Vectis Consulting
Vectis
CONSULTING

For law firms, credit unions, and Georgia counties and cities

AI governance for regulated work

Request a scoping conversation

Governed Workflow Engagement — for law firms and credit unions

Malpractice carriers increasingly ask at renewal whether a firm has a written AI policy and how AI-assisted work is verified. NCUA has named AI oversight an examiner focus and evaluates it through vendor management, fair lending, and BSA reviews. A template is not evidence. A governed engagement produces the inventory, the log, and the vendor file that answer the question.

Step 1

AI Use Charter

One page your responsible person approves, plus a control matrix (GB-01 through GB-12), an inventory of the AI tools in use, and the regulatory basis for your practice.

Step 2

One workflow, built under the charter

Examples for closing firms: HOA estoppel follow-up and seller information intake; wire-instruction verification; phone intake coverage. Human approval gates on every consequential action.

Step 3

Evidence

Run logs, vendor due-diligence records, and a review packet written so an underwriter, an examiner, or an auditor can read it.

Ground rules

U.S.-based model providers only (Anthropic, OpenAI, Google, Microsoft, Amazon). Hosted in your environment or on a Vectis-managed server. Control mapping informed by ISO/IEC 42001 and the NIST AI Risk Management Framework, with the EU AI Act as a design benchmark. We say “aligned with”, not “certified”, and we put the limitations in writing.

The first engagements are priced as early access before the rate rises, in exchange for a reference.

Request a scoping conversation

AI Governance Audit — for Georgia counties and cities

Georgia's Technology Authority has set the framework for responsible AI in state government — PS-23-001 and SS-25-001 — and Senate Resolution 789 signals more to come. Counties, cities, and regulated businesses are expected to show their AI use is governed. Most don't yet have the documentation to show it.

The Vectis AI Governance Audit is a fixed-scope engagement, structured to fit local-government small-purchase authority. It is aligned to the GTA frameworks and written in plain language your board, council, or examiners can act on.

Deliverable 1

AI use-case inventory

A complete map of where AI is in use — or quietly creeping in — across your organization: which tools, which tasks, which data.

Deliverable 2

Gap assessment against GTA PS-23-001 / SS-25-001

Where your current practices stand against Georgia's Technology Authority AI frameworks, and what closing each gap requires.

Deliverable 3

AI governance policy draft (board/council-adoptable)

A policy written for adoption — plain language your board or council can vote on, not a template you still have to translate.

Deliverable 4

Risk classification matrix (human-review tiers)

Every AI use case classified by risk, with clear tiers defining where human review is required before anything takes effect.

Deliverable 5

Vendor & procurement AI controls checklist

The questions to ask — and the contract terms to require — before any vendor's AI touches your data or your constituents.

Deliverable 6

Executive briefing + 12-month roadmap

A briefing for leadership and a twelve-month plan that sequences the work, so governance becomes practice rather than paper.

Vectis runs under its own charter.

Our internal AI Use Charter names a Responsible Person, and our build system logs every automated run with a human approval gate before anything ships. We ask nothing of clients we don't do ourselves.

Request a scoping conversation.

Thirty minutes. We'll walk through where AI is showing up in your organization and what the engagement would cover for you.