What Compass Is
An orientation, not an audit
Most organizations exploring AI governance start in the wrong place — either buying tooling before they know what they’re governing, or drafting a policy nobody can operationalize. Verity Compass is a working session with an Armorstack advisor that orients your leadership team across the questions that actually determine your exposure: where AI tools are already in use, who owns the risk decisions, what a regulator or insurer would ask first, and which of your existing frameworks (NIST AI RMF, ISO/IEC 42001, sector-specific rules) already apply. You leave with a prioritized short list, not a generic scorecard.
The Session Covers
Four orientation points
Visibility
What AI tools and models are already touching your data, sanctioned or not.
Ownership
Who signs off on AI risk decisions today, and whether that authority is documented.
Exposure
Where vendor and third-party AI usage creates contractual or regulatory exposure.
Framework fit
Which existing standard — NIST AI RMF, ISO/IEC 42001, or a sector rule you already answer to — is the fastest path to a defensible program.
Related Verity & Sentry Resources
Get oriented before you build a program
A single working session with a Verity advisor. No forms, no fabricated score — a real conversation and a prioritized next step.