The GovernIQ Continuous Monitoring retainer keeps your AI compliance posture current against a regulatory landscape that does not stop changing. We watch for framework drift, model inventory changes, new disclosure obligations, and vendor changes — and flag the signals that matter to your named compliance lead on a monthly cadence. Stacks on top of your $299 Compliance Action Plan or any Standard multi-framework engagement.
Stacks on a $299 Compliance Action Plan · Monthly retainer · Cancel anytime (after 12-mo minimum)
Every signal the retainer fires maps to one of four classes. They run on the same monthly cadence (and ad-hoc High-severity alerts fire outside the cadence) but the evidence collected and the brief delivered differ per class.
New Colorado AG guidance, NIST AI RMF revisions, EU AI Act implementing regulations, ISO/IEC 42001 amendments, FTC enforcement actions, and state-level AI bills. Each detected change is mapped against the obligations listed in your CAP and scored High / Medium / Low against your actual AI footprint.
Evidence: Regulator URL, publication date, relevant article/section, mapping to the CAP obligations affected.
Detected against your documented AI system inventory. A new in-scope system without an inventory entry is itself a compliance event under Colorado SB 26-189's pre-deployment impact assessment obligation. Substantial-modification triggers (a vendor model major-version bump, a routing change, a new deployment surface) flag a 90-day re-assessment under your existing CAP.
Evidence: Inventory diff log, affected system's last impact assessment date, freshness against the 90-day rule.
Colorado Department of Law guidance, EU AI Act Article 50 implementing rules, state-level deepfake / synthetic-content laws, and any new federal mandate. Each detected disclosure change is paired with the disclosure-template delta you'd need to publish — and a re-write of the disclosure section in your existing CAP.
Evidence: Disclosure-rule source, effective date, plain-language delta for your existing disclosure templates.
We monitor public vendor changelogs, security advisories, foundation-lab announcements, and vendor M&A signals. A material vendor model update triggers a 90-day re-assessment of the affected system; a vendor security incident triggers a same-day review of your data-flow exposure. Vendor change of ownership or developer changes trigger an updated vendor-management brief.
Evidence: Vendor change source, affected model-version, re-assessment trigger evaluation, contractible-drift recommendation.
The retainer runs on a deterministic monthly rhythm. Each month is the same four-week shape; the briefs and reports reflect what was detected in that month. High-severity signals fire ad-hoc outside the cadence.
These are the kinds of signals the retainer fires and the brief bodies they produce. Each is the worked example of one of the four signal classes above.
The Continuous Monitoring retainer stacks on top of your existing Compliance Action Plan. Free assessment identifies the gaps; the $299 CAP personalizes them; the retainer keeps that posture current against a regulatory landscape that does not stop changing.
Free assessment · Initial CAP from $299 · Continuous Monitoring retainer from $1,200/mo (12-mo minimum) · No long-term lock-in