US federal

    Assurance and oversight for US federal programmes

    Federal departments, agencies and their programme offices carry authorisation, continuous-monitoring, grant-stewardship and AI-oversight duties at the same time. We operate the evidence layer that keeps those duties answerable to an inspector general, a committee or an auditor without re-running the whole assessment each cycle.

    Who this is for

    CIO and CISO offices

    Authorisation boundaries, POA&M discipline and continuous monitoring evidence that survives an independent assessor.

    Programme and PMO leadership

    Schedule, cost and delivery integrity reporting tied to the controls that actually govern the programme.

    Grant and financial-assistance offices

    Sub-recipient monitoring, single-audit readiness and improper-payment control evidence.

    Chief AI and data officers

    Inventory of AI uses, rights-and-safety impacting determinations, and human-review records.

    Inspector general and internal audit

    Immutable calculation trails and scoped read access rather than screenshot packs.

    Acquisition and vendor management

    Flow-down of security and AI obligations to primes and their subcontractors.

    Oversight surfaces we operate

    Authorisation and continuous monitoring

    Control operation is tracked continuously rather than reconstructed at assessment time, with exception handling and remediation held in one place.

    • Control-by-control operating evidence with owner and cadence
    • Exception, deviation and compensating-control records
    • Remediation tasks with attestation and closure trails

    Third-party and supply-chain assurance

    Vendor obligations are held as controls with named owners, not as a questionnaire archive.

    • Contract clause to control mapping
    • Tiering by mission dependency and data sensitivity
    • Sub-tier concentration and single-point-of-failure views

    AI use oversight

    Every model or automated determination in scope is registered, classified and gated before it touches a public-facing decision.

    • Authorised-use registry with owner and purpose
    • Pre-deployment review gates and human-in-the-loop records
    • Stated-reason traceability for adverse determinations

    Grant and assistance stewardship

    Sub-recipient oversight becomes a monitored control set rather than an annual scramble.

    • Risk-based sub-recipient monitoring schedules
    • Finding, corrective-action and resolution tracking
    • Audit-ready evidence packages by award

    Programme delivery integrity

    Delivery health is reported next to control health so oversight bodies see one picture.

    • Milestone and dependency integrity signals
    • Escalation thresholds agreed in advance
    • Board and committee-ready reporting cadence

    Knowledge transfer

    Capability stays with the agency: our practitioners work alongside your staff and leave the operating model documented.

    • Named agency owners for every control
    • Runbooks and reporting templates handed over
    • Exit criteria defined at engagement start

    The regimes this answers to

    FedRAMPAuthorisation boundary evidence, continuous monitoring cadence and POA&M discipline for cloud services in scope.
    FISMA and NIST SP 800-53Control operation, assessment and authorisation evidence held continuously.
    NIST SP 800-171 and CMMCControlled unclassified information handling across contractor and subcontractor tiers.
    NIST AI Risk Management FrameworkGovern, map, measure and manage functions mapped to registered AI uses.
    OMB AI oversight directionInventory, impact determination and human-review expectations for rights- and safety-impacting uses.
    Uniform Guidance (2 CFR 200)Sub-recipient monitoring, allowability and single-audit readiness.
    GAO Green Book and internal control standardsControl environment, risk assessment and monitoring evidence.

    Questions buyers ask

    Do you replace our authorisation package work?

    No. We operate the evidence layer underneath it. Your assessors and authorising official keep their roles; what changes is that control operation is recorded as it happens rather than assembled at the end.

    Can this run inside a restricted environment?

    Yes. Deployment postures include dedicated tenancy and sovereign or restricted enclaves. Residency, key custody and access boundaries are set during scoping.

    How is AI oversight kept auditable?

    Each registered use carries a purpose, an owner, a classification and a gate record. Adverse determinations retain the stated reason and the human-review step, so a reviewer can reconstruct the decision.

    How do you handle knowledge transfer?

    Agency staff are named owners from day one and every control, runbook and report template is handed over. Exit criteria are agreed before work starts.

    Scope it against your own obligations

    Federal briefings start from your authorisation boundary, award portfolio or AI inventory — not from a generic capability deck. A senior practitioner reviews every enquiry.

    Request a briefing