AI Governance · Risk · Control

We don't help you adopt AI —
we help you govern it.

Senior-led AI governance, risk and control advisory for regulated and mission-critical systems. Every engagement is delivered by the principal. No junior staff, no hand-offs, no discovery theater.

DC CBE Certified
LBE · SBE · DBE · DZE · ROB · EIE
AIGP
IAPP AI Governance Professional
28 Years
Regulated Production Systems
Vendor-Neutral
No Referral Fees · No Resale
The Position

Most organizations cannot answer the first question a reviewer asks.

Not is the model accurate — that question comes later, and someone else usually owns it. The first question is simpler and harder: where does AI touch a determination you are accountable for, and who signed off?

Pilots produce demos. Vendors produce claims. Neither produces a record. When an oversight body, a contracting officer, or a resident asks how a decision was reached, the answer has to already exist in writing — assembled before it was needed, not after.

That record is what ArcPoint builds. We call it the AI Control Layer.

The AI Control Layer

Four states. Each one is a question you should be able to answer today.

Every engagement below moves an organization from the failure state on the left to the record on the right. Nothing else is the point.

01 Visible
You cannot govern what nobody has mapped.
AI Influence Mapping surfaces every place an AI system shapes, ranks, filters, drafts, or triggers a determination — including the tools nobody approved. Shadow AI is not a policy failure; it is a visibility failure that policy gets blamed for.
02 Validated
A vendor's assurance is not evidence.
Independent verification of what the system actually does — bias testing, traceability, alignment to the regulatory instruments that bind you. Vendor-neutral by construction: ArcPoint earns no referral fees and resells nothing, so a finding costs us nothing to make.
03 Controlled
Policy without decision authority is paper.
Named owners, escalation paths, and a human override that takes precedence over system output — written as a procedure staff actually follow, not a principle they acknowledge in training. Control is an org chart question before it is a technology question.
04 Auditable
The reviewer asks. You answer in writing, or you don't.
A findings register, a values-alignment record, a factsheet with a change log — artifacts that survive someone else's review because they were built to be read by someone who was not in the room. Every deliverable ships in editable source form, so the record stays yours.
The Method

The AI Control Layer is what you get. The Weftline Framework is how it is produced.

Weftline builds on the NIST AI RMF and adds two things the baseline leaves to the practitioner: IEEE 7000 ethical value elicitation, and structured bias testing. Five movements — Strategic Intent, Decision Authority, Operational Integration, Workforce Enablement, Technical Infrastructure — with AI Influence Mapping running through all five to surface where controls are absent.

See how an engagement runs →
Where You're Standing

Two buyers, two obligations, one control layer.

District Agencies & Programs

Every AI deployment needs a values-alignment record before it goes live.

The requirement is per-deployment and indefinite. The policy behind it is binding under D.C. Code and carries sanctions. And the support structure built to help agencies meet it expires at the end of 2026.

  • Values alignment verified before deployment — MO 2024-028 §III
  • Human accountability for every determination — §III.C
  • OCTO AI/ML Governance Policy conformance
  • CTO approval before funds are obligated — IT Procurement Policy §4.2
  • Responsible AI training — employees and contractors
The agency obligation surface →
Prime Contractors & Teaming Partners

Your contract already carries AI obligations. And a subcontracting line to fill.

If any part of your scope touches AI, you have already signed clauses you may not be resourced to satisfy. One subcontract can close the compliance gap and the small-business requirement at the same time.

  • Certified SBE — satisfies § 2-218.46(a)(2)(A), not the fallback
  • 100% self-performed by the principal — no pass-through
  • Proposal-ready AI governance sections on 48-hour notice, at no cost
  • Federal: NIST AI RMF, OMB M-25-21/22, CMMC-adjacent programs
  • Unclassified scope posture — no CUI required
The teaming case →
Track Record

An audit record, not an assurance.

A governance firm should be judged the way it asks its clients to be judged: on documentation that survived someone else's review.

11
Consecutive SOC 2 and PCI audit cycles carried with zero findings.
30,000+
Remote sites governed at 99.9% uptime across regulated, mission-critical production systems.
28 yrs
Senior Principal Engineer, Hughes Network Systems (EchoStar), 1997–2025.
20
Scored findings in a published-source AI values alignment assessment of a live DC deployment.

Work sample — available on request

An independent AI Values Alignment Assessment of DC Compass (OCTO / Esri / Azure OpenAI), a live District AI deployment. Conducted entirely from public sources against MO 2024-028, the OCTO AI/ML Governance Policy, and standard clauses E.1–E.4. Twenty scored findings, every citation verified, principal-signed.

Why it was self-directed

Because a client should not have to take a methodology on faith. The assessment shows the intake instrument, the findings register, the scoring, and the full deliverable set applied to a real system — before anyone signs anything.

Request the work sample →
Engagements

Fixed scope. Fixed fee. Defined deliverables.

Fixed fee is risk transfer — overrun risk sits with ArcPoint, not with your program. Three of the most common entry points below; the full ladder runs deeper.

01

AI Governance Gap Assessment

An organization-wide diagnostic: where AI influences decisions, where oversight is missing, and what to fix in what order. The standard front door when the answer to "what do we even have?" is a shrug.

Details →
02

DC AI Values Alignment Assessment

The full published obligation set for one deployment — the six §III values plus conformance testing against the OCTO AI/ML Governance Policy and clauses E.1–E.4. Assessing one instrument of three is not an assessment.

Details →
03

AI Strategy Session

One working hour with the principal and a one-page memo. Flat fee, any lane. The lowest-friction way to find out whether there is a real engagement here — for either of us.

Details →
View the full engagement ladder →
For District Agencies & Programs

The mandate survives.
The help does not.

Mayor's Order 2024-028 §III requires alignment with six AI values, verified before deploying any AI tool — every deployment, documented, indefinitely. Both the AI Taskforce and the Advisory Group expire December 31, 2026. Agencies are not losing the obligation. They are losing the structure built to help them meet it.

