Skip to content
AI governance for regulated professional services

AI governance built for law firms, RIAs & insurance agencies, not IT departments.

Your attorneys, advisors, or producers are already using ChatGPT. Your governance platform options were built for Fortune 500 security teams with 200-seat minimums. Oathmark closes that gap — for firms with 10 to 500 people, mapped to the rules that actually govern your practice: ABA Model Rules for law firms, FINRA/SEC/NASAA guidance for advisory practices, and NAIC/NYDFS bulletins for insurance agencies.

81%

of employees use AI tools their employer never approved

Source: ISACA, 2025
9%

of law firms have an enforced AI use policy

Source: 8am 2026 Legal Industry Report
78%

of RIAs have no written policy governing AI use

Source: ISS Market Intelligence Advisor Pulse, 2025
55%

of independent insurance agencies have no written AI use policy

Source: Big "I" ACT Technology Trends Report, 2026
How it works

From shadow AI to a client-ready attestation.

Four steps, no black box, no IT department required.

01

Discover

Find every AI tool actually in use across the firm — not just the ones IT approved.

02

Score

A transparent, rules-based readiness score — not a black-box AI opinion you have to trust blindly.

03

Explain

Every flag cites the exact bar rule, FINRA/SEC/NASAA guidance, or NAIC/state insurance bulletin it touches, in plain English.

04

Attest

Generate a dated report you can show clients, malpractice carriers, or regulators.

Free AI Exposure Check

See your firm's AI governance score in three minutes.

Answer a few questions about the tools your team actually uses. Get a transparent score, cited flags, and a starter policy checklist — instantly, and entirely in your browser.

1
Firm Profile
2
AI Tools
3
Governance
4
Results
5
Insurance

Tell us about your firm

This helps us apply the right jurisdictional rules to your results.

Firm type
Firm size
Jurisdictions (select all that apply)

Which AI tools are actually in use?

Self-report below, or scan your connected Gmail for real sign-up and notification emails from AI vendors — no guessing required.

Scan your inbox for real signals

We search your connected Gmail for genuine welcome, receipt, and notification emails from AI vendors — evidence, not guesswork.

Governance practices

These answers weigh heavily on your final score — governance gaps compound tool-level risk.

Do you have a written AI use policy?
Do you provide AI training to attorneys/staff?
Do you have a formal process to vet new AI vendors before adoption?
To your knowledge, has anyone at the firm entered confidential client information into a general-purpose AI tool?

Your AI governance snapshot

Based on your answers — a transparent, rules-based score with cited flags.

Governance readiness score gauge 0 OUT OF 100
Governance readiness
Self-assessment score

Sample AI Use Policy — What Yours Should Cover

    Email your results & unlock the PDF report

    Enter your email to save this snapshot to your Oathmark record and unlock a downloadable PDF copy for your files.

    This free check is a snapshot. Oathmark's full Audit & Attestation Report documents every finding with a dated, client-ready attestation.

    Your Insurance Renewal Package

    Carriers are adding AI-specific questions to renewal applications. Here's what your answers are ready to export — and what's still a gap.

    The Insurance Renewal Package formats these answers for Aon, WTW, and CNA AI supplemental questionnaires — dated and ready to attach to your renewal application.

    This self-assessment is for general informational purposes. It is not legal advice and does not replace a jurisdiction-specific ethics review.

    Why existing tools don't fit

    Enterprise AI governance platforms weren't built for your firm.

    Credo AI, Holistic AI, OneTrust, Harmonic Security, and Vanta all sell to CISOs. Nobody is mapping controls to your bar rules, your FINRA/SEC/NASAA obligations, or your state insurance bulletins.

      Enterprise AI governance platforms Oathmark
    Buyer CISO / IT security team Managing partner / General Counsel / Principal / Agency owner
    Price $30,000 – $500,000 / year $6,000 – $18,000 / year
    Rules mapped to NIST, ISO 42001, EU AI Act (generic) ABA Model Rules & state bar opinions, FINRA/SEC/NASAA guidance, NAIC/NYDFS bulletins, EU AI Act deployer duties, malpractice/E&O-carrier expectations
    Minimum firm size 200-seat minimums, typically Works from 10 employees
    On the roadmap next

    From an annual snapshot to always-on governance — and ready for your insurance renewal.

    The free check and audit are the starting point. Two expansions turn Oathmark into infrastructure a firm can't cancel: continuous discovery instead of self-report, and a report built for the questions your insurer is already asking.

    Browser extension · continuous discovery

    Continuous Monitoring

    A lightweight browser extension replaces the self-reported intake form, so your governance score updates as tool usage actually changes — not once a year.

    Add-on · $500–$2,000 / renewal

    Insurance-Ready Reports

    Carriers now ask AI-specific underwriting questions at renewal. This export answers them directly — no separate compliance project required.

    Insurers are already asking: Aon and WTW add AI underwriting questions at renewal (The Crossing Report), CNA sends AI supplemental questionnaires (Chronexa), and Verisk's new endorsements let carriers exclude AI claims without documentation (Traverse Legal).

    Pricing preview

    Priced for a 10-500 person firm — not a Fortune 500 IT budget.

    Audit & Attestation

    $3,000 – $8,000

    One-time engagement. Get an audit-ready attestation report in weeks, not months.

    • Full AI tool discovery across the firm
    • Dated, client-ready attestation report
    • Cited findings mapped to bar rules

    Multi-Office / Enterprise

    Contact us

    For firms with multiple offices or 500+ employees.

    • Multi-office rollout and reporting
    • Custom jurisdictional rule mapping
    • Dedicated onboarding