logo - Nomad
AI Governance & Cyber Risk Advisory

Your AI is moving faster than your oversight.

Nomad builds AI and cyber governance for mid-market organizations that carry enterprise obligations without an enterprise compliance function. We build it, then stay while it holds.

Established 2023Certified SBE · WBE · MBEGrapevine, TexasIndustry-agnostic
01

The advisor already in the room

Nomad Cyber Concepts is an AI governance and cyber risk advisory firm founded in 2023 and based in Grapevine, Texas. We work inside your organization rather than across a table from it: in your meetings, on your tools, accountable for the same outcomes your team is.

Our advisors have carried this work in regulated environments and Fortune 100 and 500 environments before. They speak to IT, legal, and the boardroom in the language each one uses, and they say plainly what is enforceable now and what is only direction of travel.

02

Enterprises have compliance departments. You have the same obligations.

AI went into hiring, operations, client analytics and product decisions faster than oversight could keep up. Four things follow from that, and all four land on the same small team.

01

Obligations arrive by law

Texas, California, Colorado, Utah, the EU AI Act and the state wave behind them reach companies of every size. TRAIGA even reaches systems deployed before it took effect.

02

And by contract, sooner

Enterprise customers, insurers and acquirers already ask AI governance questions in vendor reviews, renewals and diligence. Contract arrives before statute.

03

The capability is not in-house

No model risk team, and no appetite to build one. AI risk sits between IT, legal and the business, owned by no one.

04

The work does not end

Models change, vendors change, rules move. A policy written last year cannot answer this year’s regulation or client questionnaire, so governance is a standing requirement rather than a project.

Liability follows the organization that uses the AI, not just the vendor that built it.

In Mobley v. Workday, a federal court allowed a nationwide collective action to proceed over AI-driven hiring screens. “The tool did it” is not a defense.

03

Three practices, one relationship

AI governance · Cyber risk · Professional development

Every engagement is fitted to your needs, targets and budget. Pick a practice to see what that covers.

AI Governance
AI Governance
Cyber Risk & Compliance
Cyber Risk & Compliance
Professional Development
Professional Development

AI Governance

Frameworks, policy, and oversight for the AI already inside your operations. We settle who owns which decision, then build the evidence trail that proves it.

·AI strategy and governance program design
·Policy development and control implementation
·Shadow AI discovery and AI system inventory
·Ongoing regulatory monitoring as rules move
NIST AI RMF · ISO/IEC 42001 · EU AI Act · TRAIGA

Cyber Risk & Compliance

GRC advisory and audit readiness for teams without a compliance function. We find the exposure, then put controls and evidence behind it.

·AI maturity and risk assessments
·AI vendor and third-party risk review
·Ethics, bias and compliance audits
·SOC 2 readiness and audit preparation
SOC 2 · Third-party risk · Ethics and bias audits

Professional Development

Business strategy and enablement, because counsel that never reaches the team does not hold. We teach the people who have to live with the controls.

·AI literacy for staff and leadership
·Board and executive briefings
·Regulatory and ethical AI workshops
·Change management for adoption
Board briefings · Workshops · Change management
04

Still confused about AI governance?

Three ways to say it

The term gets used loosely, so here it is plainly, then in the words of two of the vendors your enterprise customers already rely on.

In plain English
In plain English
IBM says
IBM says
OneTrust says
OneTrust says

It is the rulebook for how your organization uses AI

Governance is how decisions get made, who is accountable for them, and how you prove it later. Applied to AI, it answers three questions any board member, customer or regulator can ask you today.

·What AI is in use here, including the tools staff signed up for on their own
·Who owns each system, who approved it, and against which policy
·How you know it is still behaving, and what happens the day it is not

If you cannot answer those three, you do not have AI governance yet. You have AI.

Where Nomad fits

The definitions agree on what good looks like. The gap for mid-market organizations is that the platforms assume a compliance function you may not have. We build the policy, the inventory, the review gates and the evidence trail, then train your people to run them.

Request an assessment

Guardrails around the tools

“AI governance refers to the guardrails that help ensure AI tools and systems remain safe, ethical and respect human rights.”

·Compliance, so AI decisions line up with regulation and accepted practice
·Trust, so models can be explained and shown to be fair
·Efficiency, so teams build and deploy against one standard instead of improvising

IBM frames those three as the outcomes effective governance delivers.

Source · IBM · What is AI governance?
Where Nomad fits

The definitions agree on what good looks like. The gap for mid-market organizations is that the platforms assume a compliance function you may not have. We build the policy, the inventory, the review gates and the evidence trail, then train your people to run them.

Request an assessment

Controls across the AI lifecycle

“AI governance is the policies, processes, and controls to manage AI risk, performance, and compliance across the AI lifecycle.”

·An inventory of every AI system, with owners, data and risks attached
·Risk assessments before deployment, with human review and sign-off
·Monitoring, incident response, and evidence an auditor will accept

OneTrust describes it as a management framework, not a one-time review.

Source · OneTrust · AI governance glossary
Where Nomad fits

The definitions agree on what good looks like. The gap for mid-market organizations is that the platforms assume a compliance function you may not have. We build the policy, the inventory, the review gates and the evidence trail, then train your people to run them.

Request an assessment
05

How engagements are shaped

Enter anywhere

Most clients start with a conversation or an assessment, then decide how far to go. Nothing here requires committing to a program first.

