Services / 02 — Assure: AI Compliance
You have AI. We prove it's compliant.
AI is shipping faster than your controls can track it. We map your process model, scan it against the actual code, and deliver an exposure report — every HIPAA, SOC 2, and NIST AI RMF finding cited to the line of code that caused it. Evidence, not opinions.
At a glance
- Frameworks
- HIPAA · SOC 2 · NIST AI RMF
- Deliverable
- Exposure report
- Every finding
- Cited to code
- Engagement
- Fixed scope
How it works
Model. Scan. Report.
01 — Model
Map what should happen
We capture your processes and controls as a formal model — using your existing ARIS assets if you have them, building the model if you don't. This is the compliance baseline everything gets measured against.
02 — Scan
Check what actually happens
Our tooling traces the model against your actual codebase — including the AI your teams shipped last quarter — and finds where implementation drifted from the controls on paper.
03 — Report
Get findings you can act on
An exposure report where every finding cites the process step, the control, and the line of code — plus a prioritized remediation plan. Defensible to your auditor, actionable for your engineers.
What you walk away with
Evidence your auditor can follow
Exposure report
Where you're exposed, how badly, and what it takes to close each gap.
Traceability matrix
Process step → control → code, linked end to end. The artifact auditors ask for and rarely get.
Remediation roadmap
Prioritized by risk and effort — your engineers can start Monday.
Audit-ready evidence pack
Organized against HIPAA, SOC 2, or NIST AI RMF so the next audit is a review, not an excavation.
This is for you if
- Teams across your org are shipping AI features and nobody can say, with evidence, whether they're compliant.
- An audit, ATO, or customer security review is on the calendar and the documentation isn't.
- You need findings your engineers respect — cited to code, not generic policy checklists.
It's not if
- You want a rubber stamp. If the code doesn't hold up, the report says so.
- You need a certified audit opinion — we produce the evidence; your auditor issues the opinion.
Straight answers
Questions we always get
Which frameworks do you cover?
HIPAA, SOC 2, and NIST AI RMF are our core; we also work against FedRAMP-aligned controls and agency-specific requirements for government clients. If your framework is control-based, the model-to-code approach applies.
How long does an assessment take?
A scoped assessment of a single product or process area typically runs 3-6 weeks from kickoff to exposure report. Enterprise-wide baselines take longer and are phased so you see findings from the first weeks, not at the end.
Do you need access to our source code?
Yes — that is what makes the findings defensible. We work within your security requirements: read-only access, your environment, your controls. Nothing leaves your perimeter without your say-so.
Will this disrupt our engineering teams?
Minimally. The scan is tooling-driven, not interview-driven. We need a few hours from a process owner and an engineering lead, not weeks of workshops.
Do you fix the findings too, or just report them?
Both are on the table. The report comes with a prioritized remediation roadmap; if you want the same senior team to close the gaps, that is a follow-on engagement — your engineers can also run the roadmap themselves.
Is this an audit?
No — we produce the evidence and traceability that make your audit fast and defensible. The certified opinion comes from your auditor; ours is the package that keeps that engagement short.
“A strategic framework that maximized value, streamlined operations, and enriched decision-making. Crucial to our future readiness.”
Know your exposurebefore the auditor does.
Thirty minutes with the people who run the scan. Bring your worst-case scenario — we've probably seen worse.