AI Governance · Risk · Compliance

AI is entering your operations faster than your governance can keep up.

The rules are still being written, and the accountability for every automated decision your tools make is already yours. Aegis Ethos Consulting gives you what you need to adopt AI responsibly and prove it: enterprise-grade oversight for organizations of every kind, practitioner-led, framework-anchored, and right-sized to what you actually run. Its commitment runs from the communities enterprise consultants overlook to any organization that simply wants governance it can trust.

Who we serve

Enterprise-grade governance, at any scale.

AEC's commitment is to the organizations most exposed to AI risk and least served by enterprise consultants, but the door is open to every sector and size. The frameworks are the same whether you're a five-person nonprofit or a regulated institution.

Small and minority-owned businesses

You're adopting AI tools to keep up, often on vendor contracts you didn't have the leverage to negotiate.

  • Hiring, screening, and customer-facing tools.
  • Vendor-contract and liability exposure.
  • A defensible record without a data-science team.

Nonprofits and community organizations

You serve the people most affected by algorithmic harm, and your mission depends on getting this right.

  • Constituent-data privacy and dignity.
  • Grant and funder governance expectations.
  • Fairness screening for smaller pools.

Government and public agencies

Public trust and statutory duty ride on every automated decision your office makes.

  • Automated decision systems in public services.
  • Disparate-impact and civil-rights obligations.
  • Documentation that stands up to review.
Not on this list? AEC works across every sector and size: startups and enterprises, healthcare, education, financial services, and regulated industries. The commitment to the underserved middle is a starting point, never a limit.
Talk to us about your sector
The assessment ladder

Start fast. Go deeper only where it's warranted.

Four assessments, each answering a different question. They're built to work together: start fast, go deeper only where it's warranted, screen a specific tool for fairness, and test readiness before you adopt rather than after.

Recommended start

AI Risk Triage

"Where should we look harder?"

A focused, structured screen of your AI tools against the NIST AI Risk Management Framework (Govern, Map, Measure, Manage) to find where the governance gaps are. You get a written Findings Summary, a plain-language Risk Heat Map, and a clear next step.

Virtual or on-site.

Comprehensive AI Governance Assessment

"What does a full, evidence-based audit find?"

An audit-depth engagement: real outcome data, stakeholder interviews, and vendor documentation, checked against the laws that govern automated decisions, including Title VII of the Civil Rights Act, the Federal Trade Commission Act, the Fair Housing Act, the Equal Credit Opportunity Act, and the European Union AI Act. A root-cause step traces each finding to its source. You get a Governance Risk Report with a remediation roadmap and clear flags for the findings you should take to your own counsel.

Scoped to your organization.

Disparate Impact Standards Assessment

"Does this tool treat groups of people differently?"

A structured evaluation of one specific AI tool (hiring software, tenant screening, credit scoring) against five federal and international standards, each finding mapped to the law it falls under. Calibrated for the smaller pools off-the-shelf tools weren't built for, and honest about when a sample is too small to trust.

Standalone, or bundled into a full assessment.

AI Readiness and Responsibility Assessment

"Can we adopt and sustain AI responsibly before we deploy?"

The forward-looking counterpart to the audit work: not whether your AI use is defensible after the fact, but whether you're positioned to adopt AI well in the first place. It examines culture, capacity, governance design, vendor-contract exposure, and human oversight.

Standalone, or paired with the assessment work.
Interested in any of these? Scope and pricing are set in a short, no-obligation discovery conversation. One starting point for every service.
Schedule a conversation
Governing principles

Principles that hold whether anyone is watching or not.

AEC's work rests on a set of convictions about responsible AI, drawn from risk practice, AI law and policy, and the communities most exposed to algorithmic harm.

01

Governance before adoption

Responsible governance isn't a compliance afterthought. It's the prerequisite for adopting AI at all.

02

Humans own the judgment

AI carries the volume; people carry the judgment. A named human stays accountable for every AI-informed decision.

03

Risk and rights together

A risk lens finds the technical vulnerabilities; a rights lens finds the human ones. Serious work needs both.

04

Look for what's missing

The biggest risks come from who and what is absent from the data, not only from what's in it.

05

Measure fairness, don't assert it

Fairness is tested with real methods, not taken on faith. An absence of alarms is proven, never assumed.

06

Defensibility by design

If a system can't explain why it decided something, it isn't ready to decide it. And safeguards mean something only when tied to real standards.

It reports; it does not advise.

Every AEC instrument observes a firm boundary: it identifies findings that touch a legal standard for you to take to your own counsel. AEC does not provide legal representation, does not issue legal opinions, and does not determine whether any law has been violated.

Renita M. Fisher, Founder and Principal of Aegis Ethos Consulting
Founder and Principal

Renita M. Fisher

Twenty-five years in regulated financial services taught me how to manage risk. My work now is helping organizations manage the risks of artificial intelligence, before those risks reach the people they affect.

I founded Aegis Ethos Consulting to do one thing well: assess how an organization uses AI, and tell them clearly and honestly where the risk actually sits. AI risk is rarely just a technical problem or just a legal one. It's a governance problem. Who is accountable? Is a human genuinely in the loop? Is anyone testing outcomes for fairness? Can the organization sustain responsible use over time? Those are the questions I help answer.

I believe AI should be built and used with human-centered ethics, transparency, and real governance. The human, not the machine, owns the thinking. If your organization is adopting AI and wants a clear-eyed, independent read on the risk, I'd welcome a conversation.

25 years · Financial-services risk and compliance.
Governance, controls, and policy frameworks built against federal and state regulatory mandates for core consumer safeguards, data privacy, accessibility, and fair lending.
Frameworks in practice: the NIST AI Risk Management Framework, the European Union AI Act, Title VII of the Civil Rights Act, the Federal Trade Commission Act, the Fair Housing Act, the Equal Credit Opportunity Act, the Fair Credit Reporting Act, the General Data Protection Regulation, and the California Privacy Rights Act.