QConsul LLC — a certified Oregon Benefit Company. Portland, Oregon, USA.
Build the governance foundation required to scale AI responsibly and maximize ROI
AI governance framework — from delivery artifact to framework reference
QConsul delivers AI programs engineered for governance from Sprint 1 — not governance added after deployment. Governance is the shape of the delivery method, not a document produced at the end, so the evidence a reviewer, a regulator, or your board asks for already exists when they ask.
The crosswalk below shows how QConsul's delivery artifacts relate to the NIST AI Risk Management Framework, ISO/IEC 42001, your own policy, and internal control objectives. Read it as QConsul's own interpretation. No standards or regulatory body issued, endorsed, or reviewed it. QConsul also runs a preliminary EU AI Act screening procedure, but has not built a comprehensive EU AI Act crosswalk — the EU column carries candidate screening references only.
Framework maturity and coverage — read this before the crosswalk
NIST coverage: QConsul catalogs all 72 subcategories of the NIST AI RMF 1.0 Core; the approved, evidence-backed crosswalk covers 39 of 72 (54.2%) as of July 24, 2026. ISO/IEC 42001 source status: QConsul's ISO material comes from an FDIS-era working document, not the published final text, and is not evidence of conformity with ISO/IEC 42001:2023. EU AI Act status: QConsul runs one v1.0 procedure for preliminary territorial-scope and risk-tier screening, and has not completed a source-pinned article catalog, an artifact-to-obligation mapping set, fleet-wide EU classifications, or evidence-backed coverage reporting.
The crosswalk
Every mapping is QConsul's interpretation, written for design and client communication. It is not a conformity assessment, a certification, or legal advice, and it does not replace your own determination or independent counsel. Framework descriptions are QConsul's paraphrases, not quotations.
| Artifact | NIST AI RMF (QConsul's reading) | EU AI Act (preliminary screening note — not mapped coverage) | ISO/IEC 42001 (QConsul's reading) |
|---|---|---|---|
| spec.md (agent specification) | Touches the Map function's theme of establishing context and intended use before build | Not formally mapped — intended-purpose fields may later support technical-documentation analysis, including Annex IV where it applies | Loosely relates to risk-and-opportunity planning in Cl. 6.1 and AI objectives in Cl. 6.2 |
| SOUL.md (alignment record) | Touches the Govern function's theme that organizational values show up in system behavior | No current mapping — SOUL.md is not an AI-literacy record and does not evidence Article 4 | Loosely relates to expressing AI policy in operational form in Cl. 5.2 |
| Oversight mode designation (HITL / HOTL / HOOTL) | Touches Manage (risk response) and Govern (accountable human roles) | Candidate future mapping: Article 14, for systems its high-risk human-oversight requirements reach — not validated against every requirement | Loosely relates to operational planning and control in Cl. 8.1 |
| RACI coverage record | Touches the Govern function's theme of clear roles, responsibilities, and accountability lines | Not formally mapped — role assignment may support later provider or deployer obligation analysis | Loosely relates to roles, responsibilities, and authorities in Cl. 5.3 |
| Evaluation and drift re-runs | Touches Measure-function themes of evaluation, tracking, and feedback over time | Candidate future mapping: Article 72 — QConsul's current practice is not an Article 72 post-market monitoring system | Loosely relates to monitoring, measurement, analysis, and evaluation in Cl. 9.1 |
| Operational decision log | Touches the Govern function's theme of documenting decisions and risk acceptance | No current Article 12 mapping — Article 12 addresses automatic system-level event logging, not a human governance decision journal | Relates to documented information in Cl. 7.5 |
| Content Credentials (C2PA) tagging | Touches Map and Measure themes of provenance and transparency to affected parties | Candidate future mapping: Article 50 transparency duties where they apply — no obligation-by-obligation validation completed | Cl. 7.4 covers communication about the AI management system generally, not provenance labeling — a loose association only |
| ROI per Token™ and the Token Minimalism Framework | Touches the Manage function's theme of allocating resources proportionate to benefit and risk | No current mapping — QConsul management objectives, not claimed EU AI Act duties | Loosely relates to measurable AI objectives in Cl. 6.2 |
| Benefit Company definition of done | Touches the Govern function's theme of weighing stakeholder impact in system decisions | No current mapping — not an Article 27 fundamental-rights impact assessment; confirm applicability with counsel | Loosely relates to needs and expectations of interested parties in Cl. 4.2 |
How this fits with your governance platform
QConsul is not a governance software vendor and will not replace your system of record. Platforms such as Credo AI and Saidot already hold the inventory, policy libraries, risk workflows, evidence stores, and reporting. QConsul helps you choose one, configure it, fill it with real delivery evidence, and run it: translating objectives, intended uses, risk appetite, and legal guidance into runnable workflows; designing the sprint cadence, decision rights, RACI, oversight thresholds, evaluation gates, and escalation paths around the platform you picked; producing and normalizing delivery evidence into your system of record; connecting governance requirements to delivery, adoption, cost discipline, and measurable business value; and handing the operating model to your legal, compliance, security, risk, product, data, and platform teams.