The Obligation Surface

Six things a reviewer can ask for, in writing, today.

A jurisdiction's marquee AI order is rarely its entire compliance surface. In the District, the Mayor's Order sits alongside a binding OCTO policy and a standard clause set — and OCP's own clause E.2 requires conformance with all of it.

Values alignment before deployment
A documented record for every AI tool in use or planned — not a one-time organizational attestation. The duty attaches to the deployment, and it recurs. Mayor's Order 2024-028 §III
Human accountability for every determination
Named decision owners and a review procedure staff actually follow. The standard is accountability for every action or determination — a higher bar than "a human is in the loop somewhere." Mayor's Order 2024-028 §III.C
OCTO AI/ML Governance Policy conformance
Binding under D.C. Code § 1-1401 et seq., with sanctions — not guidance, and it carries obligations the six values do not cover. Testing against §§ 4.1.3–4.1.7, 4.2.3, 4.3.6 and 5. OCTO AI/ML Governance Policy
Standard AI contract clauses E.1–E.4
Factsheet currency, bias evidence on demand, human override precedence, explainability. Clause E.2 is the one that makes the instrument set a single compliance surface rather than three separate ones. DC AI Procurement Handbook · standard clauses E.1–E.4
CTO approval before funds are obligated
In-scope IT projects must be approved by the District CTO before money can be spent, and the Contracting Officer may issue POs and contracts only after that approval is obtained. The package gets assembled either way — the question is whether it is defensible. OCTO IT Procurement and IT Project Policy §4.2
Responsible AI training — employees and contractors
The District's own framing for the mandated course is a baseline understanding. Most of the District is now past baseline. The live question inside an agency is no longer whether staff completed the course — it is whether anyone behaves differently downstream. OCTO announcement, February 12, 2026 · course: "Using GenAI In Government"
The Timing Question

Agencies are not losing the obligation. They are losing the help.

The per-deployment values-alignment requirement is permanent — §III sets no end date. The AI Taskforce and the Advisory Group both sunset at the end of 2026 under §VI.J and §IV.J. Every deployment that goes live in 2027 carries the same duty with less institutional support behind it.

That is the case for standing capacity rather than episodic projects — someone retained who already knows your systems when the question arrives, instead of a procurement that starts after it does.

How to Contract With ArcPoint

Registered, certified, and able to receive award today.

Set-aside eligible

Certified SBE, eligible for the mandatory set-aside of contracts at or below $250,000 under § 2-218.44 — the band ArcPoint's District services are scoped to sit inside, individually and in combination.

Maximum bid preference

Six CBE designations whose combined value exceeds the statutory cap, so ArcPoint qualifies for the most § 2-218.43(b) allows: 12 points on proposals, or a 12% price reduction on bids. No competitor can hold more — only match.

Never both sides of one procurement

ArcPoint does not represent a vendor bidding to an agency it advises, and takes no role in source selection. Where we support a procurement, recommended language is input to the Contracting Officer and counsel, who own the solicitation.

Vendor-neutral, and resident

No referral fees, no reseller relationships — findings serve the agency and nothing else. A DC resident with a direct stake in how the District governs AI, not a firm that flew in for the mandate.

Ready to execute: NDA · W-9 · CBE number. SAM.gov active · OCP eSourcing registered · Basic Business License and Clean Hands current.

Agency Engagements

Deliverables, not hours.

DC AI Values Alignment Assessment
CIO · Program Office · OGC
The full published obligation set for one deployment: the six §III values plus conformance testing against the OCTO AI/ML Governance Policy and clauses E.1–E.4. Ships as a package — report, client assessment, remediation workbook, readout deck, OCTO submission set, 30-day checkpoint — all rendered from a single findings register, so no two artifacts can disagree. Scope boundary: one AI deployment
6–8 wksFixed fee
AI Governance Workforce Enablement
HR · Training Office · CIO · Privacy
Role-specific operational training that begins where the District's baseline course ends. Built on a role and decision-authority map that turns §III.C human accountability into job aids staff use at the moment of decision. Not a compliance substitute — the District-level training obligation is discharged centrally; this builds above it. 3 role groups · 3 live sessions · 75 participants
4–5 wksFixed fee
AI Procurement Governance Review
CIO · CTO Liaison · Contracting Officer
Pre-award. Every other engagement assesses a system the agency already owns; this one lands in the window before signature, where requirements, evidence rights, acceptance criteria, and termination leverage are still cheap to change. Anchored to the §4.2 CTO approval gate the agency must clear regardless. 1 acquisition · 3 working sessions · 1 panel briefing
2–3 wksFixed fee
AI Governance Gap Assessment
CIO · Executive Leadership
Organization-wide rather than per-deployment. Where AI influences decisions across the agency, where oversight is missing, and a sequenced remediation roadmap. The right start when the deployment inventory itself is uncertain.
4–6 wksFixed fee
Standing AI Governance Advisory
CIO · AI Lead
Retained monthly capacity across deployment, monitoring, and review cycles — capacity held in reserve rather than episodic projects. Structured to carry an agency through the Taskforce sunset without a gap in coverage.
MonthlyBy engagement
For Prime Contractors & Teaming Partners

Your contract already carries AI obligations.
And a line to fill.

If any part of your scope touches AI — analytics, automation, a model inside a workflow, a vendor tool in a resident-facing system — you have signed clauses that require evidence you may not be resourced to produce. One subcontract can close the compliance exposure and the small-business requirement at the same time.

District Contracts — Clause Exposure

Can your program produce this today?

Each line below is a clause you have already signed. The question is not whether the obligation applies — it is whether the artifact exists before someone asks for it.

