at, produce the evidence continuously rather than at assessment time, and meet Section 508 and WCAG 2.2 AA as a floor rather than a remediation project.
Internal risk-management methodology
Govern, Map, Measure, Manage — the operating model most US programmes expect.
Certifiable AI management system
The auditable management-system standard, the AI analogue of ISO 27001.
Mandatory obligations, full enforcement in 2026
Risk-tiered duties on providers, deployers, importers, distributors and manufacturers whose systems reach the EU.
The first governance model written for agents
Published 22 January 2026 at the World Economic Forum: autonomy-level assessment, human accountability structures, risk-bounding by design.
NIST AI RMF, ISO/IEC 42001 and the EU AI Act contain no reference to "agent" or "agentic". Governance written for static models under-covers systems that act on their own — reading mail, filing contracts, provisioning infrastructure, escalating incidents. Closing that gap is design work, and it is the work we do.
Published in full, because the fastest way to tell a specialist from a generalist is to ask which of these they have actually shipped.
We will come to the first meeting with a point of view, not a capabilities deck.