AI Governance Advisory

Govern Your AI.
Before It Governs You.

PCA delivers ISO/IEC 42001 and NIST AI Risk Management Framework advisory services grounded in 30 years of operational security experience. We assess the AI systems your organization is actually deploying — not theoretical case studies — and build governance programs built for regulatory scrutiny and real-world operations.

At a Glance
ISO 42001
Certifiable international AI management system standard — PCA delivers full advisory through certification
NIST AI RMF
U.S. government-aligned voluntary framework — four functions, Govern through Manage
30+ Years
Law enforcement, gaming, hospitality, and corporate security operational experience informing every engagement
One Team
Both frameworks in a single integrated engagement, eliminating duplicated cost and effort
The Frameworks

Two Standards. One Governance Program.

ISO 42001 and the NIST AI RMF were designed to work together. Understanding both — and when to apply each — is where PCA's advisory delivers immediate value.

International Standard
ISO/IEC 42001:2023
Published December 2023  ·  International Organization for Standardization

The first internationally certifiable standard for an AI Management System (AIMS). Built on the same Plan-Do-Check-Act model as ISO 9001 and ISO 27001, it provides a structured path to documented, auditable AI governance — resulting in a third-party issued certificate from an accredited certification body.

  • Certifiable — produces a formal credential recognized globally
  • Clauses 4 through 10 govern context, leadership, risk planning, operations, evaluation, and improvement
  • Strongest fit for organizations with international operations, client procurement requirements, or formal compliance programs
  • Three-year certification cycle with annual surveillance audits
U.S. Federal Standard
NIST AI RMF (AI 100-1)
Published January 2023  ·  National Institute of Standards and Technology

Voluntary guidance from NIST that provides a practical, risk-based approach to AI governance across the full system lifecycle. No certificate is issued, but alignment is increasingly expected by federal agencies, government-adjacent organizations, and partners operating under NIST-aligned procurement frameworks.

  • Four core functions: Govern (cross-cutting), Map, Measure, and Manage
  • Generative AI Profile (NIST AI 600-1) available for organizations deploying generative AI systems
  • Strongest fit for law enforcement, municipal government, and organizations with federal agency relationships
  • Emerging state-level AI regulations are drawing from NIST guidance — early adoption is a proactive compliance posture

These frameworks are not competing alternatives. ISO 42001 Clause 4.1 explicitly cross-references the NIST AI RMF. PCA delivers both in a single integrated program, producing ISO certification readiness and NIST alignment simultaneously — eliminating the cost and effort of running separate engagements.

Service Lines

From Gap to Governance.

PCA structures engagements to match where your organization is and where it needs to go. Every engagement is led by a principal-level advisor — not handed off to junior staff.

01
AI Governance Gap Assessment

Evaluate your current state against ISO 42001, NIST AI RMF, or both. The deliverable is a written gap report with prioritized findings and a remediation roadmap. This is the entry point for any engagement and stands alone as a decision-support document.

$8,000 – $60,000  depending on scope and system count
02
ISO 42001 Certification Readiness

Full advisory from gap through documentation development, policy design, internal audit preparation, and certification body introduction. PCA's existing AIMS document library — built directly from the published standard — accelerates delivery and reduces your internal burden.

$25,000 – $90,000+  certification body fees are separate
03
NIST AI RMF Alignment Program

Structured program mapped against all four NIST AI RMF functions. Deliverables include a written governance program, policies, and a maturity scoring output. Built for law enforcement, municipal, and government-adjacent organizations that need NIST-aligned documentation without pursuing ISO certification.

$12,000 – $75,000  depending on function depth
04
Annual Advisory Retainer

Ongoing support for management review, internal audits, policy maintenance, and surveillance audit preparation. ISO 42001 requires annual surveillance audits in years one and two of the certification cycle. The retainer keeps your program current and audit-ready without internal resource strain.

$12,000 – $30,000 / year  scoped by framework and activity volume
Who We Serve

Built for the Sectors Deploying AI at the Highest Stakes.

PCA's AI governance advisory is most valuable where the operational consequences of ungoverned AI are greatest. These are the sectors we know best.

Law Enforcement & Public Safety

Agencies deploying facial recognition, mobile biometrics, tattoo identification, and predictive tools need governance frameworks their prosecutors, oversight boards, and the public can trust. NIST alignment is the language federal partners already speak.