Start

Find out where you stand

Short, scoped, and useful on its own.

·Introductory call, 30 minutes, no cost
·Cybersecurity readiness assessment
·Policy and procedure review
·Digital risk strategy session
Build

Stand the program up

Scoped to your environment, your team, and your budget.

·AI governance program development
·GRC framework alignment
·Secure infrastructure planning
·Third-party proposal and SOW evaluation
Stay

Keep it holding

For teams that need the program maintained, not handed over.

·Advisory subscription tiers
·Board and executive briefings
·Custom coaching and training
·Speaking engagements
Request an assessmentScoped to your needs, targets and budget
06

Pick where you operate

We tier obligations honestly: what is enforceable now, and what is direction of travel. Select your markets to see which is which.

Texas
Texas
California
California
Colorado
Colorado
Utah
Utah
EU market
EU market
Enterprise customers
Enterprise customers

Nothing selected yet. Most mid-market clients start with Texas, their enterprise customers, or both.

TRAIGA (Texas)
In force · Jan 1, 2026

In force, with penalties up to $200K per violation, and it reaches AI systems that were already deployed before it took effect. There is no grandfather clause to wait behind.

California CPPA ADMT rules
In force · Jan 1, 2026

Automated decision-making technology rules in force alongside TRAIGA, binding companies that make consequential decisions about Californians.

California AI Transparency Act
In force · 2026

Operative this year, adding disclosure duties on top of the ADMT rules for organizations serving the California market.

Utah AI disclosure law
In force · Live since 2024

The earliest of the state laws and a useful precedent: obligations arrived quietly and applied to companies of every size.

EU AI Act, Article 50 transparency
In force · Aug 2, 2026

Transparency obligations in force for AI that interacts with people or generates content, reaching U.S. firms that serve EU markets.

Client, insurer and acquirer questionnaires
In force · Today

Contract arrives before statute. AI governance questions already appear in vendor reviews, renewals and diligence, with NIST AI RMF and ISO/IEC 42001 converging as the evidence baseline.

Colorado ADMT Act
Coming · Dec 2, 2026

Moved from June 2026. Duties for developers and deployers of high-risk AI systems, narrowed but not withdrawn.

EU AI Act, new prohibitions and legacy duties
Coming · Jan 1, 2027

New prohibitions take hold and legacy transparency duties attach to systems already on the market.

EU AI Act, high risk, Annex III
Coming · Dec 2, 2027

Moved from August 2026. The rescheduling reduced none of the obligations, only the date.

EU AI Act, high risk, Annex I
Coming · Aug 2, 2028

Moved from August 2027. Product-embedded high-risk systems come into scope last.

shown · dates as publishedHave us map these against your systems
07

Crawl, walk, run

Three phases, paced to your budget and your people. Most organizations reach a governed program in three to six months. Click a phase.

Crawl
Crawl
Walk
Walk
Run
Run
Phase one

Foundational readiness

We start with a conversation rather than a questionnaire, then agree scope and ownership and find the gaps across security, process, and controls.

·Scope, stakeholders and decision owners agreed
·Gap map across security, process and controls
·Honest tiering of which obligations actually apply
Deliverable · Gap map and roadmap you keep
Not sure where you sit?

Take the readiness check

Six questions, two minutes, and a red, amber or green answer with the gaps we would look at first. Nothing is sent until you decide to send it.

Start the check
What we hold toAccountabilityFairnessTransparencySecurityResilience
Phase two

Control implementation

Policies become formal, controls go in, and evidence collection starts running on its own schedule rather than yours.

·Approved policy set and accountability matrix
·Controls implemented with gating criteria
·Structured evidence collection underway
Deliverable · Operating policy set and control library
Not sure where you sit?

Take the readiness check

Six questions, two minutes, and a red, amber or green answer with the gaps we would look at first. Nothing is sent until you decide to send it.

Start the check
What we hold toAccountabilityFairnessTransparencySecurityResilience
Phase three

Audit and proof readiness

Controls validated, gaps remediated, and your team ready for auditors, clients, and regulators without a scramble.

·Controls validated and gaps remediated
·Evidence ready for auditors and questionnaires
·Monitoring as models, vendors and rules change
Deliverable · Audit-ready program and reporting line
Not sure where you sit?

Take the readiness check

Six questions, two minutes, and a red, amber or green answer with the gaps we would look at first. Nothing is sent until you decide to send it.

Start the check
What we hold toAccountabilityFairnessTransparencySecurityResilience

We tell you what is enforceable now and what is only direction of travel.

Every obligation gets tiered honestly, so your budget goes to the real ones first. You will not hear a deadline from us that we cannot point to in writing.

08

Who leads the work

Nomad is led by Dr. Kimberly “KJ” Haywood, author of Here We Go Again… Except It’s AI: AI Governance from Analysis to Enterprise Action, supported by specialized consultants and executive board advisors across AI governance, cybersecurity, enterprise risk, compliance and business strategy.

AIGP · CRISC · CISA · SCCE · HCCA · CISSP · CCSO · CPA · JD · Ph.D
Meet the team
09

Request an exposure review

A focused review of where your cyber and AI governance posture stands against the obligations enforceable today, with a red, yellow, green picture of what to address first.

No obligation, and you keep the findings either way. We reply within one business day.

Ryan Hughes · VP of Strategic Partnerships

This field is for validation purposes and should be left unchanged.