The AI Factsheet, current
The live version plus a change log proving update within 30 days of the last substantive change. A factsheet that was accurate at award and untouched since is a finding, not a defense.
Bias evidence, on demand
A testing record a reviewer can read without scheduling a follow-up meeting. "On demand" means the evidence pre-dates the request.
A human override that takes precedence over system output
A named owner and a procedure staff follow — not a capability that technically exists in the admin console.
Explainability
How the system reaches determinations, written in language a resident could be handed. If it only makes sense to the vendor's engineers, it does not satisfy the clause.
A values-alignment record for the deployment
Documented before go-live, every time. Your agency customer owes this under MO 2024-028 §III — and will look to the program delivering the system to produce most of it.
A 10-day cure clock when an AI incident lands
The response procedure has to exist before the clock starts. Ten days is not enough time to design one.
Your Subcontracting Requirement

Why an SBE specifically — and why the distinction matters.

The requirement

35% to small business enterprises

On government-assisted non-construction contracts over $250,000, § 2-218.46(a)(2)(A) requires 35% of dollar volume to go to small business enterprises. CBEs generally are the (a)(2)(B) fallback — available only where qualified SBEs are insufficient. ArcPoint is a certified SBE, which satisfies the primary requirement rather than the exception.

The timing

The plan is due before your proposal is accepted

§ 2-218.46(d) makes a bid nonresponsive on a deficient plan — and the plan is due before the District accepts your proposal, not after award. After award: executed subcontract returned for your (h) submission, and quarterly figures for your (i) reports, unprompted.

No pass-through

100% self-performed by the principal

Satisfies § 2-218.46(b-1). Independent advisors are used for surge capacity, never as a conduit. There is no second-tier subcontracting behind this certificate.

Stated correctly

Preference does not pass through

§ 2-218.43 preference attaches to the bidder and does not flow through a subcontract. ArcPoint's six designations total 19 points against the 12-point cap — the statutory maximum — which applies where ArcPoint bids as prime or in a certified joint venture under § 2-218.39a. In a standard subcontract your benefit is (a)(2)(A) satisfaction and, at or below $250,000, § 2-218.44 set-aside eligibility.

Federal Programs

Subcontract and teaming capability for federal work.

AI governance is arriving in federal scopes faster than programs are staffed for it. ArcPoint teams as a subcontractor against the instruments that already bind the work.

  • NIST AI RMF — the methodology baseline, layered with program-specific requirements rather than applied generically.
  • OMB M-25-21 and M-25-22 — agency use and acquisition of AI.
  • Lifecycle controls — impact assessments, model and system cards, human-oversight procedures, change management, decommissioning.
  • AI System IV&V — independent assessment of bias, traceability, and regulatory alignment in high-impact environments.
  • OWASP LLM Top 10 — agentic and MCP-connected workflow risk in regulated environments.
  • Scope posture: unclassified only — no CUI required, stated plainly up front so the fit question is settled in the first conversation.
What You Get

Deliverables, not hours.

Pre-award

Proposal-ready governance sections

AI governance narrative written to the solicitation's evaluation criteria, on 48-hour notice, before any subcontract, at no cost. If you don't win, you owe nothing — that is the point.

Post-award

The clause evidence set

AI Factsheet drafted then maintained annually and on change · values-alignment record per deployment in the form OCTO expects · bias-testing evidence package · incident response procedure · human-accountability procedure with named owners.

Gate support

CTO approval package

Support assembling the approval package under OCTO IT Procurement Policy §4.2, so the money moves on schedule rather than stalling at a gate nobody staffed for.

The Solo Question, Answered

A single practitioner is a continuity risk only if the work lives in one head.

Senior-led by the certificate holder means no staffing ramp, no substitution risk, and no second-tier subcontracting. That is the half everyone likes. Here is the other half: the method — intake instrument, evidence request list, scored findings register — keeps work transferable rather than held in one head, and every artifact ships in editable source form.

Committed availability of 40 hours per month per engagement, response within one business day. Fixed fee where scope allows — overrun risk sits with ArcPoint. Teaming is non-exclusive, and never against a partner on the same solicitation.

Quote returned in three business days.

Subcontractor Data — Plan-Ready

Everything your § 2-218.46(d)(2) plan needs.

Legal nameArcPoint Consulting, LLC
AddressWashington, DC 20020Full street address on the capability statement, for your subcontracting plan
UEIJE2DLNX4BVQ3
CAGE code20CH5
D-U-N-S144965471
DC CBE No.LSDZRE17604082029Valid to August 10, 2029 · LBE · SBE · DBE · DZE · ROB · EIE · verifiable with DSLBD
NAICS541611 · 541618 · 541690 · 541512 · 611430Small under all listed codes
RegistrationsSAM.gov active · OCP eSourcing registered
Business sizeSmall Business
Scope postureUnclassified only — no CUI required
Point of contactJermaine Leonard, AIGP — Founder & Principal Consultant
Engagements

Fixed scope. Fixed fee.
Defined deliverables.

Every engagement declares a boundary before it starts — what is in, what is out, and what ships. Fixed fee is risk transfer: overrun risk sits with ArcPoint rather than with your program. Pricing is scoped to the engagement and quoted in three business days.

