Our Services

AI Governance, Built for the Audit Table.

Practical AI governance for hospitals, biotech, health tech, and pharma: audit-ready evidence you can defend, not just a framework on a shelf.

How We Help

One Partner. Every Stage of AI Governance.

From a first readiness check to a certified AI Management System, Primas-One meets your organization wherever it is today, and stays with you as your AI use grows.

Why Now

The Ground These Services Are Built For.

The regulatory environment around AI in healthcare has moved from guidance to enforceable obligation. These are the dates and numbers a board is being asked about.

Aug 2026 The EU AI Act's high-risk obligations take full effect
$7.42M Average cost of a healthcare data breach (2025)
~75% Of AI-enabled medical devices sit in the EU AI Act's high-risk tier
15 days To report a serious AI incident once high-risk rules apply
The Core Catalog

4 Services. 1 Continuous Program, or 4 Standalone Engagements.

This is what you actually buy from Primas-One. Each one stands on its own; run in sequence, they take you from "we don't know our AI exposure" to a certifiable AI Management System.

Where every engagement starts: a clear map, not a sales pitch.

A structured diagnostic of every AI system you run, build, or buy, mapped against the frameworks that actually apply to you (EU AI Act, FDA, HIPAA, GxP, or the WHO principles, depending on your sector) and scored against ISO/IEC 42001.

Includes
  • Full inventory of AI systems in use, in development, or embedded in vendor products
  • Regulatory exposure mapping specific to your sector and footprint
  • Scored gap analysis against ISO/IEC 42001
  • A prioritized, time-boxed roadmap, with no multi-year commitment attached

Outcome. A written readiness report and roadmap you can act on immediately, whether or not you engage us further.

Start with this engagement

System by system, not one blanket judgment call.

A deep-dive risk and bias assessment of each individual algorithm or model: the level of specificity regulators and auditors expect, and the level a generic "AI audit" rarely delivers.

Includes
  • Per-system bias and fairness testing against real-world and training data
  • Data lineage and provenance review
  • Risk-tier classification aligned to NIST AI RMF, ISO42001, EU AI Act categories and sector standards
  • Audit-ready documentation: model cards, technical files, risk registers

Outcome. A defensible, documented risk position for every AI system you run: the evidence regulators and auditors ask for first.

Start with this engagement

Governance that keeps working after the report is filed.

The operational layer that turns a one-time assessment into a living program: ownership, controls, and monitoring that catch problems while they are still small.

Includes
  • Incident response plans engineered to navigate overlapping global regulatory reporting windows, ranging from the immediate multi-hour requirements of NIS2 and DORA to the EU AI Act’s 15-day reporting duty and the continuous risk management protocols of the NIST AI RMF.
  • Post-market surveillance and model-drift monitoring
  • Vendor and third-party AI risk oversight

Outcome. A living risk-management program, not a binder that goes stale the week after it is delivered.

Start with this engagement

The credential that turns "we take this seriously" into something you can prove.

Full design and build-out of a certifiable AI Management System (AIMS), the same standard that is becoming a procurement gate in enterprise and health-system RFPs, the way ISO 27001 did for security.

Includes
  • Full AIMS built to ISO/IEC 42001 clause requirements
  • Policies, procedures, and defined roles and responsibilities
  • Internal audit program and pre-certification mock audit
  • Certification-body liaison through to audit day

Outcome. A certification-ready AI Management System, and for organizations that pursue it, a globally recognized ISO/IEC 42001 certificate.

Start with this engagement

Most clients run all four in sequence over one continuous engagement. Every one is also available on its own: start wherever your organization actually is today.

Specialized & Extended Services

9 Ways to Go Deeper on Any of the 4.

Not a separate product line: the specialized work that plugs into a Readiness Assessment, Risk Assessment, Risk Management program, or ISO/IEC 42001 implementation once your sector or situation calls for it.

Assess Deeper

Structured, recurring assessments that go beyond a one-time review.

  • AI Risk, Bias & Safety Audits Pre-deployment and post-market audits of clinical and operational algorithms, run as a standing program rather than a one-off review.
  • Algorithmic Impact Assessments & Health-Equity Testing Structured assessments of how an AI system affects patients or beneficiaries, with explicit bias and equity testing: the evidence WHO-aligned donors and boards look for.

Document & Comply

The living documentation and regulatory mapping auditors and regulators expect.

  • Regulatory Mapping & Compliance Programs A living map of every obligation that applies to you across the EU AI Act, FDA AI/ML-SaMD rules (including PCCPs), HIPAA/HITECH, GDPR, and the NIST AI RMF, kept current as the rules change.
  • AI Governance Policy & Technical-File Authoring Model cards, technical files, and governance policy written to survive an actual audit, regulator inquiry, or acquirer’s data room.

Respond & Train

The people and processes that keep a program running once it is built.

  • AI Incident Response & Post-Market Surveillance Standing incident-response plans and ongoing monitoring built to the EU AI Act's 15-day serious-incident reporting duty, so the plan exists before you need it.
  • Executive & Board AI Governance Advisory & Training Board-level briefings and role-specific AI-literacy training, an obligation under the EU AI Act since February 2025, not just good practice.

Extend Trust

Governance work that reaches beyond your own walls, to vendors, investors, and partners.

