Insight.
Two things I built, and what I am working through in public. The framework is the method; SurvAIable is how an engagement finds its starting point; the posts are the thinking before either one is finished.
SurvAIable
A secure, AI-driven survey and analytics platform that gathers structured, role-based input from across an organization and turns it into a clear, defensible picture of how AI is actually being used — formally and informally — where it creates exposure, and where it could create value. Simple for the people answering. Strategic for the people reading.
A governance policy written from assumptions governs an organization that does not exist. This is how I find out what actually exists.
- AI usage trends by role and function
- Perceived benefits and risks of AI tools
- Organizational readiness for adoption
- Priority areas for investment or controls
Policy Grounded in Reality
Responses reveal which AI tools are in use, sanctioned or not. That becomes a tailored AI governance policy and acceptable use policy built on real behavior rather than assumptions — addressing risk, compliance, and security while fitting how the organization actually operates.
Opportunity, Not Only Risk
The same instrument captures friction, inefficiency, and unmet need — surfacing high-impact automation candidates, the places employees are already experimenting, and the processes best suited for AI augmentation.
Confidential by Design
Participants enter through a shared credential, so no response is personally identifiable and everything is analyzed in aggregate. Results reach authorized administrators only. Candor is a design requirement, not a hope.
The Black Lion Integrated
AI Framework™
I do not sell policies. I sell an operating model. Six layers, built so each one produces the evidence the layer above it needs — board strategy at the top, the control an engineer runs on a Tuesday at the bottom.
| Governance Topic | ISO 42001 | NIST AI RMF | ISO 27001 | EU AI Act | TRAIGA | Policy |
|---|---|---|---|---|---|---|
| Human Oversight | ✓ | GOVERN | — | ✓ | ✓ | AI-HO-001 |
| AI Risk Assessment | ✓ | MAP | ✓ | ✓ | ✓ | AI-RISK-001 |
| Third-Party AI | ✓ | GOVERN | ✓ | ✓ | ✓ | AI-VENDOR-001 |
| Incident Response | ✓ | MANAGE | ✓ | ✓ | ✓ | AI-IR-001 |
One obligation, traced across every framework that governs it, ending in the policy your organization actually adopts. This is what turns overlapping standards into a single defensible system.