Preliminary EU AI Act screening — not yet a crosswalk
Many US organizations decide too quickly that the Act cannot reach them. QConsul's screening surfaces the questions worth taking to counsel: whether an EU nexus exists, which legal role you hold, and whether a use case warrants review for prohibited-practice, high-risk, transparency, or general-purpose-AI provisions. Common paths into scope include a subsidiary or reseller placing the system on the EU market, an EU-established customer deploying it, the output of a US-run system being used in the EU, a supplier embedding a general-purpose model in your product, and systems touching employment, credit, education, essential services, or biometrics — each role- and fact-dependent rather than automatic.
You receive an intended-purpose statement, a territorial-scope and role screen, a first-pass risk-tier hypothesis, a list of questions for counsel, and a work plan for any deeper assessment. You do not receive an article-by-article obligation matrix or an evidence-backed determination. The scope and classification decisions belong to your legal and compliance functions. QConsul does not provide legal advice and is no substitute for qualified counsel.
Model lifecycle and change management
Governance is applied at seven points: classify, specify, assign oversight, build and gate, operate and monitor, change and re-baseline, and retire or relaunch. Each stage has a question that must be answered and an artifact that records the answer. This lifecycle model is QConsul-original methodology.
Human oversight, named per decision class
Human-in-the-loop (HITL): a person approves before the action executes. Human-on-the-loop (HOTL): the system acts and a person monitors and can intervene, under a stated intervention SLA. Human-over-the-loop (HOOTL): a person sets the policy, boundaries, and escalation rules the system runs within, reserved for the lowest-risk, most contained work. Collapsing them into a generic "human in the loop" is the most common way an oversight claim stops meaning anything.
What QConsul is, and is not
QConsul is an embedded AI product and program leader and an AI-enabled transformation and governance practitioner. QConsul is not an AI researcher, a model lab, a foundation-model developer, a law firm, a certifying body, an auditor, or an attester — and does not issue GRC certifications, attestations, audit opinions, conformity assessments, or regulator-facing assurance. QConsul does not replace an AI governance-platform vendor; it advises and configures within the client's chosen tools. QConsul helps design and implement the governance processes that the client's legal, compliance, security, and platform teams operate within.
Scope and accountability
QConsul's entity-level benefit and impact posture is independently audited and scored annually by Benefit Corporations for Good (most recent: 92/100, 2026 — verifiable in the BCFG community directory). Engagement-level governance, sustainability, and token-discipline practices are self-defined and self-attested by QConsul on each engagement — not independently audited per-engagement, and not substitutes for client, investor, or regulatory frameworks. QConsul advises and configures; the client remains the accountable owner of AI deployment decisions, risk acceptance, regulator-facing role, vendor contracting, production operations, and the governance system of record. ROI per Token™ and Token Minimalism Framework are measurement and design framings applied to QConsul's own work and recommended to clients — not performance commitments and not fixed savings figures. The SOW and governing contract define the actual scope, role allocation, metrics, and accountabilities for any engagement and control over any on-site description.
