Skip to content

AI · Governance · Assess

AI Governance Pack

The policies, data-flow maps, supervision mapping and AI register a regulated firm needs before staff use AI with client data.

Quote-based · EU pricing on request

What you get

  • Acceptable-use policy and data classification
  • Data-flow maps for up to 3 AI tools
  • Supervision mapping to FINRA 2210/3110, SEC recordkeeping, GDPR
  • AI model inventory aligned with SR 26-2
  • Human-review design and staff guidance

Scope

Included

  • Acceptable-use policy
  • Data classification for AI use
  • Data-flow maps for up to 3 AI tools
  • Supervision mapping to FINRA 2210/3110, SEC recordkeeping and GDPR where relevant
  • AI model inventory (register) in line with SR 26-2 expectations
  • Human-review and approval design
  • One-page staff guidance
  • 1 walkthrough with compliance

Not included

  • Legal opinion or regulatory sign-off
  • Implementing the controls (see AI Supervision & Recordkeeping)
  • Vendor due diligence questionnaires

Always outside a fixed-scope package

  • Software licences, credits, add-ons, apps, connectors, and vendor support.
  • Custom code (Apex, LWC, Visualforce, HubSpot custom modules or apps, serverless functions, API services).
  • Data cleansing, deduplication, enrichment or transformation beyond the record counts and rules listed; data is loaded as the client provides it.
  • Integrations not named in the package, and any work inside third-party systems.
  • Content: copywriting, design, imagery, email or page templates beyond the numbers listed.
  • Training beyond the sessions listed, training for staff hired after go-live, and in-person training.
  • Legal, compliance or regulatory approval; we configure controls, the client's compliance team approves them.
  • Administration after the 30-day hypercare (sold as Support).
  • Additional UAT cycles caused by changes to approved requirements.
  • Work outside business hours (US Central or EET by client region), on-site work and travel.
  • Performance or load testing, penetration testing, and accessibility audits.
  • Licence negotiation, vendor contract changes, and vendor-side configuration we cannot access.

What you provide

  • A project owner with decision authority, available 2 to 4 hours a week.
  • Licences in place, admin access, and a sandbox or test environment by kickoff.
  • Subject-matter experts for each process in scope, available for workshops.
  • Source data exported in the agreed format by the date in the project plan.
  • Answers, design approvals and UAT sign-off within 3 business days of each request.
  • Their own users' availability for training sessions.
  • Compliance and legal review of any client-facing content, messaging or AI output.

Assumptions

AI engagement terms

  • AI output is probabilistic; we test against agreed cases and do not guarantee answers.
  • The client's compliance team approves controls, prompts and supervision rules before go-live.
  • Client data is not used to train models; enterprise or zero-retention data terms are configured where the vendor offers them.
  • Vendor model changes and retired features after go-live are handled under Support.
  • Usage costs are the client's and are estimated, not guaranteed.

Done means

Acceptance: Pack delivered and walked through with compliance.

Price and change control

  • This package is quoted after a short scoping call because the effort depends on your systems and data. The scope above is what the quote covers; you receive a written fixed price before work starts.
  • Anything not listed as included is a change. Changes are written up, priced and approved by you before we do them.
  • Software licences, subscriptions and third-party fees are bought by you from the vendor and are never included.
  • EU and UK clients: euro pricing on request; VAT is added where applicable.

Package VP-AI-GOV · scope last reviewed October 2, 2026 by the Vantage Point team. All AI packages → Print this scope