Retainer Monthly Cadence Post-Engagement

Stay audit-ready after the initial engagement

The GovernIQ Continuous Monitoring retainer keeps your AI compliance posture current against a regulatory landscape that does not stop changing. We watch for framework drift, model inventory changes, new disclosure obligations, and vendor changes — and flag the signals that matter to your named compliance lead on a monthly cadence. Stacks on top of your $299 Compliance Action Plan or any Standard multi-framework engagement.

Create a workspace → Guided intake → See Tier Context at /Pricing

Stacks on a $299 Compliance Action Plan · Monthly retainer · Cancel anytime (after 12-mo minimum)

TL;DR — Three Things You Should Know
What We Monitor

The four signal classes the retainer tracks

Every signal the retainer fires maps to one of four classes. They run on the same monthly cadence (and ad-hoc High-severity alerts fire outside the cadence) but the evidence collected and the brief delivered differ per class.

Framework Drift

Regulator publications, guidance updates, and amendments

New Colorado AG guidance, NIST AI RMF revisions, EU AI Act implementing regulations, ISO/IEC 42001 amendments, FTC enforcement actions, and state-level AI bills. Each detected change is mapped against the obligations listed in your CAP and scored High / Medium / Low against your actual AI footprint.

Evidence: Regulator URL, publication date, relevant article/section, mapping to the CAP obligations affected.

Model Inventory Changes

New deployments, retirements, and material modifications

Detected against your documented AI system inventory. A new in-scope system without an inventory entry is itself a compliance event under Colorado SB 26-189's pre-deployment impact assessment obligation. Substantial-modification triggers (a vendor model major-version bump, a routing change, a new deployment surface) flag a 90-day re-assessment under your existing CAP.

Evidence: Inventory diff log, affected system's last impact assessment date, freshness against the 90-day rule.

New Disclosure Obligations

Consumer-disclosure rule changes, transparency obligations, and labeling requirements

Colorado Department of Law guidance, EU AI Act Article 50 implementing rules, state-level deepfake / synthetic-content laws, and any new federal mandate. Each detected disclosure change is paired with the disclosure-template delta you'd need to publish — and a re-write of the disclosure section in your existing CAP.

Evidence: Disclosure-rule source, effective date, plain-language delta for your existing disclosure templates.

Vendor Changes

Vendor model updates, security incidents, contractible drift, and developer changes

We monitor public vendor changelogs, security advisories, foundation-lab announcements, and vendor M&A signals. A material vendor model update triggers a 90-day re-assessment of the affected system; a vendor security incident triggers a same-day review of your data-flow exposure. Vendor change of ownership or developer changes trigger an updated vendor-management brief.

Evidence: Vendor change source, affected model-version, re-assessment trigger evaluation, contractible-drift recommendation.

How It Works

Monthly cadence and deliverable types

The retainer runs on a deterministic monthly rhythm. Each month is the same four-week shape; the briefs and reports reflect what was detected in that month. High-severity signals fire ad-hoc outside the cadence.

Monthly cadence

Week 1
Inventory sweep. Refresh against external sources — regulator publications, vendor changelogs, NIST AI RMF updates — and produce a diff against your existing CAP.
Week 2
Impact-assessment refreshes. For each in-scope system whose score drifted above the threshold (vendor change, regulatory change, internal incident), queue a targeted impact-assessment refresh.
Week 3
Vendor delta. Compare your active vendor list against the latest vendor model-version disclosures. Flag any vendor model-version bump, security advisory, or contractible-drift signal.
Week 4
Compliance-lead briefing. Written brief delivered to your named compliance lead with all signals flagged in the prior month — severity, recommendation, and link to the evidence record.

Deliverable types

Monthly Monitoring Report
A written brief covering the month's signal inventory, inventory diffs, and any new framework amendments detected. Delivered Week 4 to your compliance lead.
Ad-hoc Signal Alert
For High-severity signals (regulator action, vendor incident, material model update). Delivered within 48–72 hours of detection, outside the monthly cadence.
Quarterly Board Summary
A consolidation of the previous three months — signal rollup, framework-amendment log, and recommended next-quarter areas for the audit committee. Suitable for board / audit-committee packages.
Annual Re-attestation Package
Signed artifacts suitable for use in a SOC 2 audit, regulator inquiry, or material-customer diligence questionnaire. Replaces the previous year's monitoring artifacts.
Example Signals

What a monthly brief actually looks like

These are the kinds of signals the retainer fires and the brief bodies they produce. Each is the worked example of one of the four signal classes above.

