Law degree · Auditor-certified · Serving clients worldwide
FromRisk to Audit‑Ready
AI governance for organizations that have to prove it — to regulators, auditors, and enterprise customers. Practical programs aligned with the EU AI Act, ISO/IEC 42001, NIST AI RMF, and new U.S. state AI laws.
Led by Nabiha Sofia Herradi — LL.B, CISA, CISM, CIPP/E, CIPP/US, with 15+ years running GRC programs.
EU AI Act · NIST AI RMF 1.0 · ISO/IEC 42001 · CCPA ADMT · GDPR
Nabiha Sofia Herradi
LL.B · CISM · CISACIPP/E · CIPP/US · CMMC-CCP
15+ years in GRC
Regulatory, audit, and privacy expertise in one advisor
Most AI governance advice comes from a compliance specialist, an auditor, or a technologist. You get all three perspectives in one engagement.
Reads the regulation, not the summary
A law degree (LL.B) and CIPP/E and CIPP/US certifications mean your program maps to what the EU AI Act, GDPR, and U.S. state laws actually require.
Built to survive an audit
As a CISA and CISM, I design controls and evidence the way auditors and certification bodies will test them — not just policies that sit in a drive.
Fits your existing security program
ISO/IEC 42001 plugs into ISO 27001, SOC 2, and CMMC programs you already run. No parallel bureaucracy.
Engagements with a clear scope and price
Start with an assessment, build the program, or bring me in as your part-time AI governance lead.
From $7,500
Fixed scope · 3–4 weeks
AI Governance Readiness Assessment
- AI system inventory and risk classification
- Gap analysis: EU AI Act, ISO/IEC 42001, or NIST AI RMF
- Prioritized 90-day remediation roadmap
- Executive readout for leadership
From $25,000
Program build · 8–16 weeks
ISO/IEC 42001 Implementation
- AI management system (AIMS) design
- Policies, risk and impact assessments
- Controls, evidence, and internal audit
- Certification-audit preparation
From $3,500/mo
Retainer · 3-month minimum
Fractional AI Governance Lead
- AI committee setup and facilitation
- New AI tool and model intake reviews
- AI vendor due diligence
- Answers to customer AI questionnaires
New AI rules start applying January 1, 2027
California’s automated decisionmaking (ADMT) rules and Colorado’s AI Act both take effect at the start of 2027. If you use AI in hiring, lending, housing, insurance, or other significant decisions, the time to prepare is now.
$4,500 fixed
Sprint · 3 weeks
2027 AI Deadline Sprint
- Identify which AI and ADMT uses are in scope
- Required notices and opt-out / appeal workflows
- Risk assessment documentation
- Compliance checklist your team can run
From $2,500
Per live session · up to 30 staff
AI Literacy & Responsible Use Training
- Supports the EU AI Act AI literacy duty
- Safe use of generative AI at work
- Role-based modules for HR, legal, and IT
- Attendance records for your audit file
Documents that ship with an implementation plan
Need to move fast on a smaller budget? Start with documents tailored to your size, sector, and risk profile.
$150
Instant download
AI Acceptable Use Policy
- Approved and prohibited uses
- Data handling rules for staff
- Tool approval workflow
- Editable Word file
From $1,500
Tailored · 1–2 weeks
AI Governance Starter Kit
- AI Governance Policy
- Acceptable Use Policy
- AI system inventory
- AI risk assessment
- Vendor questionnaire
From $4,500
Tailored · 2–4 weeks
EU AI Act & ISO 42001 Toolkit
- EU AI Act gap assessment
- ISO/IEC 42001 gap assessment
- AI impact assessment
- Everything in the Starter Kit
Handling CUI or working toward CMMC? That work lives at cyberdsc.com.
Read before you build
Two feeds: what changed in AI regulation this week, and how to actually do the work.
AI News
Regulatory moves, enforcement actions, and standards updates — summarized for the people who have to respond to them.
Learn
Step-by-step guidance on AI risk assessments, model inventories, vendor reviews, and career paths in AI governance.
Get the free playbook and the weekly AI regulation brief by email →
Next step
Tell us where your AI program actually is.
Thirty minutes, no slides. You leave with the two or three things worth doing first — whether or not you hire us.
AI governance and risk enquiries go to Nabiha Sofia Herradi, AI Governance, Risk and Compliance Advisor, at info@aigrcadvisory.com. Replies within 24 hours, worldwide.
