QConsul LLC — an Oregon Benefit Company. Portland, Oregon, USA.
Governance built into delivery, not reviewed after launch
AI governance framework — from delivery artifact to framework reference
QConsul runs your AI program in governed sprints. Oversight modes, specifications, evaluations, and decision logs come out of the delivery work, so the evidence your board or auditor asks for already exists when they ask for it. This page is a readiness aid — not a certification, audit, or legal advice.
July 2026. The NIST AI RMF, ISO/IEC 42001, and the EU AI Act keep evolving, and so does this page. Read it as an example of the type of governance scope an engagement can cover — the SOW and the client's own downstream requirements define the actual scope, artifacts, and accountabilities.
What QConsul does — governance frames the loop, so it is set before anything is built
The QConsul AI Transformation System™ runs as one loop — Discover, Prioritize, Build, Improve. Governance is not a phase. It frames all four, because oversight, controls, evidence, and token budgets cost less to design in before the Build phase than to retrofit after it. See the loop diagram on Services.
Concretely, the ROI per Token™ target and the oversight mode are set in Prioritize, the evidence is produced by the delivery work in Build under Sprint-Governed AI, and both are re-checked against the target in Improve — every turn of the loop, not once at launch.
The governance work that applies to a given engagement — oversight modes per decision class, which delivery artifacts serve as evidence, how token budgets are set and reported, and whether QConsul touches a governance platform your teams already run — is scoped in the SOW, not assumed here.
What QConsul does not do
No certification, audit, or assurance: QConsul is not a law firm, certifying body, auditor, or notified body, and issues no attestations or conformity assessments. No legal determinations: risk classification, EU AI Act scope, filings, and risk acceptance stay with your legal and compliance functions; QConsul supplies the intended-purpose statement, a first-pass screen, and the questions worth taking to counsel. No governance software: QConsul configures the platform you pick and sells no competing tool. No model research: QConsul is not a model lab or foundation-model developer; it leads AI product and program delivery.
The crosswalk
This is QConsul's own reading of how its delivery artifacts relate to themes in the NIST AI RMF 1.0 and ISO/IEC 42001:2023, current as of July 2026 and revised as those frameworks change. It is not an assessment, certification, or legal advice, and no standards or regulatory body reviewed it. The EU AI Act is handled as a scope-and-risk-tier screening exercise with your counsel, not mapped here.
| Artifact | What it is | Framework themes it addresses |
|---|---|---|
| spec.md (agent specification) | Mission, scope boundaries, refusal conditions, and success criteria, written before the agent is built. | Establishing context and intended use before build. |
| SOUL.md (alignment record) | The values, tone, and non-negotiables an agent carries across tasks, kept separate from the task specification. | Organizational values expressed in system behavior and policy. |
| Oversight mode designation (HITL / HOTL / HOOTL) | A named oversight mode assigned per agent, per skill, or per decision class — never assumed by default. | Human oversight roles and risk response. |
| RACI coverage record | Named responsible, accountable, consulted, and informed parties for every agent and skill QConsul catalogs. | Clear roles, responsibilities, and accountability lines. |
| Evaluation and drift re-runs | Dated evaluations at launch, re-run when the environment shifts, with the spec tightened in response. | Evaluation, monitoring, and feedback over time. |
| Operational decision log | A dated record of governance decisions, trade-offs accepted, and who accepted them. | Documented decisions and recorded risk acceptance. |
| Content Credentials (C2PA) tagging | Visible provenance indicators on AI-generated imagery, with the inventory published in ai.txt. | Provenance and transparency to affected parties. |
| ROI per Token™ and the Token Minimalism Framework | Compute treated as a governed budget line — measured per engagement, reported against your KPIs. | Resources allocated in proportion to benefit and risk. |
| Benefit Company definition of done | A sprint exit criterion that tests value across people, planet, and profit, not technical completion alone. | Stakeholder impact weighed in system decisions. |
What's outstanding — known gaps
QConsul reports its own mapping status here; none of it is a third-party audit finding. NIST coverage: QConsul catalogs all 72 subcategories of the NIST AI RMF 1.0 Core; 39 of 72 (54.2%) are evidence-backed as of July 24, 2026. ISO/IEC 42001 source status: QConsul's ISO material comes from an FDIS-era working document, not the published 2023 text, and reconciling it against the final publication is outstanding. EU AI Act status: QConsul screens territorial scope and risk tier as a readiness exercise; there is no artifact-to-obligation mapping, and this page is not an EU AI Act crosswalk.
