For Fractional CISOs & vCISOs

Stop Rebuilding AI Act Compliance From Scratch for Every Client

The white-label EU AI Act compliance toolkit built for fractional CISOs. Deploy a complete compliance program in hours, not weeks. Your brand. Your clients. Your margin.

The Problem

The Problem You Already Know

Your clients are asking about the EU AI Act. The August 2, 2026 enforcement deadline is less than 5 months away. Penalties reach €35 million or 7% of global annual revenue.


You know how to deliver compliance programs. But every AI Act engagement starts the same way: 20–40 hours building a governance framework, risk assessment, and policy set from scratch. The same documents. The same structure. The same questions. Rebuilt for every client.


That is 20–40 billable hours spent on document creation instead of advisory work. Every single time.

What's Inside

18 Documents. Four Categories. Fully White-Labeled.

Everything white-labeled with your firm's branding. Nothing attributed to Salish AI Security Lab.

Client-Facing Deliverables — 10 documents, white-label
01

AI System Inventory & Classification Register

Catalog all client AI systems with risk tier classification per EU AI Act requirements.

02

AI Risk Assessment Framework

Structured risk evaluation methodology mapped to AI Act risk tiers and Annex III categories.

03

EU AI Act Gap Assessment Template

Compare current state against applicable AI Act obligations with remediation priorities.

04

Acceptable Use Policy for AI Tools

Organization-wide policy governing AI tool usage, covering employee responsibilities and guardrails.

05

AI Vendor Risk Assessment Framework

Evaluate third-party AI vendor compliance posture and contractual requirements.

06

Data Classification & AI Input/Output Controls

Data governance controls specific to AI systems, covering input validation and output monitoring.

07

Incident Response Addendum for AI Systems

Extend existing IR plans to cover AI-specific incidents with 72-hour reporting requirements.

08

Employee AI Acknowledgment & Training Checklist

AI literacy training tracker per Article 4 requirements with sign-off documentation.

09

Compliance Roadmap Template

Timeline and milestones to the August 2026 enforcement deadline with owner assignment.

10

Executive Summary / Board Report Template

Board-ready compliance status report with risk posture, progress tracking, and recommendations.

Consultant Tools — 6 documents, for your use only
11

Client Discovery Questionnaire

30-question intake form mapped to AI Act obligations. Scopes every engagement in under an hour.

12

Engagement Scoping Guide

Pricing benchmarks, 3-tier engagement structure, and ready-to-use SOW template.

13

Objection Handling Guide

8 common client pushbacks with data-backed responses and reframes to next steps.

14

Implementation Checklist

Phase-gated project tracker with 43 pre-populated tasks mapped to toolkit deliverables.

15

AI Act Quick Reference Card

1-page, meeting-ready regulation summary. Risk tiers, key dates, penalties, obligations.

16

AI Act Article-to-Obligation Mapping Matrix

Every article mapped to specific obligations, applicable roles, and toolkit documents.

Sales Assets — 1 document, white-label
17

Prospect Presentation Deck

10-slide white-label deck with speaker notes. Cover through close — timeline, penalties, methodology, pricing, next steps.

Reference — 1 document
18

Document Map

Visual reference showing which toolkit document covers which AI Act obligations. Start here.

ROI

The Math Works on Client One

Average vCISO AI Act engagement
$5K–$15K
Hours saved per engagement
30+
Toolkit cost (one-time)
From $997

Deploy the complete framework for your first client. Recoup your investment. Every engagement after that is pure margin on top of your advisory fee.

Timeline

The Deadline Is Not Moving

August 2, 2026

Full enforcement of the EU AI Act begins. High-risk AI system requirements activate. Transparency obligations take effect for all AI systems. Regulatory authorities can impose fines and restrict market access.


The European Commission has rejected industry calls for blanket delays. The Digital Omnibus proposal may defer some Annex III obligations, but it has not been enacted and is not guaranteed.


Your clients need to be ready. You need the tools to get them there.

Why This Toolkit

Built by Practitioners, Not a Marketing Agency

Mapped to the regulation.

Every document is structured around specific EU AI Act articles and obligations. Not generic governance templates rebranded for AI.

Designed for operational use.

These are not policy documents that sit in a SharePoint folder. The toolkit includes implementation checklists, project trackers, and engagement scoping tools because compliance is a project, not a PDF.

Framework-aligned.

Structured for alignment with ISO 42001, NIST AI RMF, and SOC 2 — so the work integrates with your clients' existing compliance programs.

Licensing

Licensing

Single firm license. Up to 5 practitioners within your organization can use the toolkit. White-label rights for all client-facing deliverables — your logo, your brand, your clients. No attribution to Salish AI Security Lab required. No resale of the toolkit itself. 12 months of quarterly updates included as the EU publishes new implementation guidelines.

Pricing

Choose Your Implementation Level

All tiers include the complete 11-document compliance framework with EU AI Act article-level mappings. Higher tiers add structured implementation guidance and expert advisory.

Compliance Document Library
$997
One-time payment
  • 11 white-label compliance documents
  • EU AI Act article-level mappings
  • FRIA template (Art. 27)
  • 90-day implementation roadmap
  • Article-to-obligation mapping reference
  • 12 months of quarterly updates
Accelerator + Advisory
$4,997
One-time payment
  • Everything in Guided Implementation
  • Custom compliance gap assessment
  • 2x 60-minute live advisory sessions
  • Custom policy review with written feedback
  • Priority support through Aug 2, 2026

Secure checkout via Paddle. Instant delivery to your email. Questions? partners@salishsecurity.ai

Not ready to buy? Download the free Client Discovery Questionnaire to see the quality and depth of what is included.

FAQ

Frequently Asked Questions

Can I use this with multiple clients?
Yes. The license covers unlimited client deployments. You pay once and use the toolkit across all your client engagements.
Is this specific to the EU AI Act or generic AI governance?
Every document is specifically mapped to EU AI Act (Regulation (EU) 2024/1689) articles and obligations. This is not generic governance content rebranded.
Do I need to credit Salish AI Security Lab?
No. All client-facing deliverables are fully white-label. Replace our branding with yours. Your clients will never see our name.
What format are the documents?
DOCX (Microsoft Word) for all editable documents. XLSX for spreadsheet-based tools. PPTX for the presentation deck. PDF for reference materials. All easily customizable.
What happens when the regulation changes?
Quarterly updates for 12 months are included. As the European Commission publishes new implementation guidelines throughout 2026, we update the relevant toolkit documents and you receive the new versions.
Can my whole team use this?
The license covers up to 5 practitioners within a single firm. For larger teams, contact partners@salishsecurity.ai.
What if I already have some AI governance templates?
Many practitioners have started with free templates. This toolkit fills the gaps: consultant-side tools, engagement scoping, implementation tracking, and the regulatory specificity that free templates lack. You can integrate your existing materials alongside the toolkit.
Is there a refund policy?
We offer a 30-day no-questions-asked refund policy on all tiers. If the toolkit does not meet your expectations, contact partners@salishsecurity.ai within 30 days of purchase for a full refund.