Federal AI Governance
NIST AI RMF and OMB AI memos
OMB M-24-10 (and follow-on memos) require federal agencies to inventory AI use cases, designate accountable owners, and govern rights-impacting and safety-impacting AI to a higher standard. We help agencies stand up that program without slowing innovation.
AI governance is risk management, not policy theater. We use the NIST AI Risk Management Framework as the spine and connect each function (Govern, Map, Measure, Manage) to artifacts your IG can audit.
What you walk away with
Stand up a defensible AI use case inventory
A complete inventory with risk classification, accountable owners, and the rights-impacting and safety-impacting designations OMB requires.
Govern high-risk AI without blocking pilots
Risk treatment, monitoring, and human-in-the-loop controls that satisfy oversight without freezing your AI roadmap.
Pass an IG or GAO review with confidence
Documentation, governance minutes, and decision artifacts that show the program operates the way the policy requires.
Inside a Federal AI Governance engagement
- OMB M-24-10 compliance assessment and gap analysis
- NIST AI Risk Management Framework (AI RMF) implementation
- AI use case inventory and risk classification
- Rights-impacting and safety-impacting AI governance
- AI Chief AI Officer (CAIO) program support
What we work against
How We Engage
Three paths into the work, sequenced to where you are in the acquisition cycle.
Subcontracting
We sit on your prime's contract as a compliance subcontractor. Bring us in for assessment, documentation, or audit support without standing up a new vehicle.
Teaming
Joint ventures and teaming agreements with primes that need a CPA + CISSP combination on the bid. Our credentials fill the compliance gap your team does not staff in-house.
Direct
Direct engagements through GSA MAS and 8(a) Direct Award (FY26 target). We take the contract, you get the work.
The practitioner guide to Federal AI Governance
Our principal documents the methodology we bring to every engagement on josefkamara.com. Same playbook, in public, free.
Anonymized work, on request
Anonymized engagement profiles are available on request, pending NDA review. Profiles describe challenge, approach, and outcome without contract numbers, agency names, or dollar values, in line with standard professional services practice.
Request profilesMore for federal agencies
- SAM.gov UEI ZT3FHUTFA8P1
- CAGE Code 9UKZ3
- Credentials CPA · CISSP · CISA
- Status Minority-Owned SB
Standing up an AI governance program?
A scoping call covers your inventory status, your CAIO structure, and the highest-risk use cases. We can sketch the next 90 days in one conversation.
Start the conversation