AI Governance Consulting | EU AI Act, ISO 42001, NIST

Law degree · Auditor-certified · Serving clients worldwide

FromRisk to Audit‑Ready

AI governance for organizations that have to prove it — to regulators, auditors, and enterprise customers. Practical programs aligned with the EU AI Act, ISO/IEC 42001, NIST AI RMF, and new U.S. state AI laws.

Led by Nabiha Sofia Herradi — LL.B, CISA, CISM, CIPP/E, CIPP/US, with 15+ years running GRC programs.

EU AI Act · NIST AI RMF 1.0 · ISO/IEC 42001 · CCPA ADMT · GDPR

Nabiha Sofia Herradi, AI governance, risk and compliance advisor

Nabiha Sofia Herradi

LL.B · CISM · CISA
CIPP/E · CIPP/US · CMMC-CCP
15+ years in GRC
Why us01 / Proof

Regulatory, audit, and privacy expertise in one advisor

Most AI governance advice comes from a compliance specialist, an auditor, or a technologist. You get all three perspectives in one engagement.

Regulation

Reads the regulation, not the summary

A law degree (LL.B) and CIPP/E and CIPP/US certifications mean your program maps to what the EU AI Act, GDPR, and U.S. state laws actually require.

Audit

Built to survive an audit

As a CISA and CISM, I design controls and evidence the way auditors and certification bodies will test them — not just policies that sit in a drive.

Delivery

Fits your existing security program

ISO/IEC 42001 plugs into ISO 27001, SOC 2, and CMMC programs you already run. No parallel bureaucracy.

Scope02 / Advisory

Engagements with a clear scope and price

Start with an assessment, build the program, or bring me in as your part-time AI governance lead.

From $7,500

Fixed scope · 3–4 weeks

AI Governance Readiness Assessment

  • AI system inventory and risk classification
  • Gap analysis: EU AI Act, ISO/IEC 42001, or NIST AI RMF
  • Prioritized 90-day remediation roadmap
  • Executive readout for leadership
Book a scoping call

From $25,000

Program build · 8–16 weeks

ISO/IEC 42001 Implementation

  • AI management system (AIMS) design
  • Policies, risk and impact assessments
  • Controls, evidence, and internal audit
  • Certification-audit preparation
Book a scoping call

From $3,500/mo

Retainer · 3-month minimum

Fractional AI Governance Lead

  • AI committee setup and facilitation
  • New AI tool and model intake reviews
  • AI vendor due diligence
  • Answers to customer AI questionnaires
Discuss a retainer
Now03 / 2027 deadlines

New AI rules start applying January 1, 2027

California’s automated decisionmaking (ADMT) rules and Colorado’s AI Act both take effect at the start of 2027. If you use AI in hiring, lending, housing, insurance, or other significant decisions, the time to prepare is now.

Limited spots before Jan 1

$4,500 fixed

Sprint · 3 weeks

2027 AI Deadline Sprint

  • Identify which AI and ADMT uses are in scope
  • Required notices and opt-out / appeal workflows
  • Risk assessment documentation
  • Compliance checklist your team can run
Reserve a sprint

From $2,500

Per live session · up to 30 staff

AI Literacy & Responsible Use Training

  • Supports the EU AI Act AI literacy duty
  • Safe use of generative AI at work
  • Role-based modules for HR, legal, and IT
  • Attendance records for your audit file
Schedule training
Catalogue04 / Documents

Documents that ship with an implementation plan

Need to move fast on a smaller budget? Start with documents tailored to your size, sector, and risk profile.

$150

Instant download

AI Acceptable Use Policy

  • Approved and prohibited uses
  • Data handling rules for staff
  • Tool approval workflow
  • Editable Word file
Buy now

From $1,500

Tailored · 1–2 weeks

AI Governance Starter Kit

  • AI Governance Policy
  • Acceptable Use Policy
  • AI system inventory
  • AI risk assessment
  • Vendor questionnaire
Start your kit

From $4,500

Tailored · 2–4 weeks

EU AI Act & ISO 42001 Toolkit

  • EU AI Act gap assessment
  • ISO/IEC 42001 gap assessment
  • AI impact assessment
  • Everything in the Starter Kit
Start your toolkit

Handling CUI or working toward CMMC? That work lives at cyberdsc.com.

Published05 / Insights

Read before you build

Two feeds: what changed in AI regulation this week, and how to actually do the work.

Updated weekly

AI News

Regulatory moves, enforcement actions, and standards updates — summarized for the people who have to respond to them.

Open the news feed →

Guides & explainers

Learn

Step-by-step guidance on AI risk assessments, model inventories, vendor reviews, and career paths in AI governance.

Start learning →

Next step

Tell us where your AI program actually is.

Thirty minutes, no slides. You leave with the two or three things worth doing first — whether or not you hire us.

AI governance and risk enquiries go to Nabiha Sofia Herradi, AI Governance, Risk and Compliance Advisor, at info@aigrcadvisory.com. Replies within 24 hours, worldwide.

AI GRC Advisory

Practical AI governance, risk, and compliance for regulated organizations. We translate regulation into programs people can run.

Get in touch