AI Governance · Risk · Compliance Independent Practice Colorado

Everyone is
shipping AI.
Almost no one
can prove it is safe.

I am Mike Capela — 20+ years in the machine room, CISSP, and a working AI governance practice. I turn “we should probably look at that” into evidence your board, your auditor, and your customers will actually accept.

Capela Consulting — owner-operated. You get the practitioner, not a bench.

00 — What I get asked
  • “Legal wants an AI policy by Friday.”
  • “A customer sent us an AI questionnaire. Help.”
  • “Our data cannot leave the building. Can we still use AI?”
  • “Half the staff is already pasting into a chatbot.”

Yes. All four. Usually the same week.

NIST AI RMF 1.0AI Vendor RiskISO/IEC 42001 ReadinessEU AI Act ExposureLocal LLM DeploymentOllama On-PremEntra ID MigrationMicrosoft 365 & Google WorkspaceIdentity HardeningAndroid DevelopmentPolicy That People Follow
20+

Years in IT, infrastructure
and security

CISSP

Plus a governance practice
built on NIST AI RMF

18

Control questions across
five AI RMF domains

1

Android app built and
donated to a nonprofit

01 — What I do

Governance that survives
contact with reality.

Frameworks are easy to quote and hard to operate. I build the version that fits your actual stack, your actual staff, and the questionnaire that is sitting in your inbox right now.

01

AI Vendor Risk Assessment

You are about to hand a vendor your data and your liability. I will tell you what you are actually signing.

  • Mapped to NIST AI RMF 1.0 — Govern, Map, Measure, Manage, Supply Chain
  • 18-question instrument with three-tier evidence scoring
  • Findings written for legal and procurement, not for a slide
  • Reusable template so your next vendor takes days, not months
02

AI Governance Program Build

An acceptable-use policy nobody reads is not a control. It is a liability with a logo on it.

  • Model and tool inventory — including the shadow AI already in use
  • Acceptable use, human-in-the-loop, and escalation paths
  • ISO/IEC 42001 readiness and EU AI Act exposure review
  • Incident response extended to cover model and data failure modes
03

Private & On-Prem AI

Not every workload belongs in someone else’s tenant. Some of them can never leave the building.

  • Local LLM deployment with Ollama on hardware you own
  • Sanctioned internal assistants so staff stop improvising
  • Data residency, retention and training-use boundaries you can document
  • Honest cost and capability comparison against the hosted option
04

Infrastructure That Holds

Governance is worthless on a network held together by hope and a decade-old firewall rule.

  • On-prem AD to Entra ID migration and identity cutover
  • Microsoft 365 and Google Workspace tenant hardening
  • Firewall, monitoring, RMM and endpoint baselines
  • Small-team practicality — I have run the helpdesk too
02 — Published work

I did not write
a white paper.
I ran the test.

Everyone claims AI accelerates vendor risk work. I put it against a real vendor, with a real framework, and then published exactly where it failed.

Case — Open source

AI Vendor Risk Assessment: Anthropic, mapped to NIST AI RMF

A full Claude-assisted vendor risk assessment of Anthropic’s platform, scored across all five NIST AI RMF domains and published in the open — questionnaire, methodology, findings and the error analysis.

The interesting part is not that it worked. It is the three failure modes that showed up every single time: expecting audit scope that does not exist, refusing to look past the uploaded documents, and reading contractual boilerplate as if it were operational truth. Those are now encoded into the prompt chain.

“You don’t put a ten-thousand-dollar lock on a safe that holds fifty dollars of merchandise.” — Mike Capela, “I Was the Vendor Your Questionnaire Was Trying to Catch”

The takeaway I will stand behind: AI is a multiplier on practitioner judgment, not a substitute for it. Anyone selling you the substitute has not read their own output.

03 — How it goes

Three moves.
No discovery theater.

You are not buying a twelve-week engagement to find out what you already suspected. You are buying a defensible answer and the artifacts to back it.

01

Scope

One working session. What AI is actually in use, who is using it, what data touches it, and which deadline is driving this. I leave with a written scope and a fixed price.

02

Evidence

Documents, configurations, contracts and tenant reality — reviewed against the framework, with AI doing the extraction and me doing the judgment. Every finding cites its source.

03

Findings

A report your auditor can read and your engineers can act on: risk ratings, evidence, gaps, and a remediation order that respects what you can realistically staff.

04 — Receipts

Fraternal Order of Eagles

  • Designed and shipped a custom Android app — donated, no invoice
  • Rebuilt the camera system after it had been “working” for years
  • Keep the point-of-sale running on a Saturday night crowd
  • Automated the Power Hour discount so nobody has to remember it
Why this is on a consulting site

Because volunteer work is where you find out
whether someone can actually fix things.

There is no change board at a lodge. There is a bar full of people, a POS terminal that just died, and a volunteer looking at you. You either understand the system or you do not.

That is the same instinct I bring to a governance engagement. I am not interested in a policy that reads well. I am interested in the one that still works at 9pm on a Saturday when the person following it is tired and improvising.

06 — Start here

Tell me what
is on fire.

Free thirty-minute call. No deck, no discovery invoice. Describe the deadline, the vendor, or the policy someone just asked you for, and I will tell you straight whether I am the right person for it.

  • Vendor questionnaire due and nobody owns it
  • AI policy needed before the next board meeting
  • Data that legally cannot leave your building
  • Identity or infrastructure work nobody wants to touch
  • A second opinion on an assessment you already paid for
Direct line

Put the deadline in the subject line if you have one. I read everything myself — there is no intake queue and no account manager.

Email me
ResponseSame business day
First callFree, 30 minutes
Based inColorado · remote