Scope and accountability
QConsul's entity-level benefit and impact posture is publicly reported annually as an Oregon Benefit Company (the pillar commitments and their progress are published on the QConsul purpose page). Engagement-level governance, sustainability, and token-discipline practices are self-defined and self-attested by QConsul on each engagement — not independently audited per-engagement, and not substitutes for client, investor, or regulatory frameworks. QConsul advises and configures; the client remains the accountable owner of AI deployment decisions, risk acceptance, regulator-facing role, vendor contracting, production operations, and the governance system of record. ROI per Token™ and Token Minimalism Framework are measurement and design framings applied to QConsul's own work and recommended to clients — not performance commitments and not fixed savings figures. The SOW and governing contract define the actual scope, role allocation, metrics, and accountabilities for any engagement and control over any on-site description.
Attribution and IP notice
The QConsul AI Transformation System™ and ROI per Token™ are QConsul marks. QConsul also retains copyright in its original materials: the artifact templates and content structures for spec.md and SOUL.md, the decision-log template and cadence, the documented Agent Lifecycle Pipeline, and the text, diagrams, and arrangement of this page. The underlying concepts — agent specifications, alignment records, oversight modes, RACI, decision logs — are established practice, and QConsul claims no ownership of them or of the generic filenames spec.md and SOUL.md. The NIST AI RMF (NIST), Regulation (EU) 2024/1689 (EU institutions), ISO/IEC 42001:2023 (ISO/IEC), and C2PA (Coalition for Content Provenance and Authenticity) marks and texts belong to their respective owners. None of them reviewed, endorsed, or approved anything on this page.
Frequently asked questions
What is Responsible AI Program Management?
Program and product leadership in which governance is part of the delivery method rather than a review bolted on before launch. Every increment carries a specification, a named oversight mode, a RACI entry, an evaluation, and a logged decision. QConsul delivers it as Responsible AI Program & Product Leadership on the Sprint-Governed AI cadence, so the evidence a governance review needs is produced by the work itself.
Does the EU AI Act apply to a US-based company?
It can, and many US organizations assume too quickly that it cannot. The regulation can reach organizations outside the EU through an EU subsidiary, a reseller, an EU-based customer, or output used in the EU. Whether any of those paths applies depends on your facts, contracts, and role. QConsul helps you frame the question as a readiness exercise; your counsel makes the determination.
What do HITL, HOTL, and HOOTL mean here?
Three distinct oversight modes, never used interchangeably. Human-in-the-loop (HITL) means a person approves before the action executes. Human-on-the-loop (HOTL) means the system acts and a person monitors and can intervene, under a stated intervention SLA. Human-over-the-loop (HOOTL) means a person sets the policy, boundaries, and escalation rules the system operates within, reviewing in aggregate rather than per action. Each agent, skill, or decision class carries a named mode.
How does QConsul govern AI agents in practice?
QConsul is a guide for both AI agents and the human teams around them — a 'consul,' not legal 'counsel.' QConsul does not replace an AI governance platform and does not provide GRC certification, audit, attestation, or legal advice. Strategy and program leadership come first; hands-on build capability shows up when it serves the engagement, and QConsul introduces clients to independent specialists for dedicated implementation work at scale. QConsul brings in-house design frameworks that complement the client's platform of choice to define scope, checks, thresholds, constraints, and KPIs as a concrete, business-maintained governance method.
Start the conversation
Start the conversation — book a discovery call with QConsul. Or begin with the on-ramp engagement: Start a Tune-Up Start to baseline your business before building.