AI readiness and governance

Your staff are already using AI. Nobody wrote down the rules.

Somebody on your team has pasted client information into a chatbot this month. That is not a discipline problem, it is a policy vacuum. An AI readiness assessment tells you where your regulated data actually lives, which tools can reach it, which of those vendors will sign an agreement, and what your written policy needs to say before an auditor, an insurer, or a board member asks.

Why this lands on your desk now

The question is arriving from four directions at once.

Almost nobody goes looking for an AI policy. It gets requested, and usually by someone you cannot put off.

  • Your board or owner asked what the exposure is

    The honest answer is usually that nobody has inventoried which tools staff signed up for, so the exposure cannot be described yet. That inventory is the first hour of this engagement.

  • Your insurer added AI questions to the renewal

    Cyber questionnaires now ask about AI tool governance alongside MFA and backups. Answering from memory is how a renewal gets repriced.

  • You handle regulated data and the tools do not have agreements

    A vendor that will not sign a BAA or a data processing agreement is not a vendor you can put PHI or client financial records through, regardless of how good the output is.

  • You want the productivity and cannot get comfortable

    The usual outcome is not a ban. It is a short list of approved tools, configured so the data does not leave, and one page telling staff what goes where.

What we inspect

Eight things, in your actual environment.

This is a working assessment, not a questionnaire you fill out yourself. A tech goes through the environment with you and writes down what is true.

Data inventory

Where regulated and sensitive records actually live today, including the copies in shared drives and inboxes that nobody counts.

Shadow AI discovery

Which AI tools staff have already signed up for, on which accounts, and what those tools can currently reach.

Vendor agreements

Whether each AI vendor in use will sign a BAA or a data processing agreement, and which ones will not under any tier.

Tenant configuration

The settings that decide whether your prompts get retained or used for model training, on the plan you are actually paying for.

Identity and access

Who can reach the sensitive stores, whether MFA is real everywhere, and what happens to access when someone leaves.

Written policy

The acceptable use language you can hand to staff and show an auditor, in plain English rather than a downloaded template.

Incident path

What actually happens the day sensitive data does end up somewhere it should not, and who is responsible for the next hour.

Evidence and review cadence

What you keep, where it lives, and who revisits it, so the answer is still current the next time somebody asks.

What you get

A findings report and a roadmap you can act on.

The assessment ends in a document, not a conversation. You keep it, you can forward it to your board or your insurer, and every finding in it is written so the next step is obvious.

6credits

AI Readiness Assessment, one-time engagement

Book a scoping call

What you walk away with

  • An inventory of the AI tools already in use across your organization
  • Findings ranked by risk, each one tied to the system or vendor it came from
  • The vendor agreement position for every AI tool you use, including the ones that cannot be made compliant
  • Configuration changes to make, in the order they should be made
  • A written acceptable use policy drafted for your organization, ready to adopt
  • A remediation roadmap with the effort behind each item, so you can decide what we do and what you keep

Scoped in credits like everything else in the catalog. Remediation is quoted separately once you have the roadmap, and you are free to take it elsewhere.

See an example report, built from an invented practice.

How it runs

Four steps, no open-ended discovery.

The engagement is fixed in scope before it starts. If we find something that changes the shape of the work, you hear it at that point rather than in an invoice.

Not there yet? Answer eight of the questions yourself. Two minutes, no form, nothing stored.

  1. Scoping call

    We confirm what you run, what data you hold, and which regulations apply to you. If an assessment is not what you need, we say so here.

  2. Working sessions

    A tech walks the environment with whoever holds the admin accounts. Most of the finding happens here, and most of it surprises somebody.

  3. Findings and roadmap

    You get the written report with risk-ranked findings, the drafted policy, and the remediation roadmap with effort behind each line.

  4. Your call on remediation

    Take the roadmap and run it yourself, hand us the whole thing, or pick the items you do not want to own. All three are normal.

Why TechGig

We had to answer this question for ourselves first.

TechGig runs an AI support layer over customer data, including data belonging to healthcare organizations. Every constraint we assess you against is one we had to satisfy in our own platform before we could ship it.

See how credits and plans work
  • Our own AI vendors are under signed agreements

    We did the vendor diligence, signed the BAA, and built a hard gate that blocks covered-entity data from reaching any AI vendor that is not covered by one. It is enforced in code, not in a policy document.

  • Assessment-first, not tool-first

    We do not resell an AI platform, so the assessment has no product to steer you toward. Sometimes the finding is that the tool you already pay for is fine once it is configured properly.

  • The same bench handles the remediation

    Findings turn into scoped work with the techs who already know your environment. You are not handed a report and left to find someone to execute it.

Before you ask

The questions that come up on every scoping call.

Plain answers. Where the real answer is "it depends", we tell you what it depends on.

Scoped before it starts

Find out what you are actually running.

Start with the scoping call. If your setup is already in reasonable shape, that is a real outcome and we will tell you rather than sell you an assessment.

Assessments are one-time and fixed in scope. Remediation is quoted separately, after you have the findings.

Healthcare organizations review and accept our Business Associate Agreement in the app before purchasing services. Read the BAA.