District Agencies & Programs

DC AI Values Alignment Assessment
CIO · Program Office · OGC
The full published obligation set for one deployment — six §III values plus conformance testing against the OCTO AI/ML Governance Policy and clauses E.1–E.4. Report · client assessment · remediation workbook · readout deck · OCTO submission set · 30-day checkpoint, all rendered from one findings register.Boundary: one AI deployment
6–8 wksFixed fee
AI Governance Workforce Enablement
HR · Training · CIO · Privacy
Role-specific operational training that starts where the baseline course stops, built on a role and decision-authority map. Converts §III.C human accountability into job aids used at the moment of decision.Boundary: 3 role groups · 3 live sessions · 75 participants
4–5 wksFixed fee
AI Procurement Governance Review
CIO · CO · CTO Liaison
Pre-award review of a planned acquisition — requirements, evidence rights, acceptance criteria, termination leverage — with every finding attached to a named pre-award decision point. Anchored to the §4.2 CTO approval gate.Boundary: 1 acquisition · 3 working sessions · 1 evaluation-panel briefing
2–3 wksFixed fee
DC AI Factsheet & Readiness
Vendor-side · Program Delivery
The vendor-side mirror. Every District AI procurement triggers a factsheet; this produces it, keeps it current within 30 days of substantive change, and builds the readiness evidence behind it.Never run alongside the agency-side review on the same procurement
By scopeFixed fee
Standing AI Governance Advisory
CIO · AI Lead
Retained monthly capacity across deployment, monitoring, and review cycles. Standing capacity rather than episodic projects — structured to carry an agency through the Taskforce sunset without a gap.
MonthlyBy engagement

Federal & GovCon

AI Governance Gap Assessment
Program Manager · CISO · Compliance
Organization- or program-wide diagnostic against the NIST AI RMF baseline plus the instruments binding the specific program. Where AI influences decisions, where oversight is missing, sequenced remediation.
4–6 wksFixed fee
AI System IV&V
Program Office · Independent Review
Independent verification and validation of an AI system — bias, traceability, and alignment with regulatory expectations in high-impact environments. Vendor-neutral by construction.Unclassified scope only — no CUI
By scopeFixed fee
MCP & Agentic AI Readiness Assessment
CISO · Architecture · Program
Where agentic workflows and tool-connected models create exposure that traditional model review does not catch — connector permissions, action authority, prompt-injection surface, and the human checkpoint that should exist and usually doesn't. Mapped to the OWASP LLM Top 10.
By scopeFixed fee
AI Risk Gap for CMMC Programs
DIB Contractors · CMMC Leads
Where AI adoption intersects an existing CMMC or SP 800-171 posture — and where a well-meaning AI rollout quietly undermines a control that was already assessed.
By scopeFixed fee
Proposal Governance Support
Capture · Proposal Managers
AI governance sections written to the solicitation's evaluation criteria, on 48-hour notice, before any subcontract — at no cost to the prime.
48 hrsNo cost

Commercial & Regulated SMB

AI Governance Starter
Owner · COO · General Counsel
For organizations with no AI policy at all. Acceptable use, shadow-AI controls, decision authority, and a governance structure sized for an organization without a compliance department.
By scopeFixed fee
AI Governance Gap Assessment
Owner · COO · Compliance
For organizations that already have some policy and need to know whether it survives contact with how staff actually work. Plain language, no framework theater.
By scopeFixed fee
AI Automation Risk Review
Operations · IT
Is what you have already automated actually under control? The risk companion to an automation program — what the workflow can do unsupervised, and who finds out when it does it wrong.
By scopeFixed fee
AI Tool Usage Workshop
Teams · Department Leads
Hands-on enablement — teaching staff to use AI tools well. Deliberately distinct from governance and policy work, and sold separately so neither pretends to be the other.
1 sessionFlat fee
AI Governance Retainer
Owner · COO
Ongoing monthly advisory for organizations that have a policy and need someone to keep it true as tools, staff, and regulation change.
MonthlyBy engagement

Any Lane

AI Strategy Session
Anyone deciding what to do first
One working hour with the principal and a one-page memo. Flat fee. The lowest-friction way to establish whether there is a real engagement here — including the answer that there isn't one yet.
1 sessionFlat fee
Before You Ask For a Quote

Bring one AI deployment — in use or planned.

In thirty minutes you will know whether that deployment has an alignment record that would survive review, and — for District work — whether the engagement can be procured under the § 2-218.44 set-aside. No fee, no obligation.

Book the Call
Method

The AI Control Layer is the outcome.
Weftline is how it's built.

Governance-first, with the NIST AI RMF as the baseline and jurisdiction-specific requirements layered on top. The framework exists so the work is repeatable, transferable, and legible to someone who was not in the room — which is the only kind of governance record worth having.

The Weftline Framework

Five movements, with influence mapping running through all of them.

Builds on the NIST AI RMF and adds what the baseline leaves to the practitioner: IEEE 7000 ethical value elicitation, and structured bias testing.

I
Strategic Intent
What the organization is actually trying to accomplish with AI, stated precisely enough that a control can be tested against it.
II
Decision Authority
Who decides, who reviews, who can override, and who is accountable when the determination is wrong. An org chart question before a technology one.
III
Operational Integration
How the control lives inside the workflow rather than beside it. Governance that requires an extra step gets skipped by week three.
IV
Workforce Enablement
Whether the people holding the authority know they hold it, and what to do at the moment of decision.
V
Technical Infrastructure
Logging, traceability, testing, and the evidence plumbing that makes the record reproducible instead of anecdotal.

AI Influence Mapping runs across all five — the technique that surfaces where AI shapes a determination and no control is present. It is what makes the difference between a governance program that covers the systems you remembered and one that covers the systems you have.

How an Engagement Runs

One dataset. Every artifact rendered from it.

Findings are structured records before they are prose — consequence × evidence confidence, named owner, effort, remediation wave. Which means the report, the workbook, the readout, and the submission set cannot disagree with one another.

01
Intake
A questionnaire and evidence-request list issued before work begins. Intake quality is the ceiling on deliverable quality — so it is an instrument, not a kickoff chat.
02
Evidence Review
What exists, what is claimed, and the distance between them. Assessed against the full published obligation set, not the headline instrument alone.
03
Findings Register
Every finding scored on consequence and evidence confidence, with a named owner, effort estimate, and remediation wave. The single source everything else renders from.
04
Deliverable Set
Report, workbook, readout, submission set — generated from the register, verified citation by citation against primary sources, and signed by the principal.
05
30-Day Checkpoint
A return visit after the readout, because the value of a remediation roadmap is decided in the thirty days nobody schedules.
Standards Applied

Baseline, then jurisdiction.

