Jesse isn't taking new orders for this project right now. Here are some similar projects to explore.

You will get AI Governance Gap Assessment with Compliance Roadmap

Jesse H.Status: Offline
Jesse H. Jesse H.
5.0
Top Rated

Let a pro handle the details

Buy Other Consulting & HR services from Jesse, priced and ready to go.
Jesse H.Status: Offline
Jesse H. Jesse H.
5.0
Top Rated

Let a pro handle the details

Buy Other Consulting & HR services from Jesse, priced and ready to go.

Project details

Not sure where you stand with AI regulations? I'll tell you exactly where the gaps are and what to fix first.
I deliver a clear gap assessment against the frameworks that matter to your business. EU AI Act, ISO 42001, NIST AI RMF, GDPR, and others depending on your industry and geography.
What you get:

Gap matrix showing exactly where you're compliant and where you're not
Risk ratings so you know what's urgent vs. what can wait
Executive summary your leadership can actually read
Prioritized remediation roadmap with realistic timelines

I've spent 27 years in IT compliance across Fortune 500 pharma and biotech companies including Pfizer, Novartis, and Gilead. I've been through FDA audits, Consent Decrees, and regulatory actions. I know what auditors look for and how to close gaps before they become findings.
The process is simple. You fill out a short intake form describing your system, the data it handles, and what documentation you already have. I analyze it against your applicable frameworks and deliver a prioritized action plan.
No fluff. No 50-page reports that sit on a shelf. Just clear findings and a roadmap you can execute.
Project Type
Business Consulting

What's included $299

These options are included with the project scope.

$299
  • Delivery Time 3 days
  • Number of Revisions 1
Optional add-ons You can add these on the next page.
Additional Revision
+$99
30-min Consultation Call
+$75

Frequently asked questions

5.0
11 reviews
100% Complete
1% Complete
(0)
1% Complete
(0)
1% Complete
(0)
1% Complete
(0)

EB

Edward B.
5.00
Jun 10, 2026
AI Governance & Controls Specialist Needed for Independent Framework Alignment Assessment

YH

Yekeh H.
5.00
May 26, 2026
US Federal Proposal Manager (AI Enabled)

DB

David B.
5.00
May 7, 2026
HIPAA compliance Review One of the best freelancers I've hired her on Upwork. Strongly recommend Jesse!

KS

Karl S.
5.00
Apr 2, 2026
NIST AI Risk Management Framework Implementation Jesse is an expert in his field. I enjoyed working with him. He is very detailed and does his best to make sure that you are comfortable with his implementation approach. I enjoyed working with him and surely we will work together in the future.

MV

Mike V.
5.00
Feb 12, 2026
Data Privacy Consultant for AI Company (familiar with both GDPR and U.S. state privacy laws) Jesse was amazing. He is knowledgeable and a great communicator. I highly recommend him
Jesse H.Status: Offline

