I am Mike Capela — 20+ years in the machine room, CISSP, and a working AI governance practice. I turn “we should probably look at that” into evidence your board, your auditor, and your customers will actually accept.
Capela Consulting — owner-operated. You get the practitioner, not a bench.
Yes. All four. Usually the same week.
Years in IT, infrastructure
and security
Plus a governance practice
built on NIST AI RMF
Control questions across
five AI RMF domains
Android app built and
donated to a nonprofit
Frameworks are easy to quote and hard to operate. I build the version that fits your actual stack, your actual staff, and the questionnaire that is sitting in your inbox right now.
You are about to hand a vendor your data and your liability. I will tell you what you are actually signing.
An acceptable-use policy nobody reads is not a control. It is a liability with a logo on it.
Not every workload belongs in someone else’s tenant. Some of them can never leave the building.
Governance is worthless on a network held together by hope and a decade-old firewall rule.
Everyone claims AI accelerates vendor risk work. I put it against a real vendor, with a real framework, and then published exactly where it failed.
A full Claude-assisted vendor risk assessment of Anthropic’s platform, scored across all five NIST AI RMF domains and published in the open — questionnaire, methodology, findings and the error analysis.
The interesting part is not that it worked. It is the three failure modes that showed up every single time: expecting audit scope that does not exist, refusing to look past the uploaded documents, and reading contractual boilerplate as if it were operational truth. Those are now encoded into the prompt chain.
The takeaway I will stand behind: AI is a multiplier on practitioner judgment, not a substitute for it. Anyone selling you the substitute has not read their own output.
You are not buying a twelve-week engagement to find out what you already suspected. You are buying a defensible answer and the artifacts to back it.
One working session. What AI is actually in use, who is using it, what data touches it, and which deadline is driving this. I leave with a written scope and a fixed price.
Documents, configurations, contracts and tenant reality — reviewed against the framework, with AI doing the extraction and me doing the judgment. Every finding cites its source.
A report your auditor can read and your engineers can act on: risk ratings, evidence, gaps, and a remediation order that respects what you can realistically staff.
There is no change board at a lodge. There is a bar full of people, a POS terminal that just died, and a volunteer looking at you. You either understand the system or you do not.
That is the same instinct I bring to a governance engagement. I am not interested in a policy that reads well. I am interested in the one that still works at 9pm on a Saturday when the person following it is tired and improvising.
Free thirty-minute call. No deck, no discovery invoice. Describe the deadline, the vendor, or the policy someone just asked you for, and I will tell you straight whether I am the right person for it.
Put the deadline in the subject line if you have one. I read everything myself — there is no intake queue and no account manager.
Email me→