AI Risk Governance Framework
Built an enterprise AI risk governance framework for a managed services provider, inventorying 15 AI-enabled features with no prior oversight and cutting client AI-governance questionnaire turnaround from three business days to same-day.
Prism Technologies, a managed services provider running IT operations and security tooling for clients across multiple regulated industries, had no formal inventory or governance process for the AI systems already embedded in its service stack. Engineering and support teams had adopted generative AI copilots and AI-driven automation inside the RMM (Remote Monitoring and Management) and PSA (Professional Services Automation) platforms used to manage client environments, with no risk assessment, approval, or monitoring process governing how these systems handled client data or made decisions on clients' behalf. The exposure was compounded by Prism's position in the supply chain: a growing share of client security questionnaires now asked directly how Prism governed AI systems with access to client environments, and NIST's (National Institute of Standards and Technology) AI Risk Management Framework had become the reference model those questionnaires were increasingly built around. MSP (managed services provider) compromises had already shown how one vendor's gap can cascade across every downstream client, and leadership needed a defensible governance framework in place before a client audit, a regulator, or an AI-driven incident exposed the gap first.
I started with an AI system inventory across the environment, not just the tools formally procured. This surfaced fifteen AI-enabled features already live inside the RMM and PSA platforms, plus several generative AI tools engineers had adopted informally for scripting and documentation. I built the governance framework around NIST AI RMF (Artificial Intelligence Risk Management Framework) 1.0's four functions, Govern, Map, Measure, and Manage, and used the EU (European Union) AI Act's risk categories to classify each use case by the level of autonomy it had over client systems and data. Use cases with direct write access to client environments, such as AI-assisted remediation scripts, were classified high-risk and required human approval before execution; use cases limited to internal documentation or ticket summarization were classified lower-risk with lighter-touch monitoring. I set data handling guardrails to block client data from reaching public AI tools without a signed data processing agreement (DPA) in place, since that was the most immediate way client information could leave Prism's environment unnoticed. I also built a standard AI governance disclosure that could be attached directly to client security questionnaires, since a growing number of clients were asking how Prism governed AI with access to their environments and Prism had no consistent answer.