top of page
Search

The AI debate is stuck on the wrong question.

Everyone is arguing the same two points. Should we use it. Is it good or bad.

Meanwhile almost no one is handing people what they actually need: a way to start governing it.

So I built one, and I am sharing it - my next two posts are these two docs.


Here is what I keep seeing. Teams open the conversation by asking which framework is best. SOC 2? ISO 42001? NIST? The EU AI Act?

That is the wrong question, and asking it is a tell.


Those four are not competitors. They do four different jobs.


SOC 2 attests.

ISO 42001 manages.

NIST guides.

The EU AI Act regulates.


And not one of them hands your engineer a control to implement on Monday morning. That gap is the whole reason I put this together.


The starter kit is two documents:


1. A white paper that kills the framework-shopping reflex and lays out 10 control domains, crosswalked to all four standards.

2. An AI Governance Audit Plan that turns each domain into a real test: a procedure, the evidence to request, and an adversarial probe.


Because a control that has never been attacked is a hypothesis, not a control.


The maturity scale tops out at tested against an adversary, not documented. That is the line most starter kits never cross, and it is where the theater hides.


This is a starting point, not the last word. Take it, use it, push back on it. If you want the working version of the audit plan in Excel, message me and I will send it over (LinkedIn does not allow it to be uploaded:( )


Gut check: if someone attacked your AI controls tomorrow, would you find out what your policy claims, or what your attack surface actually allows?

 
 

Recent Posts

See All

Timcke Risk Management, LLC

660 Massachusetts Ave

6th Floor, Boston, MA 02118

 

© 2025 by Timcke Risk Management, LLC

 

bottom of page