Skip to content
AI Vendor & Risk Management

How much do you really know
about the AI risk you're operating?

AI-VRM assessment across 6 domains — posture, architecture, data, governance, vendors, and exposure. In 4 weeks you leave with a quantitative scorecard, risk heatmap, and 30/60/90 plan.

6AI-VRM domains
120+Audited controls
4 wksFrom kickoff to scorecard
30/60/90Remediation plan
The six AI-VRM domains

360-degree assessment — posture, architecture, data, governance, vendors, and response

Each domain is audited against NIST AI RMF, ISO 42001, and OWASP LLM Top 10 controls, and scored on a 0–100 scale with market benchmarks.

D1 · POSTURE

Security posture

AI inventory, criticality classification, access controls, environment segregation, and credential management for LLM systems.

D2 · ARCH

Architecture & models

Assessment of in-house and third-party models, tool/function design, RAG safety, data/instruction separation, and orchestration patterns.

modeltoolsdata
D3 · DATA

Data & privacy

Training data and RAG lineage, LGPD/GDPR compliance, automatic PII redaction, and output leakage validation.

PII em training set
vector store sem isolam.
output filter ausente
D4 · GOV

Governance & compliance

AI acceptable-use policy, review committee, EU AI Act readiness, PL 2338 (BR), and audit trails for every decision.

42001
D5 · VENDOR

Vendor risk

Due diligence on AI providers, contracts with security clauses, multi-tenant isolation, and exit/portability plan.

D6 · DR

Detection & response

Prompt/response observability, prompt-injection detection, AI IR runbooks, and adapted tabletop exercises.

14:02CRITprompt injection
14:03WARNtool abuse
14:05CONTisolated
4-week process

From kickoff to executive scorecard

WK 1

Kickoff & inventory

Executive workshop, AI systems mapping, criticality classification, and stakeholder definition per domain.

InventoryRACI
WK 2

Collection & interviews

Interviews with engineering, product, data, legal. Review of configurations, code, and documentation. Access to logs.

15+ interviewsRead-only
WK 3

Analysis & benchmark

Scoring of 120+ controls, market peer comparison, top-gap identification, and attack-scenario simulation.

ScoringBenchmark
WK 4

Scorecard & plan

C-level presentation, quantitative scorecard, business-unit heatmap, and 30/60/90 remediation plan.

Executive30/60/90
+ 90D

Post-remediation review

Re-assessment 90 days after remediation start to validate implemented controls and update the scorecard with a new score.

Re-scoreOptional
30 / 60 / 90 Plan

From current score to executive target

Each gap identified becomes a prioritized action with owner, effort, and window. The target: go from an average of 60 to 80+ in 90 days — without freezing the product roadmap.

DAYS 1–30

Quick wins

Prompt logging, output PII redaction, published acceptable-use policy, API key segregation by environment.

QW1
QW2
QW3
DAYS 31–60

Structural controls

Prompt-injection detection, output classifier, AI IR runbooks, review committee for new models.

DAYS 61–90

Continuous program

Operational AI SOC, quarterly tabletop exercises, vendor due diligence, and scorecard re-scoring.

80+

Where does your organization stand today?

Start with a 4-week AI-VRM diagnostic — leave with executive scorecard, heatmap, and actionable 30/60/90 plan.

Start diagnostic