A framework alone does not discharge an obligation. The baseline establishes the discipline; the binding local instrument decides what the record has to contain.

  • NIST AI RMF — the methodology baseline across every lane.
  • IEEE 7000-2021 — ethical value elicitation, added where the baseline defers to the practitioner.
  • ISO/IEC 42001 — AI management system structure for commercial and multi-jurisdiction clients.
  • DC: MO 2024-028 · OCTO AI/ML Governance Policy · AI Procurement Handbook and clauses E.1–E.4 · OCTO IT Procurement and IT Project Policy.
  • Federal: OMB M-25-21 and M-25-22 · CMMC L2/L3 · NIST SP 800-171 · DFARS 252.204-7012.
  • OWASP LLM Top 10 — agentic and MCP-connected workflow risk.
Standing Commitments

The constraints we accept before you ask.

Every citation verified at ship

Each regulatory citation in a client-facing deliverable is re-checked against the primary source before delivery, and the verification is documented citation by citation. A governance finding built on a misremembered section number is worse than no finding.

Principal-signed, principal-defended

The principal reviews and signs every deliverable, and defends every finding in the room. AI is used as back-office leverage in research and drafting; judgment and accountability are not delegated.

Editable source form

Every artifact ships in a form the client can maintain. Your governance record should not depend on our availability, and it should not be hostage to a file format.

Vendor-neutral, with nothing to disclose

No referral fees, no reseller relationships, no platform partnerships. Nothing a competitor can characterize as steering, and no finding that costs us revenue to make.

The Firm

Senior-led means
exactly what it says.

ArcPoint Consulting is a solo, senior-led AI governance, risk and control practice in Washington, DC. Every engagement is delivered by the principal. There is no bench, no staffing ramp, and no junior consultant learning your program on your budget.

Jermaine Leonard AIGP
[ headshot ]
Founder & Principal Consultant

Jermaine Leonard, AIGP

Twenty-eight years governing regulated, mission-critical production systems — and the audit record to show what that produced.

From 1997 to 2025, Senior Principal Engineer at Hughes Network Systems (EchoStar), responsible for regulated production infrastructure spanning more than 30,000 remote sites at 99.9% uptime, including an 80% reduction in provisioning time through zero-touch orchestration. Across that tenure: eleven consecutive SOC 2 and PCI audit cycles carried with zero findings.

That is the relevant background for AI governance, and it is a deliberate claim. The hard part of governing AI is not the model — it is producing a control record that survives an outside reviewer, in a live system, under real operating pressure, without stopping the work. That is a discipline built over decades in regulated operations, not a framework certification earned in a weekend.

  • AIGP — IAPP AI Governance Professional, and a member in good standing of the IAPP
  • CDP Certified AI Consultant
  • DC Certified Business Enterprise — LBE · SBE · DBE · DZE · ROB · EIE, certified through August 2029
  • Washington, DC resident — with a direct stake in how the District governs AI
Why ArcPoint

Five positions, held consistently.

01

Governance-first architecture

Governance built in before deployment, not retrofitted after an incident. Retrofitting is more expensive and produces a weaker record, because the decisions that needed documenting were made months ago by people who have moved on.

02

Decision accountability focus

We address how decisions are made, influenced, and defended — not only how a model performs. Model performance is a vendor's problem. Determinations are yours.

03

Operational AI risk expertise

AI behavior in real environments, under real constraints, with real consequences — assessed by someone who has carried production systems through outside audits rather than only read about them.

04

Senior-led engagements

Every engagement led by the principal. No junior staff, no hand-offs, no billable-hour padding. Fixed fee where scope allows, so overrun risk sits with ArcPoint.

05

Vendor-neutral

No referral fees, no reseller relationships, no platform partnerships. Our findings serve your interests, and there is nothing to disclose because there is nothing to disclose.

06

Skeptical of hype, by policy

Nothing in the fee structure rewards telling you to adopt more AI. Often the finding that matters most is that a control, an owner, or a written procedure is missing — not that a tool is.

Corporate Information

Registered and able to receive award today.

Ready to execute: NDA · W-9 · CBE number. Basic Business License and Clean Hands current.

Professional references available on request, including a named reference to the regulated-systems and audit record described here.

Legal entityArcPoint Consulting, LLC
LocationWashington, DC 20020
UEIJE2DLNX4BVQ3
CAGE20CH5
D-U-N-S144965471
DC CBELSDZRE17604082029Certified 2026-08-10, valid to 2029-08-10
NAICS541611 · 541618 · 541690
541512 · 611430
RegistrationsSAM.gov · OCP eSourcing
Scope postureUnclassified only — no CUI
Insights

Regulatory developments,
read as obligations.

Not news summaries. Each piece takes a development a client will hear about anyway and works out what it actually changes about someone's duty, evidence, or exposure — including the frequent answer that it changes less than the headline suggests.

Sep 29, 2026
What Assurance Actually Tests: A Test Plan for Auditing the AI Control Layer
An AI governance review that never selects a decision has audited the paperwork, not the controls. A white paper adapting SOX control testing to AI: what to sample, which evidence counts, how to grade findings, and where internal audit needs a specialist. Includes a 21-test matrix.
White PaperAssurance
Jul 23, 2026
DC's AI Values Have Never Been Enforced. The Window to Fix That Is Closing.
A framework becomes credible the first time its consequence lands on someone. DC's six values have not had that moment — and the bodies that would make it a citable precedent expire December 31, 2026.
DC-GovOCTO
Jul 17, 2026
Illinois Didn't Just Add an AI Law. It Changed Who Gets to Grade the Homework.
SB 315 replaces self-attestation with independent third-party audit — the SOX playbook applied to catastrophic-risk claims. The penalties target frontier developers; the diligence pressure lands on everyone buying from them.
CommercialAssurance
Jul 17, 2026
The CMMC Suspension Didn't Lower Your Risk. It Moved It.
The suspension removed a verification step, not the obligation under it. NIST 800-171, DFARS 252.204-7012, and SPRS attestation all survive — and DoW cannot suspend DOJ's False Claims Act authority.
FederalCMMC
Jul 13, 2026
Default-On Consent Isn't a PR Risk. It's a Compliance Case Study.
The exposure in AI image generation sits in biometric and minor-safety statutes, not general AI law — and most teams have that backwards.
CommercialPrivacy

Each article was originally published on LinkedIn; the version here is the same text with its source link. White papers are published here first. Regulatory positions are stated as of the publication date and are not updated in place — where a development has since moved, a later piece says so rather than a silent edit.

