— AI governance consulting · Data compliance
AI governance consulting that produces evidence, not policy binders.
Our AI governance consulting turns scattered data, models and agents into one governed lakehouse you can defend: an inventory of what exists, lineage for where regulated data goes, access rules for every person and agent, and audit logs an assessor can read. New rules on automated decisions, breach notices and log review all ask for the same evidence. We build it once.
30+ years inside IBM · EY · J&J · McKesson
Lean Six Sigma Master Black Belt
AIMContext from $3,500
60-Day Ship Guarantee
— The pattern · Why governance stalls
The policy exists. The evidence does not.
Data in silos, no inventory.
Customer data sits in the ERP, the CRM, a warehouse and a dozen spreadsheets. When a regulator or customer asks where a person’s data went, nobody can answer inside the deadline.
Symptom: a breach review that starts with a spreadsheet of systems.
Agents with inherited access.
Copilots and AI agents read whatever their user can read. Nobody decided that on purpose, and nobody logs what the agent actually touched.
Symptom: no one can say which files an agent opened last week.
Decisions with no record.
A model scores a loan, a claim or a candidate, but the inputs, the version and the human review are not recorded anywhere a person could retrieve them later.
Symptom: an explanation request nobody can answer.
— The work · What we build
What our AI governance consulting actually delivers.
Data and AI inventory
One catalog of the systems, tables, models and agents in scope, with an owner for each, built in Unity Catalog on your lakehouse.
Lineage for regulated data
Automatic table and column lineage from source to report, so you can show where regulated data came from and where it went.
Access for people and agents
Grants by group, masking and row filters for sensitive columns, and a deliberate decision about what each AI agent is allowed to read.
Decision records
For automated decisions: the inputs, model version, outcome and human review captured as data you can query when someone asks why.
Audit logs and retention
Platform audit logs and security logs landed in one place, retained for as long as each rule requires, and reviewed automatically.
Orchestration with controls
Pipelines and jobs that carry the controls with them, so governance does not break the first time data moves between tools.
— The approach · One layer, many rules
Different regulations. The same five pieces of evidence.
California’s automated decision-making rules, Colorado’s replacement AI law, PCI DSS 4.0.1 log review and the SEC’s Regulation S-P all read differently. Underneath, they keep asking for the same things: know what data you hold, know where it flows, control who and what can read it, record the decisions, and keep the logs.
So we do not build a project per regulation. We build one governed data layer that produces that evidence, then map each rule onto it. Our data compliance deadlines tracker lists the dates that apply.
— The method · AIM-IT
Five phases. Every build, every time.
Assess, Innovate, Model, Implement, Track. Each phase ends with something you can inspect and sign off, not a slide.
01 · ASSESS
Assess
Scope and inventory
Which regulations apply, which systems, models and agents are in scope, and who owns each one.
02 · INNOVATE
Innovate
Control design
The access, lineage, logging and decision-record controls each rule needs, designed once for the whole lakehouse.
03 · MODEL
Model
Prove it on one flow
One regulated data flow governed end to end, with the evidence an assessor would ask for.
04 · IMPLEMENT
Implement
Roll out in your workspace
The remaining flows brought under the same controls, with your engineers pairing on the work.
05 · TRACK
Track
Control plan
What is checked, how often and by whom, so the evidence is still current at the next audit.
— The deliverable · What you get
AI governance consulting with a fixed scope.
AIMContext
Governed data and AI foundation, fixed scope.
Most engagements start with AIMContext, the fixed-scope build of a governed foundation. What the first ninety days look like:
- By day 30: the inventory, the scope of rules that apply, and the control design.
- By day 60: one regulated data flow governed end to end, with lineage, access rules, decision records and audit logs.
- By day 90: the remaining priority flows under the same controls, and a written control plan your team runs.
We build the evidence and the controls. Your counsel and your assessor make the compliance call; we will not tell you a tool makes you compliant.
$3,500+
14 days
5 phases
60 days
60-Day
Ship Guarantee
On every Sprint engagement: if we do not deliver the agreed working artifact in 60 days, you do not pay the final invoice. That is what AIM-IT is for.
— The discipline · Process before tools
Agree the rules first. Then encode them in the lakehouse.
Governance that starts in a tool ends as a list of permissions nobody can explain. We start at the whiteboard with data, security and the business owners in the room, and agree who may see what, which decisions need a human, and what must be kept.
That is Lean Six Sigma discipline applied to data: define the control, measure it, and put a named owner on it. Thirty years of enterprise systems work inside IBM, Ernst & Young, Johnson & Johnson and McKesson says the process is where governance holds or fails.
— Related reading · From the blog
Go deeper on governance and compliance.
Framework
A practical framework you can run on the lakehouse.
Lineage
What auditors ask for and where lineage breaks.
Logs
One table of retention rules, and one design.
California
The data work behind California’s ADMT rules.
Colorado
The decision records SB 26-189 asks for from 2027.
PCI DSS
Automated log review with evidence.
Silos
Why silos make every deadline harder to meet.
Platform
The governance layer this work is built on.
AI
Keeping AI agents inside governed data.
— Straight answers · FAQ
Questions we get asked first.
Are you a Databricks partner or certified?
No, and we will not imply otherwise. Certification is in preparation, and we are not in the Databricks partner programme. What we bring is thirty years of delivering the enterprise systems this data comes out of, inside IBM, Ernst & Young, Johnson & Johnson and McKesson, plus Lean Six Sigma at Master Black Belt level. Ask us for the work, not the badge.
Will this make us compliant?
No tool or consultant can promise that, and you should be wary of anyone who does. We build the evidence and the controls: inventory, lineage, access rules, decision records and logs. Your counsel and your assessor decide whether that meets the rule for your business.
Which regulations do you work with?
The ones that ask data teams for evidence: California’s automated decision-making rules, Colorado’s AI law, PCI DSS 4.0.1 log review, SEC Regulation S-P incident response, and EU AI Act obligations for teams serving EU customers. Our deadlines tracker lists the current dates.
How do you govern AI agents like ChatGPT or Copilot?
Agents read whatever their user can read, so we start with access: which data an agent may reach, through which connector, and what is logged when it does. The safest pattern is to give agents governed data from the lakehouse rather than raw access to every system.
What does AI governance consulting cost?
AIMContext starts at $3,500 for a fixed-scope governed foundation, and a typical first build lands in 14 days. Larger programmes are quoted after the scoping phase, because an honest number needs to see your systems and the rules that apply. Every engagement carries the 60-Day Ship Guarantee.
Start with the evidence, not another policy.
One call, your systems and your deadlines on the table, and a straight read on what evidence you can already produce and what is missing.
