AI Governance Toolkit for vCISOs and Consultants
This page is for consultants considering ACT products. Client use and reuse require separately agreed rights recorded in the invoice, order, contract or licence.
The problem this page solves
Advisors lose margin when every AI governance client requires a custom control matrix, policy set, vendor questionnaire, risk register, and board pack from scratch. The opportunity is to productize the repeatable artifact layer while preserving room for expert judgment.
Confirm the rights before client work
Client use, redistribution, consultant reuse and transferable rights are not automatic. Any expanded rights must be separately agreed and explicitly stated in the invoice, order, contract or licence.
Tailor by client maturity
Client use, redistribution, consultant reuse and transferable rights are not automatic. Any expanded rights must be separately agreed and explicitly stated in the invoice, order, contract or licence.
Keep expertise where it matters
Spend billable time on interpretation, facilitation, and decisions instead of formatting first-draft documents.
Decision path for this buyer
Client use, redistribution, consultant reuse and transferable rights are not automatic. Any expanded rights must be separately agreed and explicitly stated in the invoice, order, contract or licence.
| Step | Action | Evidence output |
|---|---|---|
| Day 1 | Agree client-use rights before the engagement. | Written scope and licence. |
| Week 1 | Confirm the required files and client-use scope | Agreed file and rights list |
| Week 2 | Review only files included in the agreed package | Review under the agreed licence |
| Month 1 | Facilitate governance review | Outputs defined in the client engagement |
Which Move78 artifact fits the job?
| Need | Recommended fit | Why |
|---|---|---|
| You need a reusable starter offer | ACT-1 Starter | Client use, redistribution, consultant reuse and transferable rights are not automatic. Any expanded rights must be separately agreed and explicitly stated in the invoice, order, contract or licence. |
| You need implementation-grade delivery assets | ACT-2 Professional | Client use, redistribution, consultant reuse and transferable rights are not automatic. Any expanded rights must be separately agreed and explicitly stated in the invoice, order, contract or licence. |
| You need co-delivery or rollout support | ACT-3 Implementation Sprint | The Sprint requires prior ACT-2 purchase and fit review. Any client engagement or co-delivery terms must be separately agreed. |
Who this is not for
- You want to resell the files without permission or without respecting license terms.
- You need a white-label legal opinion or certification service.
- You expect client implementation without adapting artifacts to context.
- You assume specialist modules or expanded licence rights without checking the order.
Frequently Asked Questions (FAQs)
How can a vCISO or consultant use ACT-2 with clients?
Client use, redistribution, consultant reuse and transferable rights are not automatic. Any expanded rights must be separately agreed and explicitly stated in the invoice, order, contract or licence.
Can consultants resell or white-label the toolkit?
Client use, redistribution, consultant reuse and transferable rights are not automatic. Any expanded rights must be separately agreed and explicitly stated in the invoice, order, contract or licence.
What client problems does this help solve fastest?
Confirm the required evidence records and package contents before considering ACT-2 for a client engagement. No setup-time saving or included module should be assumed from a sample.
Does the toolkit replace consultant expertise?
No. The professional remains responsible for scoping, interpretation, client alignment and delivery quality. Package contents and client-use rights must be confirmed separately.
What should be reviewed before client delivery?
Before client delivery, review the client’s actual AI systems, legal obligations, sector rules, internal control environment, data flows, vendors, and risk appetite. Remove irrelevant fields, add required local obligations, and confirm that every artifact reflects real practice. Client-facing evidence must not look copied, generic, or unreviewed.
Source and review note
This page is based on Move78 product scope and public framework references. It is not legal advice and does not certify compliance.
| Reference | Source |
|---|---|
| EU AI Act | Regulation (EU) 2024/1689 on EUR-Lex |
| ISO/IEC 42001 | ISO/IEC 42001:2023 official ISO page |
| NIST AI RMF | NIST AI Risk Management Framework |
| NIST AI 600-1 | NIST Generative AI Profile |
| OWASP Agentic AI | OWASP Top 10 for Agentic Applications |
| Colorado AI Act | Colorado SB26-189 (ADMT) and Colorado AG rulemaking page |
Published: 2026-04-28. Last updated: 2026-04-28. Last reviewed against official source pages: 2026-04-28.
Source and review note: This page was last reviewed on 6 May 2026 against the current Move78 public site baseline and relevant official or authoritative sources where laws, standards, frameworks, cybersecurity controls, product scope, pricing, support policy, or implementation guidance are discussed. It provides operational implementation guidance and product information only; it is not legal advice, tax advice, audit assurance, certification assurance, conformity-assessment advice, buyer-approval assurance, or security assurance. Validate legal, regulatory, contractual, tax, audit, and security decisions with qualified professionals.