  • Third-Party & Vendor AI Risk Management Due-diligence frameworks for the AI you buy, because a vendor's compliance claim doesn't discharge your own duties as a deployer.
  • AI Readiness Due Diligence (Funding, M&A & Grants) Governance-readiness packages built for investor diligence, acquisition review, and donor or grant compliance audits.
  • GxP-Aligned AI Validation (Pharma & Biotech) GAMP 5, risk-based validation of AI used in trials, pharmacovigilance, and regulatory submissions, built for inspection.
Why Primas-One

Built at an Intersection Few Firms Occupy.

Clinical fluency, not borrowed vocabulary

Our team has spent ten years inside CDC- and USAID-funded health-program implementation. We know what a clinical workflow actually looks like, not just what a framework says it should.

Formal AI management-system training

ISO/IEC 42001 Lead Implementer certification means we build management systems designed to pass certification audits, not just internal reviews.

Cybersecurity and GRC discipline

Our co-founder's background in cybersecurity and Governance, Risk & Compliance means the technical and security controls under your program are as rigorous as the policy layer on top of them.

1 team, not a handoff

Most firms are either cybersecurity specialists with no clinical fluency, or clinical consultants with no formal AI-governance credential. You get both, from one engagement, speaking the same language to your board.

How We Work

5 Stages. A Scoped Start, Not a Multi-Year Contract.

Every engagement is scoped against your actual AI footprint before you commit, and you can stop after any stage.

01

Assess

Inventory every AI system in use, classify risk, and map current-state gaps against ISO/IEC 42001, the EU AI Act, FDA, HIPAA, and WHO expectations relevant to you.

02

Design

Design the governance structure, policies, and documentation set your organization needs, sized to your team, not a generic template.

03

Implement

Stand up the AI Management System: risk registers, model cards, technical files, incident-response plans, and training.

04

Certify-Ready

Prepare for ISO/IEC 42001 certification audit or the equivalent regulatory review: evidence organized, gaps closed, team rehearsed.

05

Monitor

Ongoing post-market surveillance, incident-response readiness, and board reporting, so governance stays current as your AI use grows.

The Real Comparison

Where This Leaves You: With a Program and Without One.

Every line on the left is drawn from enforcement actions, litigation, and breach-cost data already on the record in 2025–2026.

Without a governance program
  • Risk analyses for AI tools stay informal or missing: the gap most often cited in regulator findings.
  • Exposure under the EU AI Act's high-risk penalties, up to €15M or 3% of global turnover, sits unquantified.
  • The average healthcare data breach now runs $7.42M before litigation or patient attrition are counted.
  • Funding rounds, acquisitions, and grant renewals can stall on AI-governance gaps found in diligence.
With Primas-One
  • A documented, defensible risk analysis and AI Management System: the discipline regulators point to.
  • A scoped readiness assessment as the starting point, not a multi-year retainer.
  • Certification-ready documentation that turns intent into a verifiable, board-reportable position.
  • A governance file that speeds diligence, audits, and renewals instead of raising new questions.
Beyond Healthcare

Built for Healthcare. It Travels.

The same logic (high-risk AI classification, non-delegable deployer duties, board-level AI literacy, and audit-ready documentation) applies wherever AI touches regulated decisions about people. Financial services, insurance, and critical-infrastructure and public-sector organizations face the same EU AI Act deployer obligations and the same reasonable-care standard under frameworks like the NIST AI RMF.

Our methodology was built in one of the most tightly regulated, highest-stakes environments there is. Healthcare remains where we go deepest, and where our team's clinical and public-health background gives us an edge a generalist firm can't match.

Financial services Insurance Critical infrastructure Public sector
Questions We Get

From the People Who'll Actually Sign Off on This.

A vendor's compliance claim covers the vendor's obligations, not yours. Under the EU AI Act and emerging U.S. state law, the organization that deploys an AI system carries its own, non-transferable duties: risk analysis, human oversight, incident reporting, and record-keeping. Our work builds the evidence that those duties are being met on your side.

A security audit asks whether your systems are protected. AI governance asks whether the decisions an AI system influences are safe, fair, documented, and accountable, and whether you can demonstrate that to a regulator, an auditor, or a court. The two overlap on controls, but the frameworks, evidence, and reviewers are different.

It depends on how many AI systems you run and how much governance already exists. A readiness assessment is measured in weeks; a full AI Management System build to certification readiness is typically a few months. We scope it against your actual footprint before you commit, and you can stop after any engagement.

Yes. Our methodology was built for multi-jurisdiction health and global-health programs, and ISO/IEC 42001 is an international standard by design. Where a program spans many countries with uneven local law, we build one governance framework that travels and note the local requirements it has to satisfy.

No one can. What a governance program does is put the evidence regulators and courts ask for first: a documented risk analysis, clear ownership, human oversight, and an incident process, on the record before you need it. That is the difference between demonstrating reasonable care and improvising it.

No. Every engagement is scoped to the team you have. For smaller organizations we right-size the readiness assessment and the risk work so it runs without pulling people off their day jobs, and we build documentation that a lean team can actually keep current.

Ready to Govern Your AI With Confidence?

Whether you are preparing for AI regulation, assessing an existing AI system, implementing ISO/IEC 42001, strengthening cybersecurity, or building an enterprise AI governance program, Primas-One can help you take the next step with confidence.

Book a Consultation
Chat with us