AI Governance — Cybersecurity Compliance — Solution Delivery

Complex programs.
Serious delivery.

Independent advisory and delivery for organizations navigating AI governance, cybersecurity compliance, and authorization programs. I help clients scope risk, align engineering and assessor timelines, and ship — without the motivational filler.

DoW RMF

FedRAMP

SOC 2

CMMC

ISO 42001

NIST AI RMF

EU AI Act

AI Governance

Cybersecurity

Carl Scott

What you get

Four core capabilities.

No motivational framing. Just the work I actually do when programs are at risk of slipping, failing audit, or missing their authorization window.

Program Leadership

End-to-end delivery of multi-stakeholder programs across distributed teams, ambiguous requirements, and fixed deadlines. Scope, risk, and velocity held together.

Security & Compliance

FedRAMP High, DoW RMF, SOC 2, and CUI/ITAR-controlled environments. Control mapping, POA&M remediation, and first-attempt authorization readiness.

AI Governance

Practical AI risk frameworks, model evaluation workflows, and compliance posture for emerging AI systems. The same work applies to commercial organizations facing the EU AI Act, ISO 42001 certification, and customer AI governance requirements — not only federal programs. Building tools that make governance operational.

Applied AI & Automation

Working applications, not slideware. Custom AI tools, workflow automation with n8n and Make, and CRM and pipeline builds. Forty years of delivery experience pointed at systems that actually ship.

Selected work

Programs delivered under pressure.

Case studies organized by program type. Each includes scope, constraints, and the outcome — not aspirational language.

Onebrief

Senior Cybersecurity Compliance Expert. Led control mapping across the NIST 800-53 High baseline, ran the remediation program, and aligned engineering, security, and assessor timelines for a FedRAMP High authorization effort.

FedRAMP High
NIST 800-53

Outcome

FedRAMP High program

NIST 800-53 High baseline

AIGRA

Built a governance assistant that translates AI risk frameworks into actionable evaluation workflows for technical teams.

AI Governance
Multi-Framework
Risk Framework

Outcome

Operational AI governance tool

Multi-framework

SAIC

Led a DoW RMF authorization program across engineering and compliance teams in a CUI-controlled environment, closing control gaps and delivering the ATO package.

DoW RMF

Outcome

ATO delivered

DoW RMF

Products

Tools I've built.

Working products that operationalize governance, compliance, and AI readiness — not slide decks or vaporware.

AIGRA

AI Governance Readiness Auditor

Gap analysis across 15+ global AI frameworks from a single document upload.

Status

Live

AIGP Exam Prep Studio

IAPP AI Governance Professional Certification Study Platform

Study platform for the IAPP AI Governance Professional certification.

Status

Beta

GRC Verge

Governance, Risk, and Compliance Tooling

Governance, risk, and compliance tooling.

Status

In development

Credentials

Verified. Current. Relevant.

Certifications, clearance status, and current role — visible early because prospects shouldn't have to dig.

Certifications

  • CISSP

    Certified Information Systems Security Professional

    Active
  • CCSP

    Certified Cloud Security Professional

    Active
  • CGRC

    Governance, Risk, and Compliance

    Active
  • PMP

    Project Management Professional

    Active
  • CSM

    Certified ScrumMaster

    Active
  • Associate C|CISO

    Associate Certified Chief Information Security Officer

    Active
  • AIGP

    Artificial Intelligence Governance Professional

    In progress

Clearance & Domains

Supported by CISSP, CCSP, CGRC, PMP, CSM, and Associate C|CISO

  • ClearanceDetails on request
  • DoW RMFATOs
  • SOC 2Program Initiation/Delivery
  • CMMCProgram Initiation/Delivery
  • FedRAMPProgram Initiation/Delivery
  • AIGovernance/Solution Dev
  • Commercial AI GovernanceAdvisory/Delivery

Note: DoW (Department of War) is the restored executive title authorized by Executive Order 14347 (September 2025). Statutory references to DoD (Department of Defense) remain controlling until changed by law.

Current Role

  • Founder

    Independent Advisory PracticeAI governance, cybersecurity compliance, and applied AI delivery across FedRAMP, DoW RMF, SOC 2, and CMMC

  • Senior Cybersecurity Compliance Expert

    OnebriefFedRAMP High authorization & compliance

Contact

Start an inquiry.

Tell me what you're building, where the risk is, and what the authorization or delivery timeline looks like. I'll respond directly.

Also find me on