About | AI Governance, Risk & Compliance Advisory

About

A practitioner, not a panel of them.

You work directly with the advisor who writes your documents. No junior hand-off, no template mill.

Nabiha Sofia Herradi Advisor Nabiha Sofia Herradi LL.B · CISM · CISA
CIPP/E · CIPP/US
CMMC-CCP

Fifteen years across governance, risk, compliance, privacy, cybersecurity, and regulatory readiness — now focused entirely on how organizations adopt AI without losing control of it.

The work sits where legal obligation meets operational reality. A policy that no one can follow does not reduce risk; a control with no owner does not survive its first audit. Every engagement is built backwards from the evidence someone will eventually ask you to produce.

How we work

  • Fixed scope, fixed price. You approve the deliverables and the dates before work starts.
  • Documents you own. Editable files, no locked platforms, no per-seat licensing.
  • Plain language. Written so a business owner can act on it without a translator.
  • Framework-traceable. Every recommendation maps to NIST AI RMF, ISO/IEC 42001, or a specific EU AI Act article.

What we don’t do

We do not provide legal advice, and we do not certify anyone against ISO/IEC 42001 — certification comes from an accredited body. We prepare you for it.

Defense-sector work involving Controlled Unclassified Information and CMMC is delivered separately through cyberdsc.com.

Next step

Thirty minutes, no slides.