Regulatory · High
New Colorado SB 26-189 amendment detected → flagged to your compliance lead within 48h; disclosure-template delta queued for Week 2 refresh.
Vendor · High
Vendor X shipped model v3.2 with a known regression on protected-class F1 → flagged + impact-assessment refresh queued within 90-day trigger window.
Regulatory · Medium
EU AI Act Article 50 implementation guidance updated → disclosure language delta delivered for review; your existing disclosure template reverse-mapped to the new text.
Inventory · Medium
New in-scope system detected (internally-built screening tool added since last CAP) → pre-deployment impact assessment obligation triggered; engagement for CAP refresh recommended.
Vendor · Medium
Foundation-lab changed developer for your deployed model (acquired by Vendor Y) → vendor-management brief delivered; contractible-drift recommendation queued.
Regulatory · Low
NIST AI RMF companion publication revision detected → no immediate impact on your current CAP; logged for inclusion in next quarter's Board Summary.
Frequently Asked Questions

Continuous monitoring — the questions we hear most

What is Continuous Compliance Monitoring?
Continuous Compliance Monitoring is the GovernIQ retainer tier that runs after the initial engagement (Foundation, Standard, or Concierge). It is a monthly-cadence service: tracking framework drift, monitoring changes to your AI model inventory, detecting new disclosure obligations as regulators publish guidance, and reviewing your vendor rosters for material changes. When a signal fires, your named compliance lead gets a documented brief within 48–72 hours. The retainer stacks on top of a $299 Compliance Action Plan or a Standard multi-framework engagement.
Who needs continuous monitoring?
Any mid-market company that has shipped an initial AI compliance engagement and now needs to keep that posture current against a regulatory landscape that changes every quarter. Continuous monitoring is the natural next step for financial advisory firms with model-portfolio AI, law firms using AI for document review, healthcare practices with AI-assisted scheduling, and SaaS companies shipping AI features into EU or Colorado contexts. If you are liable under Colorado SB 26-189's 90-day reporting trigger or the EU AI Act's post-market monitoring obligation (Article 72), the cadence is a regulator-facing requirement — not a best practice.
What cadence does the retainer run on?
Monthly. Each month follows a four-week rhythm: Week 1 inventory sweep against external sources; Week 2 targeted impact-assessment refresh for any system whose score drifted above the threshold from the original CAP; Week 3 vendor delta against the latest vendor model-version disclosures; Week 4 compliance-lead briefing — a written brief delivered to your named compliance lead with all signals flagged in the prior month. Ad-hoc signal alerts fire outside the monthly cadence when a regulator action, vendor incident, or material model update is detected.
What deliverables are produced each month?
Four deliverable types: (1) Monthly Monitoring Report — written brief covering the month's signal inventory, inventory diffs, and any new framework amendments detected; (2) Ad-hoc Signal Alerts — High-severity signals delivered within 48–72 hours of detection, outside the monthly cadence; (3) Quarterly Board Summary — consolidation of the previous three months, suitable for inclusion in a board or audit-committee package; (4) Annual Re-attestation Package — signed artifacts suitable for use in a SOC 2 audit, regulator inquiry, or material-customer diligence questionnaire.
What alert channels are available?
Three alert channels: (1) email to your named compliance lead and backup contact, with severity (High / Medium / Low) and recommended action in the subject line; (2) a shared Signals dashboard — a read-only URL maintained by GovernIQ that reflects the same signal inventory as the monthly report; (3) Slack-channel delivery, available on the Standard retainer and above, posts into a designated channel in your Slack workspace with the signal brief inline. The recommended default for most SMB retainers is email + dashboard.
How does the retainer stack against the Standard engagement?
The Standard engagement is a one-time, 4–6 week project that produces your Compliance Action Plan, your per-framework policy templates, and your monitoring instrumentation plan. The retainer runs after the Standard engagement completes. It does not redo the audit; it keeps the audit's outputs current. Once a quarter, the retainer triggers an impact-assessment refresh on systems that have drifted; once a year, it produces a full re-attestation package. The retainer is not a replacement for the initial engagement — a retainer without an initial CAP does not have a baseline posture to monitor against.
What is the minimum commitment and what are the exit terms?
The retainer is structured as a 12-month engagement with monthly billing, mirroring the Concierge tier's structure. You can exit at any month boundary after the 12-month minimum by giving 30 days' written notice — there is no auto-renew. If you exit mid-cycle, you receive the Monthly Monitoring Report for the partial month regardless. The deliverables you received during the retainer (Reports, Signal Alerts, Quarterly Board Summaries, the Annual Re-attestation) are yours to retain and use; you do not lose access to prior artifacts on exit.
What is NOT covered by the retainer?
Three things are explicitly out of scope: (1) legal advice — the retainer produces monitoring briefs and impact-assessment refreshes, not legal opinions; run any binding interpretation of new framework guidance through qualified counsel; (2) vendor-included model retraining or remediation — the retainer flags a vendor model drift; it does not negotiate with the vendor on your behalf or run a remediation project; (3) a re-run of the original assessment — if your AI stack has changed materially (more than three new in-scope systems added), the retainer flags it and recommends re-engagement for a refreshed CAP rather than attempting to fold the new scope into the monitoring cadence.

Keep your initial engagement's outputs current.

The Continuous Monitoring retainer stacks on top of your existing Compliance Action Plan. Free assessment identifies the gaps; the $299 CAP personalizes them; the retainer keeps that posture current against a regulatory landscape that does not stop changing.

Create a workspace → Guided intake → See Tier Context at /Pricing

Free assessment · Initial CAP from $299 · Continuous Monitoring retainer from $1,200/mo (12-mo minimum) · No long-term lock-in