AI Governance & Security.
An implementation practice and a set of assessment artifacts — so an AI project can pass the same SA&A rigor as any other Protected B system.
Model risk is not application risk.
Traditional application security assumes a deterministic system, a documented data flow, and a threat model whose actors are outside the code. Generative AI systems break all three assumptions — model outputs are non-deterministic, training data flows are opaque, and the “actor” can be a prompt embedded inside the very content the system is reading. Governance has to catch up.
ISO/IEC 42001
The AI management-system standard — the ISO 27001 counterpart for AI. Skymeba runs lead-implementer engagements end to end: scope, context, controls, evidence.
NIST AI RMF
The Govern-Map-Measure-Manage risk framework mapped to the SA&A artifacts a Government of Canada team already produces — so AI risk lives inside the SSP, not beside it.
AI project SA&A
Categorization, TRA, SSP, and SRTM tuned for AI systems — model-risk appendix, data-lineage attestations, and inheritance from platform ATOs where they apply.
Where governance meets the engagement.
Every AI engagement is scoped from a concrete outcome — an ISO 42001 certificate, a board-ready risk register, an assessor-defensible SA&A package for an AI project — and delivered on a fixed statement of work.
| Engagement type | Typical duration | Primary deliverables |
|---|---|---|
| AI risk baseline | 2 – 3 weeks | NIST AI RMF baseline, prioritized risk register, control gap analysis |
| ISO/IEC 42001 lead implementation | 3 – 6 months | Scope statement, management-system documentation, internal-audit dry run |
| AI project SA&A support | 6 – 12 weeks | SoS, TRA, SSP tuned for the AI project; model-risk appendix; assessor liaison |
| Executive AI briefing | 1 day | Board-level session on AI risk, current regulation, and the organization's exposure |