NIST AI RMF Lead
🏨
Hospitality & Gaming

AI is embedded in guest screening, surveillance, fraud detection, and compliance workflows. International operations and institutional procurement requirements make ISO 42001 certification a competitive advantage and a procurement necessity.

ISO 42001 Lead
🏛
Municipal Government

Cities and counties using AI for traffic management, public safety, licensing, and social services face growing legislative pressure. NIST-aligned governance documentation positions agencies ahead of state-level AI regulation before it becomes enforceable.

NIST AI RMF Lead
🔒
Corporate Security

Security departments integrating computer vision, access control analytics, and real-time screening platforms into enterprise operations need documented AI governance to satisfy board-level risk oversight, insurance underwriters, and client due diligence requirements.

Dual-Framework
🤖
AI-Enabled Technology Vendors

Companies selling AI-powered security, biometric, or risk screening platforms to regulated industries increasingly need documented governance to win procurement bids. PCA helps vendors build the governance posture that enterprise and government buyers require.

Dual-Framework
🎓
Education

Institutions deploying AI in admissions, student safety, and campus access control face FERPA obligations, board scrutiny, and community trust considerations. A structured governance program demonstrates responsible deployment before regulatory mandates arrive.

ISO 42001 or NIST
🏗
Commercial Real Estate

Property managers integrating tenant screening, surveillance analytics, and predictive maintenance AI into multi-site operations need governance structures that protect against liability and demonstrate due diligence to institutional investors and insurers.

ISO 42001 Lead
Events & Venue Operations

Major event producers and venue operators using crowd analytics, behavioral detection, and access biometrics face both public trust and regulatory exposure. PCA's background in large-scale security operations informs governance frameworks that map directly to operational reality.

Dual-Framework
Why PCA

The Governance Is Only as Good as the Operational Knowledge Behind It.

Most consultants selling AI governance advisory have never operated, evaluated, or deployed the systems they are auditing. PCA's gap assessments reflect actual operational risk in context — not checkbox compliance.

Background
30+ years — LVMPD, FBI task force, senior corporate security leadership
License
NV PILB #2916 — Private Investigator, State of Nevada
ISO 42001
Full AIMS document library built and validated against the published standard
NIST
Deep familiarity with NIST AI RMF, CSF, and the broader NIST risk framework ecosystem
01
We Know the Systems
PCA has hands-on experience evaluating and positioning facial recognition, mobile biometrics, under-vehicle scanning, tattoo identification, real-time risk screening, and computer vision platforms. That operational context makes our governance work specific and defensible — not generic.
02
Principal-Level on Every Engagement
There is no handoff to junior staff. The advisor who scopes your engagement is the advisor who delivers it. That means continuity, accountability, and a direct line to someone who understands both the standard and your operational environment.
03
Existing Document Infrastructure
PCA has already built a complete ISO 42001 AIMS document library — AI policy, scope document, gap assessment template, certification roadmap, and supporting annexes — directly from the published standard. That library compresses your timeline and reduces your internal burden from day one.
04
The Right Market Position
Not a large firm charging enterprise rates with no operational context. Not a template vendor with no advisory relationship behind the deliverables. PCA sits between both — competitive fees, genuine expertise, and a principal who has been in the field, not just in the boardroom.
How an Engagement Works

Four Phases. One Clear Path.

1
Scoping Call

We understand your AI systems, current governance posture, regulatory environment, and organizational goals. No discovery questionnaire — a direct conversation with the principal.

2
Gap Assessment

PCA evaluates your current state against the applicable framework or both simultaneously. Output is a written report with prioritized gaps, risk ratings, and a remediation roadmap.

3
Program Development

Policies, procedures, controls, and documentation are built to your scope. For ISO 42001, PCA's existing document library is adapted to your specific AIMS. For NIST, the four-function program is built to your operational context.

4
Certification or Ongoing Support

For ISO 42001, PCA prepares you for the accredited certification body audit and introduces qualified audit partners. For NIST, we deliver the completed program and offer retainer support for ongoing maturity advancement.

Get Started

Ready to Build a Governance Program That Holds Up?

The conversation starts with a scoping call — no questionnaires, no sales process. We discuss your AI systems, your current state, and what a realistic program looks like for your organization. From there, we scope the engagement and move.

Direct Contact
Joel Kisner
Founder and CEO, Pinnacle Consulting and Advisors
NV PILB License #2916  ·  Pinnacle Consulting and Advisors