Enter your keyword

← All Projects  ›  AI Risk Governance Framework
Project 11 - AI Governance

AI Risk Governance Framework

Managed Services Provider - Prism Technologies

Built an enterprise AI risk governance framework for a managed services provider, inventorying 15 AI-enabled features with no prior oversight and cutting client AI-governance questionnaire turnaround from three business days to same-day.

15 AI use casesNIST AI RMF 1.0EU AI Act alignedMSP client trustBoard-level reporting
15
AI use cases inventoried
40+
Tools and platforms scanned
100%
Endpoints with AI guardrails
Same-day
Client questionnaire turnaround
The Challenge
Problem Statement

Prism Technologies, a managed services provider running IT operations and security tooling for clients across multiple regulated industries, had no formal inventory or governance process for the AI systems already embedded in its service stack. Engineering and support teams had adopted generative AI copilots and AI-driven automation inside the RMM (Remote Monitoring and Management) and PSA (Professional Services Automation) platforms used to manage client environments, with no risk assessment, approval, or monitoring process governing how these systems handled client data or made decisions on clients' behalf. The exposure was compounded by Prism's position in the supply chain: a growing share of client security questionnaires now asked directly how Prism governed AI systems with access to client environments, and NIST's (National Institute of Standards and Technology) AI Risk Management Framework had become the reference model those questionnaires were increasingly built around. MSP (managed services provider) compromises had already shown how one vendor's gap can cascade across every downstream client, and leadership needed a defensible governance framework in place before a client audit, a regulator, or an AI-driven incident exposed the gap first.

The Approach
How I Solved It

I started with an AI system inventory across the environment, not just the tools formally procured. This surfaced fifteen AI-enabled features already live inside the RMM and PSA platforms, plus several generative AI tools engineers had adopted informally for scripting and documentation. I built the governance framework around NIST AI RMF (Artificial Intelligence Risk Management Framework) 1.0's four functions, Govern, Map, Measure, and Manage, and used the EU (European Union) AI Act's risk categories to classify each use case by the level of autonomy it had over client systems and data. Use cases with direct write access to client environments, such as AI-assisted remediation scripts, were classified high-risk and required human approval before execution; use cases limited to internal documentation or ticket summarization were classified lower-risk with lighter-touch monitoring. I set data handling guardrails to block client data from reaching public AI tools without a signed data processing agreement (DPA) in place, since that was the most immediate way client information could leave Prism's environment unnoticed. I also built a standard AI governance disclosure that could be attached directly to client security questionnaires, since a growing number of clients were asking how Prism governed AI with access to their environments and Prism had no consistent answer.

Frameworks & Standards
NIST AI RMF 1.0
EU AI Act
ISO/IEC 42001
NIST CSF 2.0
Tools & Platforms
RMM Platform · PSA Platform · Microsoft Purview · AI Use Case Register · DPA Tracking
Category
AI Governance · Risk Management · MSP Security
What Was Delivered
Outcomes & Results
Inventoried 40+ internal and client-facing tools, surfacing 15 AI-enabled features with no prior oversight, including 9 with direct write access to client systems or data
Classified all 15 AI use cases into 3 risk tiers under the NIST AI RMF 1.0 model - 4 high-risk, 6 medium-risk, 5 low-risk, each with its own approval and monitoring requirement
Implemented data handling guardrails blocking public AI tool access to client data across 100% of managed endpoints, zero unauthorized data transfers found in the first 90-day audit
Cut average turnaround on client AI-governance questionnaires from 3 business days to same-day, across 30+ client security reviews in the first year
Established quarterly Board-level AI risk reporting, the company’s first formal AI oversight structure, covering all 15 inventoried use cases plus ongoing new-tool intake
Key Lesson
Most of the actual AI risk wasn't coming from a formally procured tool with a contract and a vendor review. It was already running inside platforms Prism had used for years, quietly switched on by a vendor update, or installed by an engineer trying to move faster. A governance framework that only reviews AI purchases misses most of the real exposure. Inventory has to start from what's already running, not from what procurement approved.
// Evidence artifacts - downloadable
Documented. Verifiable. Downloadable.
This project has two corresponding evidence artifacts available in the Evidence Vault.