AI Governance & Risk Advisory
We don't build AI. We govern it.
Novaris is an AI governance and risk advisory practice, not a general AI consultancy — we don't implement models or write prompts. The work is organized into five practice areas, built on enterprise risk management, fraud-risk, and controls-testing discipline (RCSA), not generic AI hype.
COSO ERM-Based AI Compliance Assessment
Most institutions already run their enterprise risk program on COSO ERM — it's the same framework behind SOX and internal control over financial reporting. Rather than introducing a new methodology for AI, we extend the one your board and auditors already trust, applied specifically to AI risk across three phases.
Risk Identification
Building the AI risk universe against COSO's Strategy & Objective-Setting and Performance components — every AI system mapped to the strategic, operational, reporting, and compliance objectives it touches.
- AI system and use-case inventory
- Risk event identification by objective category
- Likelihood and impact scoring
- Risk register build-out
Control Building
Designing the control environment — preventive and detective controls mapped to COSO's Control Activities, tested with the same RCSA discipline used in fraud and operational risk programs.
- AI control library design
- Preventive & detective control mapping
- Control ownership and testing cadence
- KRIs/KPIs tied to each control
Gap Assessment
Scoring current-state AI risk management against all five COSO ERM components, producing a prioritized remediation roadmap your risk committee can act on.
- Maturity scoring across all 5 COSO components
- Gap report ranked by exposure
- Remediation roadmap with owners and timing
- Board-ready executive summary
This is typically the starting engagement — the AI Governance, Risk Management, and Controls & Assurance practice areas below build directly on its findings.
Book a COSO ERM assessmentHow clients typically move through it
Assess with COSO ERM. Build the program. Sustain it on retainer.
Assess
Most engagements start with the COSO ERM-based compliance assessment above, or with a narrower assessment in one practice area — scoped to a specific question the board or an examiner is already asking.
Build
Findings turn into a governance framework, a control library, or a compliance program — whichever practice area the assessment pointed to.
Sustain
Once a program exists, most clients move to the vAI-CRO retainer to keep it current — one relationship covering all five practice areas going forward.
AI Governance
The accountability layer everything else depends on: who owns AI risk, what they're allowed to approve, and how that authority is structured so it survives staff turnover.
- AI governance framework
- AI policy development
- AI risk appetite
- AI steering committee design
- AI operating model
AI Risk Management
Turning "we use some AI" into a scored, prioritized picture of exposure — the same discipline enterprise risk management already applies to credit, market, and operational risk, applied to AI.
- AI risk assessments
- AI risk registers
- NIST AI RMF implementation
- Risk heat maps
- Executive reporting
AI Controls & Assurance
Where risk management meets internal audit: a documented control library, tested on a schedule, with metrics your risk committee can actually track quarter over quarter.
- AI control library
- Preventive and detective controls
- AI control testing
- AI KRIs / KPIs
- AI audits
AI Compliance
Mapping your AI systems against the specific regulatory regimes that actually apply — not a generic checklist, but the classification and documentation work each framework requires.
- EU AI Act readiness
- ISO/IEC 42001 advisory
- NIST AI RMF alignment
- Internal audit preparation
- Vendor AI risk assessments
AI Fraud & Trust Differentiator
This is the practice area most AI governance consultancies can't offer, because it requires a fraud-risk background, not just a compliance one. It's where Novaris's enterprise risk and fraud-risk experience becomes a direct advantage rather than a talking point.
- AI-enabled fraud assessments
- Deepfake risk
- Prompt injection
- Data leakage
- Identity fraud
- AI misuse by employees
- AI vendor risk
The virtual AI Chief Risk Officer (vAI-CRO)
Most institutions in our market don't need a full-time AI risk executive — they need one on call. The vAI-CRO retainer covers all five practice areas on an ongoing basis, replacing one-off consulting projects with a single, predictable relationship.
- Quarterly AI risk assessments
- AI governance committee facilitation
- Board and executive reporting
- AI policy updates
- AI control reviews
- Vendor AI risk assessments
- Regulatory monitoring
- AI incident advisory
Most clients arrive here after an initial assessment in one practice area — the retainer is the "sustain" step, not the starting point.
Discuss the vAI-CRO retainerNot sure which practice area you need first?
Twenty minutes is usually enough to tell — most conversations point to one clear starting place.
Book a 20-minute posture call