About Jesse

Jesse H.Status: Offline
ISO 9001/27001/42001 HIPAA/GDPR | Policies & Audits | AI Governance
100% Job Success
5.0  (11 reviews)
Houston, United States - 10:46 pm local time
Here's the complete overview with everything integrated — regulation-first opening, REMVER fully gone, fintech resilience built in generically, current high-level work led up front, three books, no speed claims:
Get your application ISO 27001 certified, HIPAA compliant, GDPR ready, or FDA defensible. I write the policies, procedures, and compliance frameworks that regulated companies need to pass audits and launch. GDPR. HIPAA. ISO 9001. ISO 27001. FDA 21 CFR Part 11. A lot of the applications I work on use AI, so when it is in the stack I handle it correctly, layering in governance frameworks, privacy policies, and purpose-built agents trained on domain knowledge, not generic demos. 27 years in regulated industries. 300+ templates. Faster than traditional consulting using my trademarked AAIG methodology.
I am not a consultant who says "no." I find the "yes, if we do it this way" path that lets you move fast and stay compliant.
WHAT I BUILD
Policies, Procedures, and Quality Management. SOPs, quality manuals, work instructions, and complete QMS builds. ISO 9001/27001/42001 from gap assessment through certification readiness. Audit preparation, corrective action workflows, and management review packages. Rebuilt an entire QMS for a global clinical trials platform, zero audit findings.
Privacy Policies, Terms of Service, and Legal Compliance Documents. GDPR-compliant privacy policies, terms of service, cookie policies, data processing agreements, sub-processor agreements, consent frameworks, and data subject rights implementation. Fixed 7 live GDPR violations for an AI meeting platform. Built Django deletion workflows for right-to-erasure compliance. Global consent matrices covering US, EU, Canada, and Asia-Pacific.
Financial Services and Operational Resilience. Business continuity and IT disaster recovery frameworks for U.S. financial institutions. Operational resilience programs aligned with OCC, FDIC, FRB, and FFIEC guidance. SR 11-7 model risk status assessments. Regulatory framework mapping for banking and fintech compliance.
AI Compliance and Risk Frameworks. EU AI Act roadmaps. ISO 42001. NIST AI RMF. HIPAA Security Risk Analyses. Privacy impact assessments for GDPR, CCPA, and Colorado AI Act. GxP validation and 21 CFR Part 11 compliance for healthcare AI.
AI-Powered Product Development. Purpose-built AI agents and document-drafting suites trained on domain-specific regulatory knowledge, with proprietary multi-section architectures spanning 32+ regulatory frameworks and enterprise-grade quality gates. Agent suites built to replace $50K-$500K/year software platforms.
Content, Courses, and Books. Three published books on AI governance. 48,000-word KDP reference book. 12 Udemy courses with slide decks and speaker notes. Synthesia video content. Full enablement ecosystem, not just the framework.
CURRENT AND RECENT WORK
National AI Governance Framework. Developed the AI Governance Framework for the Republic of Liberia, integrating NIST AI RMF, OECD, UNESCO, EU AI Act, and African Union standards. Government-level deployment with training packages, implementation roadmaps, and stakeholder consultation.
Multi-Entity Financial Services Governance. Regulatory gap assessment and phased remediation program for a multi-entity fintech group, delivered through outside counsel. 35 findings across 10 governance domains, mapped to 13 frameworks and a multi-state applicability survey.
Enterprise Governance Platform Advisory. Independent strategic advisory to a governance and assurance platform on enterprise category positioning, adoption, and certification pathway, working with the executive team and board.
ISO 27001 Certification Program. Full certification preparation for a medical diagnostics software platform. Gap assessment, a fourteen-document ISMS, and a tiered implementation register from current state to audit readiness.
FDA Quality System Reconstruction. Design History File and ISO 14971 Risk Management File rebuilt from source for a medical device manufacturer under an active FDA commitment timeline, with an independent internal audit.
GDPR Controller Determination. Corrected a controller-versus-processor misclassification for an AI clinical platform under GDPR Article 4(8), reassigning data protection obligations to the right party.
THE FOUNDATION
27 years in regulated industries. Fortune 500: Alcon/Novartis (8 years, 200+ projects), Gilead, Genzyme, Pfizer, Baxter. Zero audit findings. Consent decree and FDA regulatory action leadership. MS Operations and Project Management. PMP certified 20 years. Contributing author, The FDA Group Newsletter (10,000+ executives). Published author of three books on AI governance.
300+ templates covering EU AI Act, ISO 42001, NIST AI RMF, ISO 27001, GDPR, CCPA, HIPAA, FDA 21 CFR Part 11, and Colorado AI Act. Every template refined through Fortune 500 implementations and delivered through 10-20+ iterations before handoff.
WHO HIRES ME
Companies needing SOPs, quality manuals,

Steps for completing your project

After purchasing the project, send requirements so Jesse can start the project.

Delivery time starts when Jesse receives requirements from you.

Jesse works on your project following the steps below.

Revisions may occur after the delivery date.

Intake and Scoping

Review your system details, data types, and geographic footprint to identify applicable frameworks like EU AI Act, ISO 42001, NIST AI RMF, GDPR, and others.

Gap Analysis

Assess your current state against applicable frameworks. Identify and categorize gaps by severity and effort to remediate.

Review the work, release payment, and leave feedback to Jesse.