Services
Fractional CISOFractional CIOAI Readiness & Security AuditStrategic Implementation
Who we serve
NonprofitsChurches & ministriesSmall businessesMSP partners
Company
AboutCase studiesInsightsContactStart with a conversation →
Home/Services/AI Readiness & Security Audit

AI Readiness & Security Audit · 30 days

Thirty days from first meeting to a roadmap your board can read.

A fixed-scope assessment of your AI strategy, security posture, and compliance gaps, delivered as a prioritized, costed roadmap with the first 90 days spelled out. It is where most engagements begin — and it stands alone if that is all you need.

Duration30 days, fixed scope
StandardNIST CSF 2.0 · NIST AI RMF
OutputRoadmap, risk register, executive briefing
PricingFixed fee, quoted in the first call

What you get

Not a 90-page PDF. A decision document.

Every finding is ranked by risk and effort, given an owner, and costed. The executive briefing fits on two pages; the technical appendix is for your IT partner.

Week 1

Discovery

Interviews with leadership, staff, and your IT provider. Inventory of systems, data, vendors — and every AI tool in use, sanctioned or not.

Weeks 2–3

Assessment

Security posture against NIST CSF 2.0 across all six functions; AI use against NIST AI RMF; gap analysis against the frameworks your customers, funders, or insurers name.

Week 4

Roadmap

Findings ranked and costed, a 90-day quick-win plan, a 12-month roadmap, a starter risk register, and a one-hour briefing for leadership or the board.

Who it is for

Three moments when an audit is the right first step.

Moment

The questionnaire arrived

An enterprise customer, insurer, or funder sent a security questionnaire and nobody is sure what the honest answers are.

Moment

Staff started using AI

ChatGPT, Gemini, or Copilot are already in the building. Leadership wants the benefit without the exposure — and a policy that is more than a ban.

Moment

The MSP relationship is a question mark

You pay a provider every month and cannot tell whether the organization is actually protected. An independent look answers that.

After the audit

Most clients keep the executive.

The roadmap is yours to run with your own team or your MSP. Most organizations ask us to stay on as their fractional CISO or CIO to own it — the audit month becomes the onboarding month, and the first steering meeting starts with a real risk register already on the table.

Either way, you will know exactly where you stand, in words a trustee understands.

“What stood out about working with Mike and ForEffect was that they took the time to understand how our church actually operates before writing a line of code.”

AJ
Alex JohnsonExecutive Pastor, Gold Creek Community Church

Questions we hear

Frequently asked

Is the audit a penetration test?
No. A penetration test probes systems for exploitable weaknesses. The audit assesses the whole program — governance, controls, AI use, compliance obligations — and tells you whether a penetration test is one of the things you need.
What do you need from us?
About six hours of leadership and staff time across the month, access to your IT provider, and the documents you already have. We work around your calendar.
Can our MSP execute the roadmap?
That is how it is written. Every item has an owner, a cost, and enough specificity that your provider can quote and schedule it.
What if we want you to run the roadmap?
Most clients do. The audit month becomes the onboarding month of a fractional CIO/CISO retainer, and the first steering meeting starts with the risk register already on the table.

One call, no deck

Start with a conversation.

Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.

info@foreffectai.comMill Creek, WA · Remote-first

Book a 20-minute conversation

Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.

Choose a time
or
Send a short note instead