A cost with no counterfactual gets deferred, and correctly. A chief financial officer looking at a $180,000 programme with no stated alternative will defer it, because nothing in the paper says what happens if they do. The opposite error is just as common: count only software licences, produce a number three or four times too low, and have the programme dismantled the first time somebody asks who is actually going to do the work. Roughly three-quarters of the cost at this scale is internal labour, and labour is the constraint that will actually bind.
Build, run, tooling, certification and inaction. Three of them are routinely mis-sized, and each one is mis-sized in a predictable direction.
Of 150 person-days a year, customer security review responses and evaluation maintenance are already being paid, usually costing more because they happen ad hoc. Present gross and net-new separately. The gross number is honest about the work; the net number is honest about the decision, and leading with gross alone is the most common reason a good case gets refused.
Accredited bodies have been quoting roughly $20,000 to $50,000 for initial ISO/IEC 42001 at mid-market scope. Implementation and gap remediation typically adds $40,000 to $150,000, which is why year-one all-in lands between $95,000 and $240,000. A quoted cost of certification naming only the audit fee is misleading by a factor of three.
Not incident probability, which is the softest number in any model and the first a finance team will attack. Deal friction is different: pull the cycle time of your last ten enterprise deals, isolate the security review stage, and count the ones where an AI question extended it. That evidence is yours and cannot be argued away with a citation.
Total compensation times a load factor of 1.25 to 1.45, divided by about 220 working days. A $150 error moves year one by roughly $17,000, so do not estimate it.
Count AI systems after a real sweep including embedded SaaS and shadow AI, then count high-risk systems separately. High-risk count is the single largest cost driver in the model.
Enterprise deals per year, average contract value, days per deal on security questionnaires, and deals delayed or lost on governance grounds in the last twelve months.
Put year-one cost against the recoverable share of the status quo, in conservative, central and optimistic cases, and re-run it at twelve months against actuals.
For a 400-person company with around 18 AI systems: roughly $80,000 of one-time internal build effort, $105,000 a year gross to run of which about a third is already being spent, and $25,000 to $55,000 a year in tooling and external services if you defer a platform purchase. Certification, if elected, is a separate $95,000 to $240,000.
Only against demand. Certify when a named deal requires it, or when three or more qualified prospects ask in a single quarter. It attests that you run a management system, not that any AI system is safe, and sophisticated buyers know the difference and will ask for your evidence pack regardless.
Usually not, but you do need to stop pretending it is free. Fund half a full-time equivalent of a named senior person and protect it in planning, reducing their delivery commitments by the same amount in writing. A dedicated hire makes sense past roughly forty AI systems, in a regulated sector, or once certification is committed.
In the worked example, $223,000 to $356,000 annually. The largest component is enterprise deal friction, followed by sales-engineering drag, shadow AI incident exposure, and remediation under duress, which runs 1.5 to 2.5 times the planned figure.
Yes, in three ways. Defer the governance platform through year one. Defer certification until a demand signal exists. And keep the high-risk system count genuinely low by calibrating the rubric properly, since evaluation is the long pole. What does not save money is skipping the register, because an incomplete register understates every downstream figure.
Lead with four operating metrics rather than the maturity score, and with the payback period rather than the cost. Registry coverage, high-risk control completeness, intake bypass rate and evidence freshness are four numbers a board can act on.
Drop your details and we'll send AI Governance Cost Calculator straight to your inbox - no spam, unsubscribe anytime.
Work through your own inputs with our engineering leads before you take it to finance, and we will pressure-test the assumptions that will get challenged. A working session, not a sales pitch. SECTION 7 - FAQ - 5 to 8 questions
Talk to our engineers