Skip to content
Ramanova Labs

Services

Governance Assessment

A fixed-scope engagement that ends with a complete AI inventory, a controls baseline, and a prioritized remediation plan.

At a glance

Who it's for
Firms facing audit or regulatory questions about AI, or finding AI in tools nobody approved.
Typical sponsor
CIO, Chief Risk Officer, CISO, Chief Compliance Officer, or head of internal audit.
Format
Fixed scope and deliverables, agreed in writing.
You end with
A complete AI inventory, a controls baseline, and a remediation plan with owners.

Why it matters

AI now arrives inside SaaS products, copilots, and vendor platforms, not only in projects you commission. Most firms cannot say where AI is in use, what data it touches, or who approved it. That is the first thing an auditor or regulator will ask. You cannot govern what you cannot see.

Signs you need this

  • An audit, regulator, or board has asked for an AI inventory, and producing one is hard.
  • Teams use generative AI tools that were never reviewed.
  • Vendors are switching on AI features inside products you already license.

What you get

  • AI inventory: Every AI system in use, including AI inside SaaS and vendor platforms, with owner, data touched, and risk tier.
  • Risk triage: Each system rated, with the highest-risk items flagged for immediate action.
  • Controls baseline: The minimum controls to operate: model and vendor due diligence, risk-tiered approval, validation standards, monitoring, and documentation.
  • Framework gap analysis: Where you stand against the NIST AI RMF and the EU AI Act.
  • Remediation plan: What to fix first, who owns it, and what done looks like.
  • An approval path for new AI work: Lightweight and risk-tiered, so governance does not stall delivery.

Example format. Not client data.

Sample AI inventory fields

System nameVendor or internalBusiness ownerData it touchesCustomer-facing?Risk tierApproved byLast reviewed

How it runs

  1. 01DiscoverInterviews, tool and contract review, and a sweep for AI inside existing software.
  2. 02TriageRate each system by risk and flag urgent items.
  3. 03BaselineDefine the controls your firm should operate, matched to risk.
  4. 04PlanAgree remediation priorities, owners, and the approval path for new work.

What we need from you

  • A sponsor from risk, compliance, or technology.
  • Access to software inventories, vendor contracts, and procurement records.
  • A contact in each business unit.
  • Your security and privacy leads.

The method behind it

Ramanova Governance Baseline

The controls regulated firms need before scaling AI: model due diligence, AI inventory, and risk review.

The Baseline defines the minimum controls to have in place before AI use grows beyond a few pilots. It is built so you can show auditors and regulators how AI is controlled, without slowing every project, by matching the depth of review to the risk of each use case.

What it covers

  • An inventory of AI in use, including AI inside SaaS tools
  • Due diligence for foundation models and AI vendors
  • Risk-tiered review and approval
  • Validation standards: grounding, evaluation sets, and model-as-judge review
  • Monitoring, documentation, and audit readiness
  • Alignment to the NIST AI RMF and the EU AI Act

Illustrative scenario

Illustrative scenario. Not a client case study.

Regional bank with shadow AI

Business units adopted GenAI tools on their own, and audit flagged it.

Approach: A rapid AI inventory and risk triage, a governance baseline, then a CoE charter that turns shadow usage into a governed intake pipeline.

  1. A 15-minute call
  2. A scoping session
  3. A fixed-scope proposal