AI Readiness & Security Audit · 30 days
Thirty days from first meeting to a roadmap your board can read.
A fixed-scope assessment of your AI strategy, security posture, and compliance gaps, delivered as a prioritized, costed roadmap with the first 90 days spelled out. It is where most engagements begin — and it stands alone if that is all you need.
What you get
Not a 90-page PDF. A decision document.
Every finding is ranked by risk and effort, given an owner, and costed. The executive briefing fits on two pages; the technical appendix is for your IT partner.
Discovery
Interviews with leadership, staff, and your IT provider. Inventory of systems, data, vendors — and every AI tool in use, sanctioned or not.
Assessment
Security posture against NIST CSF 2.0 across all six functions; AI use against NIST AI RMF; gap analysis against the frameworks your customers, funders, or insurers name.
Roadmap
Findings ranked and costed, a 90-day quick-win plan, a 12-month roadmap, a starter risk register, and a one-hour briefing for leadership or the board.
Who it is for
Three moments when an audit is the right first step.
The questionnaire arrived
An enterprise customer, insurer, or funder sent a security questionnaire and nobody is sure what the honest answers are.
Staff started using AI
ChatGPT, Gemini, or Copilot are already in the building. Leadership wants the benefit without the exposure — and a policy that is more than a ban.
The MSP relationship is a question mark
You pay a provider every month and cannot tell whether the organization is actually protected. An independent look answers that.
After the audit
Most clients keep the executive.
The roadmap is yours to run with your own team or your MSP. Most organizations ask us to stay on as their fractional CISO or CIO to own it — the audit month becomes the onboarding month, and the first steering meeting starts with a real risk register already on the table.
Either way, you will know exactly where you stand, in words a trustee understands.
“What stood out about working with Mike and ForEffect was that they took the time to understand how our church actually operates before writing a line of code.”
Questions we hear
Frequently asked
Is the audit a penetration test?
What do you need from us?
Can our MSP execute the roadmap?
What if we want you to run the roadmap?
One call, no deck
Start with a conversation.
Tell us what keeps you up at night. We read and reply to every note — usually within one business day — and the first conversation is about your organization, not our services.
Book a 20-minute conversation
Pick a time that suits you. No slides, no pitch — twenty minutes on what your organization is dealing with and whether a fractional executive is the right shape of help.
Choose a time