The AI governance credential built for firms your size — not a compliance department.

Five domains, twenty criteria, translated from ISO/IEC 42001, the NIST AI Risk Management Framework, and the MITRE AI Maturity Model. This is a business readiness check, not a technical audit.

5 Domains · 20 Criteria · 4/4 Required Per Domain

Built on existing standards and best practices

We didn't invent a governance framework. AI Ready is translated for small-firm realities — accessible rigor, not enterprise overhead — from the same standards enterprise compliance teams already answer to.

Standard

What it covers

Maps to

ISO/IEC 42001

International AI Management Standard — planning, operations, supplier management, and support

Domains 1, 2, 3, 5

NIST AI RMF

U.S. federal framework for governing, mapping, measuring, and managing AI risk

Domains 1, 2, 4, 5

MITRE AI Maturity

Leading maturity model across strategy, workforce, and technology

Domains 1, 3, 4, 5

If your clients or partners ever ask whether you follow recognized AI governance standards, this is your answer. It's built for a 12-person shop, not for an enterprise compliance team.

The Five Domains

Passing means all five hold up — not most of them. Governance doesn't average out: a firm that's strong on data privacy but has no idea what its tools do with client information isn't 80% covered, it's exposed.

Domain 1 — AI Strategy & Intent

Do you have a clear, intentional reason for using AI in your business?

• Documented purpose for each AI tool

• Tool adoption decision process

• Customer transparency policy

• Human oversight of consequential decisions

Domain 2 — Customer Data & Privacy

Do you know what happens to your customers' data when you use AI tools?

• AI tool data access inventory

• Vendor data terms reviewed

• Customer data request process

• Data minimization in practice

Domain 3 — Tool Selection & Vendor Basics

Are you choosing AI tools with at least a minimum of due diligence?

• Provider legitimacy verified

• Cost/data tradeoff understood

• Data portability & exit plan

• Sensitive function tools vetted

Domain 4 — Team Readiness & Guardrails

Does anyone using AI in your business know how to use it safely?

• AI limitations understood by all users

• AI use boundaries documented

• Error feedback loop in place

• Output review before publishing

Domain 5 — Change Management

Has your team been brought along, not just handed the tools?

• AI adoption communicated

• Expectations documented

• Support resources available

• Concern feedback mechanism

Two Ways to Certify

Every criterion is scored Met or Not Yet. All 5 domains have to hit 4/4 — 20 of 20 — to certify at either tier. No domain is optional, and no domain gets averaged into a passing score on the strength of the others. This is a growth tool, not a pass/fail exam: findings are framed as opportunities to close, not failures to hide.

AI Ready — $97 one-time

Self-certified. Complete the assessment independently, see exactly where you stand, and get your results the moment you finish.

• Self-assessment across all 5 domains, 30–45 minutes

• Instant results and gap report on completion

• Digital AI Ready badge on passing

• For firms that want a credible answer now, without advisor involvement

AI Ready Pro — $497 one-time

Advisor-verified. Submit structured evidence, then walk through it with an advisor who checks the mechanics behind your answers — not just the checkboxes.

• Structured evidence submission + 60–90 minute advisor consultation

• Distinct Advisor Verified badge, separate from self-certified

• Full Gap Report with prioritized action plan and improvement roadmap

• For firms whose clients or partners want third-party validation, not a self-reported score

Already completed AI Ready? Your $97 applies toward Pro — upgrade cost is $400.

Give your clients the answer before they ask the question.

Start with the self-assessment, or talk to us about which tier fits your firm.

Most firms don't find out they're missing a policy until a client asks for one. Five minutes now beats a hard question later.

What Pro verification actually confirms

Advisor review doesn't rubber-stamp your self-assessment. It results in one of three outcomes, reflecting a collaborative-growth philosophy rather than a binary pass/fail:

Certified

All 5 domains meet standard. No gaps identified.

Certified with Commitments

1–2 gaps identified, with a clear, documented timeline to close them.

Certification in Progress

Meaningful progress made; a roadmap is in place for what's next.

Every Pro engagement includes a full Gap Report: a domain-by-domain scorecard, findings on strengths and gaps, a prioritized action plan, and a 30/60/90-day improvement roadmap — plus advisor notes on recertification timing.

We don't sell compliance theater or a checkbox you forget about next month. Certification isn't a one-time badge. Annual review keeps it current — the same "Adjust" step that shapes how we work with every firm, not just at the Pro tier.

Get the Sunday AI Governance Brief

One email a week on how independent firms are building AI governance that actually holds up — plain language, real examples, no compliance theater.

Turning AI governance from a liability into a differentiator.

Quick links

Home

Pricing

About

Contact

Connect

LinkedIn

Blog

Facebook

Company

Terms

Privacy