Insights / White Paper

What Assurance Actually Tests. A Test Plan for Auditing the AI Control Layer.

← All insights

An AI governance review that never selects a decision has audited the documentation of AI governance. It may have done that well. What it hasn't tested is whether anything in the organization would stop a consequential AI system that was producing bad outcomes.

The main audit guidance on AI tells you what to look at. It doesn't tell you what to sample, how many items to pull, or what evidence passes. This paper does. It adapts twenty years of Sarbanes-Oxley control testing to AI, where three things change: controls shift without a change ticket, human review decays as volume rises, and the most important control has usually never been used.

Inside the paper

  • Why the sampling unit is the consequential decision, not the AI system
  • The timestamp test: which evidence counts, and which is a reconstruction
  • How to test human review, including when a falling override rate means trouble
  • A severity scale for AI control findings, graded by reversibility and likelihood
  • A first-year scope an audit function can actually deliver
  • Where internal audit can work alone and where it needs an independent specialist
  • A 21-test matrix covering Visibility, Validation, Control and Auditability

Six questions for your audit committee

  1. What was the sampling unit, systems or decisions?
  2. How was the AI inventory tested for completeness, and from which sources outside the governance team?
  3. How many consequential decisions were tested, from what population, at what confidence?
  4. How much of the evidence the organization supplied existed before the request?
  5. How many stop authorities have never been used?
  6. Who reviewed the validations, and what's their relationship to the people who built the system?

A report that can answer those has tested something. A report that can't has read something.

Written for chief audit executives and audit committees, and their public-sector equivalents: agency heads, inspectors general and oversight boards.

About the author. Jermaine Leonard, AIGP, is the principal of ArcPoint Consulting, a senior-led AI governance, risk and control advisory practice in Washington, DC. Every engagement is delivered and signed by the principal.

Insights / DC Government

DC's AI Values Have Never Been Enforced. The Window to Fix That Is Closing.

← All insights

Every governance framework works fine right up until the moment it actually costs someone something. Before that moment, nobody can tell you whether it's real or whether it's a mission statement with a mandate number attached.

DC's six AI values, in place since 2024 under Mayor's Order 2024-028, have not had that moment yet. That's the real question hanging over the framework — not whether the org chart names an owner for Accountability.

I'd call this the founding violation problem. A rule doesn't become credible because someone wrote a consequence into it. It becomes credible the first time that consequence actually lands on someone, and everyone watching adjusts their behavior because of it. Miranda warnings didn't change policing because a court described them well. They changed policing once departments started losing cases over ignoring them.

Until DC's six values produce their own version of that moment, they're operating on borrowed credibility.

A finding. A paused deployment. A factsheet rejected and made public. Until one of those happens, the framework rests on the assumption that it would hold up if tested — never actually tested.

Why this is urgent rather than academic

DC's AI Taskforce and Advisory Group sunset December 31, 2026. Whatever informal enforcement muscle exists right now mostly runs through that structure. If the first real test of the six values happens after these bodies are gone, it happens without the apparatus that would have made it a clean, citable precedent.

And a framework that misses its own founding-violation window doesn't get a second one on the same terms. Whatever comes next has to rebuild credibility from scratch, against a public record showing two full years of a mandate nobody was held to.

What to watch between now and year end

One specific thing: whether OCTO, an inspector general, or any agency points to an actual finding under the six values — not a policy citation, an enforcement action.

If that doesn't happen before the Taskforce sunsets, the framework doesn't fail. It just becomes permanently aspirational by default, and no later reorganization fixes that retroactively.

This is my read, not a compliance assessment of any specific agency's program.

Insights / Commercial

Illinois Didn't Just Add an AI Law. It Changed Who Gets to Grade the Homework.

← All insights

Every other state AI law runs on the honor system: a company writes its own safety framework and tells regulators to take its word.

Illinois' Artificial Intelligence Safety Measures Act (SB 315), signed July 6, breaks that pattern. Large frontier developers must publish a safety framework and hire an independent, conflict-free third party to audit it annually, with results going to the state and the Attorney General.

Why this shift matters

Self-attestation and independent audit look similar on paper. They produce opposite incentives. Under disclosure, the company grading its own framework has no cost for optimistic language. An audit moves the liability: a named auditor certifies the result under their own professional standing. That's the SOX playbook, run on catastrophic-risk claims instead of earnings.

One wrinkle shows real audit sophistication: SB 315 requires the auditor to both certify compliance and recommend improvements. That's the same independence conflict that ended Arthur Andersen and split audit from consulting after Enron. The statute hasn't resolved it. Neither has the auditor market, yet.

What the audit actually requires

  1. Independence — no financial interest between auditor and developer.
  2. Competence — demonstrated frontier-model safety expertise, not general IT audit credentials.
  3. Standard — "generally accepted auditing standards," which don't yet formally exist for this domain; expect early reliance on NIST AI RMF and ISO 42001.
  4. Access — auditors see unredacted documentation, not just the published framework.
  5. Disclosure — a redacted summary goes public in 30 days; the full report goes to regulators, trade secrets or not.

