Insight.

Two things I built, and what I am working through in public. The framework is the method; SurvAIable is how an engagement finds its starting point; the posts are the thinking before either one is finished.

SurvAIable

A secure, AI-driven survey and analytics platform that gathers structured, role-based input from across an organization and turns it into a clear, defensible picture of how AI is actually being used — formally and informally — where it creates exposure, and where it could create value. Simple for the people answering. Strategic for the people reading.

A governance policy written from assumptions governs an organization that does not exist. This is how I find out what actually exists.

SurvAIable
Administrator Dashboard
  • AI usage trends by role and function
  • Perceived benefits and risks of AI tools
  • Organizational readiness for adoption
  • Priority areas for investment or controls
01

Policy Grounded in Reality

Responses reveal which AI tools are in use, sanctioned or not. That becomes a tailored AI governance policy and acceptable use policy built on real behavior rather than assumptions — addressing risk, compliance, and security while fitting how the organization actually operates.

02

Opportunity, Not Only Risk

The same instrument captures friction, inefficiency, and unmet need — surfacing high-impact automation candidates, the places employees are already experimenting, and the processes best suited for AI augmentation.

Confidential by Design

Participants enter through a shared credential, so no response is personally identifiable and everything is analyzed in aggregate. Results reach authorized administrators only. Candor is a design requirement, not a hope.

The Black Lion Integrated
AI Framework™

I do not sell policies. I sell an operating model. Six layers, built so each one produces the evidence the layer above it needs — board strategy at the top, the control an engineer runs on a Tuesday at the bottom.

01Strategy
02Governance
03Legal & Regulatory
04Information Governance
05AI Security
06Operations
The CrosswalkSignature Asset
Governance TopicISO 42001NIST AI RMFISO 27001EU AI ActTRAIGAPolicy
Human OversightGOVERNAI-HO-001
AI Risk AssessmentMAPAI-RISK-001
Third-Party AIGOVERNAI-VENDOR-001
Incident ResponseMANAGEAI-IR-001

One obligation, traced across every framework that governs it, ending in the policy your organization actually adopts. This is what turns overlapping standards into a single defensible system.

What I'm Talking About Right Now.

in
This week
Where your data lives in AI: the prompt boundary.
What actually leaves your environment when an employee pastes a contract into a chat window — and which contract terms govern it once it does.
Read on LinkedIn →
in
Two weeks ago
Vendor risk is the AI risk most programs miss.
Your model supply chain is someone else's roadmap. What diligence, contract terms, and oversight should look like before the tool is already in production.
Read on LinkedIn →
in
Three weeks ago
Policy is not a program.
A signed AI policy proves intent. Evidence proves governance. The workflows, records, and human-oversight steps that turn principles into something auditable.
Read on LinkedIn →

Start Now — Protect Your Customers and Your Organization.

You do not need a finished program to begin. Governance can start with what you already have today — policies, contracts, and workflows. Let's build a plan that reduces risk, protects the people who trust you with their data, and accelerates responsible innovation.

Telephone
(877) AI-CAIO-1
877-242-2461
Email
rick@sanchize.com
Engagements
Flexible models to fit your needs