Governance artifacts
The documents an assessment actually produces. Each is tagged with the engagement door it belongs to — Door A advisory or Door B independent testing — so a practice never accidentally sells remediation into an institution it is meant to be testing.
AI Vendor Due-Diligence Question Set
Forty questions to send a vendor, ordered so that the answers map directly onto the seven GRI dimensions. Includes the follow-up that catches an evasive answer.
EU AI Act Annex IV Documentation Checklist
Article-level checklist for the technical documentation a high-risk system provider must hold, with the evidence tier each item realistically supports.
GRI Method Specification v0.1
The full scoring method: seven dimensions, five evidence tiers, five weighting profiles, and the stated limitations. Published deliberately — the method is not the moat.
Governance Probe Battery — published subset
The eleven publishable probes. The prompt-injection and name-origin disparity corpora are withheld: publishing them would let vendors tune to pass the test and destroy the instrument.
MSA Derived-Data Clause Set
Contract language securing the right to retain de-identified, aggregated benchmark data from an engagement. Without this in engagement one, the comparative corpus never accumulates.
Quarterly Governance Retainer — SOW skeleton
Scope, deliverables and exclusions for a recurring quarterly governance review. The only engagement shape that is not priced by the calendar day.
SR 26-2 Generative-AI Gap Workbook
Structured worksheet for documenting how an institution governs the generative and agentic AI that SR 26-2 explicitly excludes. Ten sections, each with the examiner question it answers.
Comparative Benchmark Medians — subscriber report
Aggregate medians across assessed systems: where evidence typically fails, by dimension and by product category. Requires five engagements before any statistic is published.