What to do about it, by tier

Near or above $500M and training frontier-scale models: the 18 months to January 2028 is short given how thin the qualified-auditor pool is. Scope your exposure, formalize catastrophic-risk assessment in writing, build the 72-hour incident playbook, and start auditor conversations before the market gets crowded.

Everyone else — most companies buying AI rather than building it — your compliance move is with your vendors, not Illinois:

  • Ask vendors whether their compliance claim is self-reported or audited, in writing.
  • Add audit-report access language to contracts and DPAs now.
  • Build internal AI governance that survives outside review, even without a legal mandate yet.

Watch for who copies the auditor requirement. That's what turns AI governance into an assurance function.

States that follow Illinois won't copy the penalty figures. The companies treating that distinction as semantic now are the ones explaining it to a regulator later.

Insights / Federal

The CMMC Suspension Didn't Lower Your Risk. It Moved It.

← All insights

On July 13, 2026, the Department of War suspended CMMC Phase II — the third-party assessment piece that was supposed to start this November. Most of the reaction treats this as a break. I'd argue it's the opposite.

Here's what actually happened. The suspension removed a verification step. It didn't touch the obligation underneath it. NIST 800-171 is still the baseline. DFARS 252.204-7012 hasn't changed. SPRS scoring and your annual affirmation are still required. And nothing about this action touches DOJ's separate authority to pursue False Claims Act cases against contractors who misrepresent their cybersecurity posture. DoW can suspend its own assessment program. It can't suspend DOJ's.

What's gone is the independent check. Your obligation to be right about what you attest isn't.

For two years, a C3PAO assessment meant someone outside your organization had looked at your controls before the government relied on your score. That check is paused now.

Why this is a governance issue, not just a cyber one

Every SPRS filing is now a claim to the federal government that nobody outside your walls has verified. Based on how DOJ's Civil Cyber-Fraud Initiative cases have generally been built, the exposure tends to come less from missing controls and more from a gap between what got attested and what an audit would have found. Self-attestation without an outside check widens that gap's room to hide.

So if your read on this suspension is "we can slow down," what you're actually doing is holding onto that gap without the buffer that used to make it smaller.

What I'd be doing instead

  • Pull the evidence behind every control claim in your SPRS score, tied to what's actually running — not what a policy document says should be running.
  • Get clear on who owns the affirmation, and make sure there's a record of what they checked before they signed it.
  • Look hard at whether your CUI scope can shrink. Smaller footprint, easier to defend, easier to keep accurate.
  • Run your own internal testing against the 110 controls, because nobody's scheduling that visit for you anymore.

The compliance calendar just got longer. The liability window didn't move at all. If you sit on a board or in GC and you're looking at cyber risk this quarter, that's the signal: tighten review, don't ease off it.

This is my read on where things stand, not legal advice. FCA exposure is a question for counsel. Note added since publication: the suspension was subsequently confirmed to cover CMMC Phases 3 and 4 and all future milestones, not Phase II alone. The argument above holds — the underlying obligation survives regardless of scope — but the original post understated how broad the suspension was.

Start Here

Bring one AI deployment.
In use, or planned.

Thirty minutes. You will leave knowing whether that deployment has an alignment record that would survive review, and — for District work — whether the engagement can be procured under the § 2-218.44 set-aside. No fee, no obligation, no slide deck.

Send a note

Or skip the form and book the call directly.

Please do not send CUI, procurement-sensitive, or pre-decisional material through this form. Sensitive material is handled under NDA through a separate channel — say so here and we'll set one up.

Book directly
Straight to the principal's calendar. No qualification gate, no SDR.
Phone
Response within one business day.
Capability statements
DC agency · DC prime · federal prime
Say which one you need and it comes back same day, along with the DC Compass work sample on request.
Location
Washington, DC
Engagements delivered on site across the District and the National Capital Region.
Accessibility

Accessibility Statement

A firm that sells governance should be willing to be measured by its own instrument. This page states what standard this site targets, what was done to meet it, what is known not to meet it, and how to tell us when we're wrong.

Last reviewed: August 13, 2026 · Applies to: arcpointconsulting.com

Conformance target

This site is built to conform to Web Content Accessibility Guidelines (WCAG) 2.1, Level AA. That standard is also the benchmark referenced by Section 508 of the Rehabilitation Act, which governs information and communication technology procured by federal agencies, and is used as a reference standard by District of Columbia agencies.

We state this as a target with known exceptions rather than as a certification. No third party has audited this site. Claiming certified conformance without an independent assessment would be the same self-attestation problem we advise clients against.

Measures taken

  • Contrast. Primary text combinations were selected against measured ratios — cream on navy at approximately 13.8:1 and gold on navy at approximately 6.4:1, both exceeding the 4.5:1 AA threshold for body text. The lighter brand gold is deliberately never used for text on light backgrounds, where it fails; a darker gold is substituted for accents.
  • Keyboard operability. Every interactive element is reachable and operable by keyboard, with a visible focus indicator at 3px and 2px offset. A skip-to-content link is the first focusable element on the page.
  • Target size. Interactive targets are set to a 44px minimum.
  • Semantic structure. Headings descend in order, navigation is marked as a landmark, the current page carries an aria-current state, and the mobile menu button exposes its expanded state.
  • Form labels. Every field has a persistently visible label. Placeholders are never used as the only label, and validation errors are conveyed in text rather than by color alone.
  • Motion. Transitions are limited to color and opacity at 150–250ms. There is no parallax, no scroll-jacking, and no entrance animation on body copy. The prefers-reduced-motion setting is honored.
  • Meaning without color. No information is conveyed by color alone.