Attribution and IP notice
Agent specification files, alignment records, human-in/on/over-the-loop oversight modes, RACI matrices, and decision logs are established or generic concepts, not QConsul inventions. QConsul owns, to the extent protectable, its specific templates, definitions, control thresholds, per-decision-class assignment practice, decision-log cadence, the seven-stage lifecycle as a sequence, the ROI per Token™, Sprint-Governed AI, Token Minimalism Framework, Human–AI Partnership, Embedded AI Program & Product Leadership, and Agent Lifecycle Pipeline framings — including the documented 18-step pipeline and QConsul's HOTL/HOOTL implementation patterns — the Benefit Company and AI governance operating model and its definition-of-done practice, and the original text, selection, and arrangement of this page. The NIST AI RMF (NIST), Regulation (EU) 2024/1689 (EU institutions), ISO/IEC 42001:2023 (ISO/IEC), C2PA (Coalition for Content Provenance and Authenticity), and BCFG marks and texts belong to their respective owners. None of the mappings on this page have been reviewed, endorsed, or approved by those bodies.
Roadmap — what this page will include in a future iteration
Planned next steps, none with a committed ship date: evidence-ID publication for each crosswalk row; validation of QConsul's ISO mapping against the final published ISO/IEC 42001:2023 text; EU screening validation with counsel; evidence portability into common governance-platform objects; and visible coverage-freshness indicators.
Frequently asked questions
What is Responsible AI Program Management?
It is program and product leadership in which governance is part of the delivery method rather than a review bolted on before launch. Every increment carries a specification, a named oversight mode, a RACI entry, an evaluation, and a logged decision. QConsul delivers it as an Embedded AI Program & Product Leadership on the Sprint-Governed AI cadence, so the evidence a governance review needs is produced by the work itself.
Does the EU AI Act apply to a US-based company?
It can, and many US organizations assume too quickly that it cannot. The regulation reaches providers and deployers outside the EU when a system is placed on the EU market, when a deployer is established in the EU, or when the output of a system is used in the EU — which can happen through a subsidiary, a reseller, an EU-based customer, or a supplier embedding your model in their product. QConsul helps organizations work through whether the Act applies to their systems, suppliers, or deployments, and what the answer implies for documentation and oversight. Legal determination stays with the client's counsel.
How is governance traceable rather than asserted?
Delivery records carry the trace. QConsul relates its artifacts to the NIST AI RMF, ISO/IEC 42001, your own policy, and internal control objectives, and the crosswalk table on this page publishes that mapping. It is QConsul's own interpretation, not an assessment any standards or regulatory body issued or reviewed, and the EU AI Act column holds preliminary screening notes rather than mapped coverage. A reviewer can follow an operating practice to the theme it addresses instead of taking a claim on faith.
What do HITL, HOTL, and HOOTL mean here?
They are three distinct oversight modes, never used interchangeably. Human-in-the-loop (HITL) means a person approves before the action executes. Human-on-the-loop (HOTL) means the system acts and a person monitors and can intervene. Human-over-the-loop (HOOTL) means a person sets the policy, boundaries, and escalation rules that the system operates within, reviewing at the aggregate rather than per action. Each agent, skill, or decision class carries a named mode.
Who decides the risk classification of a system?
The client does. QConsul produces the intended-purpose statement, the first-pass classification, and the documentation that a classification decision rests on, then works alongside the client's legal, compliance, and security functions who own the determination. QConsul is not a law firm, an auditor, a notified body, or a certifying authority, and does not perform conformity assessments.
What audit evidence does an engagement leave behind?
Specifications, oversight designations, RACI coverage, evaluation results with dates, drift re-runs, an operational decision log, and token accounting tied to ROI per Token™. These are produced sprint by sprint and handed to the client's system of record, which the client owns and operates.