AI Governance & Risk Advisory

We don't build AI. We govern it.

Novaris is an AI governance and risk advisory practice, not a general AI consultancy — we don't implement models or write prompts. The work is organized into five practice areas, built on enterprise risk management, fraud-risk, and controls-testing discipline (RCSA), not generic AI hype.

Primary offering

COSO ERM-Based AI Compliance Assessment

Most institutions already run their enterprise risk program on COSO ERM — it's the same framework behind SOX and internal control over financial reporting. Rather than introducing a new methodology for AI, we extend the one your board and auditors already trust, applied specifically to AI risk across three phases.

PHASE 1

Risk Identification

Building the AI risk universe against COSO's Strategy & Objective-Setting and Performance components — every AI system mapped to the strategic, operational, reporting, and compliance objectives it touches.

  • AI system and use-case inventory
  • Risk event identification by objective category
  • Likelihood and impact scoring
  • Risk register build-out
PHASE 2

Control Building

Designing the control environment — preventive and detective controls mapped to COSO's Control Activities, tested with the same RCSA discipline used in fraud and operational risk programs.

  • AI control library design
  • Preventive & detective control mapping
  • Control ownership and testing cadence
  • KRIs/KPIs tied to each control
PHASE 3

Gap Assessment

Scoring current-state AI risk management against all five COSO ERM components, producing a prioritized remediation roadmap your risk committee can act on.

  • Maturity scoring across all 5 COSO components
  • Gap report ranked by exposure
  • Remediation roadmap with owners and timing
  • Board-ready executive summary

This is typically the starting engagement — the AI Governance, Risk Management, and Controls & Assurance practice areas below build directly on its findings.

Book a COSO ERM assessment

How clients typically move through it

Assess with COSO ERM. Build the program. Sustain it on retainer.

Assess

Most engagements start with the COSO ERM-based compliance assessment above, or with a narrower assessment in one practice area — scoped to a specific question the board or an examiner is already asking.

Build

Findings turn into a governance framework, a control library, or a compliance program — whichever practice area the assessment pointed to.

Sustain

Once a program exists, most clients move to the vAI-CRO retainer to keep it current — one relationship covering all five practice areas going forward.

01 · Practice area

AI Governance

The accountability layer everything else depends on: who owns AI risk, what they're allowed to approve, and how that authority is structured so it survives staff turnover.

  • AI governance framework
  • AI policy development
  • AI risk appetite
  • AI steering committee design
  • AI operating model
GOVERNPolicyOperating model
02 · Practice area

AI Risk Management

Turning "we use some AI" into a scored, prioritized picture of exposure — the same discipline enterprise risk management already applies to credit, market, and operational risk, applied to AI.

  • AI risk assessments
  • AI risk registers
  • NIST AI RMF implementation
  • Risk heat maps
  • Executive reporting
MAPMEASURENIST AI RMF
03 · Practice area

AI Controls & Assurance

Where risk management meets internal audit: a documented control library, tested on a schedule, with metrics your risk committee can actually track quarter over quarter.

  • AI control library
  • Preventive and detective controls
  • AI control testing
  • AI KRIs / KPIs
  • AI audits
MEASUREMANAGERCSA-based testing
04 · Practice area

AI Compliance

Mapping your AI systems against the specific regulatory regimes that actually apply — not a generic checklist, but the classification and documentation work each framework requires.

  • EU AI Act readiness
  • ISO/IEC 42001 advisory
  • NIST AI RMF alignment
  • Internal audit preparation
  • Vendor AI risk assessments
EU AI ActISO 42001Vendor risk
05 · Practice area

AI Fraud & Trust Differentiator

This is the practice area most AI governance consultancies can't offer, because it requires a fraud-risk background, not just a compliance one. It's where Novaris's enterprise risk and fraud-risk experience becomes a direct advantage rather than a talking point.

  • AI-enabled fraud assessments
  • Deepfake risk
  • Prompt injection
  • Data leakage
  • Identity fraud
  • AI misuse by employees
  • AI vendor risk
Fraud riskUncommon specialty
Flagship offering · Monthly retainer

The virtual AI Chief Risk Officer (vAI-CRO)

Most institutions in our market don't need a full-time AI risk executive — they need one on call. The vAI-CRO retainer covers all five practice areas on an ongoing basis, replacing one-off consulting projects with a single, predictable relationship.

  • Quarterly AI risk assessments
  • AI governance committee facilitation
  • Board and executive reporting
  • AI policy updates
  • AI control reviews
  • Vendor AI risk assessments
  • Regulatory monitoring
  • AI incident advisory

Most clients arrive here after an initial assessment in one practice area — the retainer is the "sustain" step, not the starting point.

Discuss the vAI-CRO retainer

Not sure which practice area you need first?

Twenty minutes is usually enough to tell — most conversations point to one clear starting place.

Book a 20-minute posture call