Known limitations

Stated plainly, because an accessibility statement that lists only successes is marketing:

  • No independent audit. Conformance has been assessed internally only. No assistive-technology user testing has been conducted.
  • Client-side routing. Pages are rendered without a full page load. Focus is moved to the main region on each route change and the document title is updated, but screen reader announcement behavior across this pattern has not been verified with every assistive technology.
  • Third-party scheduling. The booking tool linked from this site is operated by a third party. Its accessibility is outside our control and has not been assessed by us.
  • Documents. Capability statements and other PDFs distributed by ArcPoint have not been individually tested for tagged-PDF accessibility. An accessible alternative format is available on request.

Feedback and alternative formats

If any part of this site or any ArcPoint document is inaccessible to you, write to jleonard@arcpointconsulting.com or call (240) 244-9850. Tell us the page or document and the barrier you hit. We aim to acknowledge within one business day and to supply the content in an accessible alternative format at no cost.

If a response is unsatisfactory, say so directly to the principal — there is no escalation tier above him, which is the point of the firm.

Privacy

Privacy Notice

Short, because this site does very little. It describes what actually happens here, not what a generic template would allow us to do later.

Effective: August 13, 2026 · Controller: ArcPoint Consulting, LLC, Washington, DC

What this website collects

No analytics. No cookies. No tracking pixels. No advertising technology. This site sets no cookies and embeds no third-party analytics or marketing scripts. We do not build profiles of visitors, and we cannot tell you which pages you read.

Two exceptions are worth naming precisely:

  • Web fonts are currently loaded from Google Fonts, which means your browser makes a request to Google's servers and Google receives your IP address in the process. We are moving to self-hosted fonts to remove this.
  • Hosting logs. Our hosting provider records standard server logs, which typically include IP address, timestamp, and user agent. We do not use these for analytics.

Information you send us

If you use the contact form, it opens a message in your own email client — the data is not posted to a server we control. If you email, call, or book a call, we receive what you send: typically name, organization, email address, phone number, and whatever you choose to describe about your situation.

We use that information only to respond to you and to carry out any engagement that follows. We do not sell it, rent it, or share it for anyone else's marketing, and we do not add you to a mailing list you didn't ask for.

The scheduling tool

Booking a call sends you to a third-party scheduling service. Information you enter there is handled under that provider's privacy terms, not ours.

What we ask you not to send

Please do not send Controlled Unclassified Information, procurement-sensitive material, pre-decisional documents, or personal information about third parties through this website, the contact form, or ordinary email. ArcPoint operates an unclassified-only scope posture. Sensitive material is handled under a non-disclosure agreement through a separate channel — ask and we will set one up before you send anything.

Retention and security

Enquiry correspondence is retained while a business relationship is reasonably in prospect and thereafter as required for tax, insurance, and professional-record purposes. Engagement records are retained under the terms of the applicable agreement. Access is limited to the principal.

Your choices

You may ask what we hold about you, ask for it to be corrected, or ask for it to be deleted, by writing to jleonard@arcpointconsulting.com. Where a legal obligation requires us to retain something, we will tell you that rather than quietly decline.

Changes

If this site later adds analytics, a hosted form handler, or any other data collection, this notice will be updated before that change goes live, and the effective date above will change with it.

Note: this notice describes current practice accurately. It has not been reviewed by counsel, and it is not tailored to GDPR, CCPA, or other specific regimes. If ArcPoint begins handling personal data at scale or for clients in those jurisdictions, it should be replaced with a reviewed instrument.

Terms

Terms of Use

The terms on which this website is offered. They govern the site only — engagements are governed by their own signed agreement, which controls wherever the two differ.

Effective: August 13, 2026 · ArcPoint Consulting, LLC

No advice, and no relationship formed

Everything on this site — including the Insights articles and every description of a regulation, mandate, policy, or contract clause — is general information, not advice. It is not legal advice, and ArcPoint is not a law firm. It is not a compliance assessment of your organization, your program, or any specific deployment. Reading it, emailing us, or booking a call does not create a consulting or advisory relationship. That begins only when a written agreement is signed by both parties.

Regulatory content is accurate as of its date

Citations to statutes, mayor's orders, agency policies, and contract clauses were verified against primary sources at the time of writing. Regulation moves. Articles carry a publication date and are not updated in place — where a development has since changed, a later piece says so rather than a silent edit to the original. Verify anything you intend to rely on against the current primary source, or ask us to.

No warranty

This site is provided as-is. We do not warrant that it is free of errors or omissions, or that it will be continuously available. To the fullest extent permitted by law, ArcPoint Consulting, LLC disclaims liability for loss arising from reliance on site content that has not been provided under a signed engagement.

Intellectual property

Site content, the Insights articles, the AI Control Layer descriptor as used here, and the Weftline Framework and its structure are the property of ArcPoint Consulting, LLC. You may quote briefly with attribution and a link. You may not reproduce substantial portions, or use this content to train a model or build a competing methodology, without written permission.

Names of statutes, agencies, standards bodies, and third-party organizations are used for identification and reference. Their use does not imply endorsement, affiliation, or approval by those parties in either direction.

Independence and conflicts

ArcPoint is vendor-neutral: no referral fees, no reseller relationships, no platform partnerships. ArcPoint does not represent a vendor bidding to an agency it advises, takes no role in source selection, and will not act on both sides of the same procurement. Nothing on this site should be read as an offer to do any of those things.

Do not send sensitive material

Do not transmit Controlled Unclassified Information, classified material, procurement-sensitive or pre-decisional documents, or third-party personal information through this site or by unsecured email. ArcPoint operates an unclassified-only scope posture. Unsolicited material sent contrary to this notice is not accepted in confidence.

Governing law

These terms are governed by the laws of the District of Columbia, without regard to conflict-of-law principles.

Contact

Questions about these terms: jleonard@arcpointconsulting.com.

Note: these terms have not been reviewed by counsel. They should be before the site goes live, particularly the limitation of liability and intellectual property sections.

Next Step

Start with a working session.

Thirty minutes with the principal. Bring one AI deployment — in use or planned — and leave knowing whether its record would survive review.

Book a Call