VERITY AI · Governance Program

AI governance built to survive the auditor — and the board.

A managed program that builds and operates your AI Acceptable Use Policy, Model Review Board, model inventory registry, algorithmic impact assessments, and vendor AI risk scoring, aligned to NIST AI RMF, ISO/IEC 42001, and evolving state AI transparency laws.

Program Overview

What the AI Governance Program Builds

Most organizations that reach the point of formalizing AI governance are doing it retroactively — after a use case is already in production, after a customer or regulator asked a question no one could answer. The AI Governance Program builds the structure that should have existed from the start: a written AI Acceptable Use Policy, a Model Review Board with real intake and approval authority, a model inventory registry that stays current, algorithmic impact assessments for higher-risk use cases, and vendor AI risk scoring for the third-party tools your teams already rely on.

The program is built and mapped simultaneously against the NIST AI Risk Management Framework, ISO/IEC 42001, the EU AI Act (for organizations with EU exposure), and applicable state AI transparency requirements such as NYC Local Law 144’s bias-audit rules for automated employment decision tools and Colorado’s revised AI transparency law (SB 26-189, effective January 1, 2027). Quarterly executive briefings keep leadership current as both your AI footprint and the regulatory landscape evolve.

Program Components

What’s Built and Operated

Delivered as a monthly managed program, not a one-time policy document.

Policy

AI Acceptable Use Policy

Written, enforceable policy governing employee and system use of AI tools, reviewed and updated as tools change.

Governance

Model Review Board

Cross-functional board with defined intake, approval, and periodic re-review authority for AI use cases.

Inventory

Model Inventory Registry

Living registry of every model and AI system in use, kept current as tools are added or retired.

Risk

Impact Assessments & Vendor Scoring

Algorithmic impact assessments for higher-risk use cases plus a vendor AI risk-scoring methodology.

Mapped to Current AI Governance Requirements

The program tracks a moving regulatory target so your governance documentation stays current, not just compliant on the day it was written.

NIST AI RMF 1.0ISO/IEC 42001EU AI ActNYC Local Law 144Colorado SB 26-189 (eff. 1/1/2027)

Frequently Asked Questions

How is this different from the vCAIO engagement under VERITY Bridge?
The vCAIO is the named executive who owns AI strategy and can chair your Model Review Board. The AI Governance Program is the underlying program build-out — the policy, registry, and assessment infrastructure the vCAIO operates. Many clients engage both together.
Do you track new state AI laws for us?
Yes. The program includes ongoing monitoring of applicable state and federal AI transparency and disclosure requirements as they take effect, with policy updates reflected in quarterly briefings.
What is an algorithmic impact assessment?
A structured evaluation of a specific AI use case’s potential for harm or bias — particularly for use cases touching employment, credit, healthcare, or other consequential decisions — documenting the assessment methodology and results.
Can this run alongside our existing compliance programs (SOC 2, HIPAA)?
Yes. AI governance is scoped to complement, not duplicate, your existing framework programs under VERITY Govern, with explicit cross-references where AI use cases touch regulated data.

Ready to Build AI Governance That Holds Up?

Every VERITY AI engagement starts with a scoping call and a written proposal covering scope, deliverables, timeline, and pricing.

Request a Governance Proposal →

Part of Armorstack’s VERITY AI program.