Governance Readiness Score
FreeA five-minute self-audit that returns a graded readiness score, the specific rules your current setup breaks, and a shareable PDF report. The most honest version of “where do we actually stand?” you can run today.
Your attorneys, CPAs, advisors, or producers are already using ChatGPT. Your governance platform options were built for Fortune 500 security teams with 200-seat minimums. Oathmark closes that gap — for firms with 10 to 500 people, referencing the authorities that actually govern your practice: ABA Model Rules and state bar opinions for law firms, IRS Circular 230 and AICPA SSTS for accounting and tax firms, FINRA/SEC/NASAA guidance for advisory practices, and NAIC/state insurance bulletins (which speak to insurers, and reach agencies through carrier-contract pass-through) for insurance agencies.
Four steps, no black box, no IT department required.
Find every AI tool actually in use across the firm — not just the ones IT approved.
A structured, rules-based self-assessment score — a working starting point, not an audit or attestation.
Findings cite the relevant bar rules, FINRA/SEC/NASAA guidance, and NAIC/state insurance bulletins in plain English so you know what to check next.
Escalate to a paid tier — Discovery Scan, Policy Kit, or Attorney Governance Review — when you need a dated, client- or carrier-shareable governance record, or an attorney-signed report from the independent law firm delivering Attorney-Led Packages under a separate engagement letter.
Answer a few questions about the tools your team actually uses. Get a transparent score, cited flags, and a starter policy checklist — instantly, and entirely in your browser.
This helps us apply the right jurisdictional rules to your results.
Self-report below, or scan your connected Gmail for real sign-up and notification emails from AI vendors — no guessing required.
We search your connected Gmail for genuine welcome, receipt, and notification emails from AI vendors — evidence, not guesswork.
These answers weigh heavily on your final score — governance gaps compound tool-level risk.
Based on your answers — a transparent, rules-based score with cited flags.
Enter your email to save this snapshot to your Oathmark record and unlock a downloadable PDF copy for your files.
This free check is a self-assessment snapshot. To close the gaps it surfaced, pick the tier that matches where you are:
Attorney-Led Packages are delivered by an independent law firm under a separate engagement letter. Oathmark is not a law firm.
Carriers are adding AI-specific questions to renewal applications. Here's what your answers are ready to export — and what's still a gap.
The Insurance Renewal Package formats these answers for your malpractice and cyber/E&O insurance carriers' AI supplemental questionnaires — dated and ready to attach to your renewal application.
Billed at $500/yr, auto-renewing annually so your documentation is refreshed every renewal cycle. Cancel anytime before your next renewal.
This self-assessment is for general informational purposes. It is not legal advice and does not replace a jurisdiction-specific ethics review.
Credo AI, Holistic AI, OneTrust, Harmonic Security, and Vanta all sell to CISOs. Nobody references your bar rules, your FINRA/SEC/NASAA obligations, or the NAIC/state insurance bulletins that reach your agency through carrier contracts.
| Enterprise AI governance platforms | Oathmark | |
|---|---|---|
| Buyer | CISO / IT security team | Managing partner / General Counsel / Principal / Agency owner |
| Price | $30,000 – $500,000 / year | $6,000 – $18,000 / year |
| Rules mapped to | NIST, ISO 42001, EU AI Act (generic) | ABA Model Rules & state bar opinions, FINRA/SEC/NASAA guidance, NAIC/state insurance bulletins (via carrier-contract pass-through for agencies), EU AI Act deployer duties, malpractice/E&O-carrier expectations |
| Minimum firm size | 200-seat minimums, typically | Works from 10 employees |
Most firms start with the free score, run continuous monitoring across their devices, and add attorney-led work when a client, regulator, or insurer starts asking questions. You never buy more than you actually need this quarter.
A five-minute self-audit that returns a graded readiness score, the specific rules your current setup breaks, and a shareable PDF report. The most honest version of “where do we actually stand?” you can run today.
A one-time endpoint scan across the browsers your team actually works in. Surfaces shadow AI use — personal ChatGPT logins, unsanctioned Otter installs, unreviewed extensions — that self-report never catches, and delivers a firm-wide inventory report you can circulate internally the same week.
The Discovery Scan turned into an always-on service: a lightweight browser extension across your firm's devices reports newly-detected AI tools into a central dashboard, tracks whose training is current, and refreshes your policy documentation each billing cycle. This is the recurring backbone of the Oathmark program.
100+ employees? Contact us for custom annual pricing ($8,000–$18,000/yr).
Cyber, E&O, and malpractice carriers are adding AI-specific supplemental questionnaires to renewal underwriting. This add-on packages your Continuous Monitor data into the evidence format those carriers ask for: approved tool list, DPA status, training completion, incident-response plan, and a dated, self-reported governance record. Requires an active Tier 3 subscription.
Industry reporting on the trend: The Crossing Report, Chronexa, Traverse Legal.
A complete governance package built for your industry — law firm, accounting firm, registered investment adviser or broker-dealer, or insurance agency — with policies, training modules, and employee acknowledgment templates that reference the rules governing your practice. Authored by the independent law firm delivering Attorney-Led Packages under a separate engagement letter, reviewed quarterly and refreshed when guidance changes materially.
An attorney-led review of your AI environment: a governance assessment based on your Monitor data, custom policy documents tailored to your practice, and specific written recommendations. Delivered as a fixed-fee engagement so you know exactly what you’re getting for exactly what you pay.
Ongoing attorney-led AI governance support: quarterly reviews, policy refreshes as guidance changes, an on-call attorney when an incident or a regulatory inquiry surfaces, and priority handling on Monitor findings. The relationship version of tier 6, for firms treating AI governance as a standing obligation.
Every tier is priced at the firm level, not per seat. Multi-office and 500+ employee engagements are quoted individually — contact us.