governance · compliance · project management

Put AI to work, with governance built in.

Operational AI governance for small and mid-size organizations and public bodies, from impact assessment review to day-to-day oversight.

Start with a conversation See how it works
speaker · responsible AI summit 2026
17
years in healthcare, where records have to hold up
50+
governance controls mapped across leading frameworks
5
frameworks we work across: NIST AI RMF, ISO 42001, EU AI Act, GDPR, OMB M-25-21
55%
of AI-related failures stem from third-party AI tools, the ones bought from outside vendors
Source: BCG, Responsible AI
what we do

Governance built in, not bolted on.

Practical help for teams adopting AI, so policies, reviews, and projects work together as one system from the start.

AI governance setup

Use case intake, an AI inventory, and policies sized to your organization.

Impact assessment review

Review draft AI impact assessments, find the gaps, and coach teams to an approval-ready version with a clear record of what changed.

Compliance and documentation

Records that hold up when someone asks later, including vendor and third-party AI due diligence.

Project management

AI rollouts and compliance projects planned, coordinated, and delivered.

Team enablement

Working sessions so your people use AI well and know when to bring a human in.

ways to start

Pick the starting point that fits.

Book a call
per assessment or ongoing

Impact assessment review

Expert review of your draft AI impact assessments, with coaching until they are approval-ready.

two to three weeks

AI governance gap assessment

Compare your practices to NIST AI RMF, ISO 42001, or OMB M-25-21, and to your own policies. Leave with a prioritized fix list.

six weeks

AI Readiness Assessment

See where AI is already in use, what needs attention first, and leave with a governance plan your team can run.

what a review looks like

Specific notes, not vague feedback.

Every note points to a gap, explains why it matters, and says what a strong answer includes. Teams know exactly what to fix, and the final record shows what changed and why.

Illustrative example. Client work stays confidential.
AI impact assessment · draft 2
Section 4: Potential harms
note 1
This harm needs an owner and a mitigation. Who checks it, and how often?
note 2
“Minimal risk” needs evidence. Attach the test results or name them.
AIINTAKEASSESSDECIDEMONITOR
Our approach

From first request to ongoing oversight

One connected cycle that runs alongside your AI work, not a checklist at the end.

01
Intake
Every new AI tool or use case comes through one front door, with the questions that matter asked up front.
02
Assess
Risks, data, and people affected are reviewed at a depth that matches the stakes.
03
Decide
A named owner approves, approves with conditions, or declines, and the reasoning is recorded.
04
Monitor
Owners, review dates, and change triggers keep approved AI on track as it evolves.
how we work

Three ways to work together.

Fixed-scope projects

Defined deliverables, a set timeline, and a set price. You know what you are getting before work starts.

Ongoing support

A monthly arrangement for teams that need steady governance and project help without a full-time hire.

Subcontracting and teaming

Support for consulting firms and prime contractors that need governance or project management expertise on their teams.

  1. 01
    Discovery call
    A short conversation about what you are trying to do and whether we are a fit.
  2. 02
    Written proposal
    Scope, deliverables, timeline, and price, in plain language.
  3. 03
    Kickoff and delivery
    Scheduled working sessions and regular updates until the work is done.
  4. 04
    Ongoing support
    Everything is documented for your team, with ongoing support available to keep governance running as your AI use grows.
Remote and available nationwide
Replies within one business day
Meetings by appointment, Mountain Time
Specialists brought in on a project basis when the work calls for it
why jasta alliance

What you can count on.

Regulated-industry depth

17 years of healthcare compliance and documentation work, where records have to hold up.

Principal-led

The person who scopes your work leads it from start to finish.

Framework fluency

NIST AI RMF, ISO 42001, the EU AI Act, and OMB M-25-21, translated into steps your team can follow.

Woman-owned small business

Owned by an Air Force veteran.

about
Jasmine Luedke, Principal Consultant

Jasmine Luedke

Principal Consultant

Most organizations adopting AI don’t need a large consulting team. They need someone who understands regulated work and can build processes their people will actually use.

Jasmine has spent 17 years in healthcare, making regulated work run cleanly. She coordinated patient records with the VA healthcare system for a multi-provider radiology practice, reviewed HIPAA and PCI-DSS compliance documentation as a cybersecurity consultant, and kept documentation accuracy above 98% across thousands of genetic testing cases a year.

Through JASTA Alliance, she designed an AI governance control framework of more than 50 controls mapped to the NIST AI RMF, ISO 42001, the EU AI Act, and GDPR, along with practical templates built for small and mid-size teams. She spoke at the 2026 Responsible AI Summit North America on “AI Literacy: A Shared Responsibility?”

She is an Air Force veteran, recognized as Airman of the Quarter.

Connect on LinkedIn

Credentials

  • AI Governance training, Oxford Saïd Business School (online)
  • ISO 31000:2018 Enterprise Risk Management training
  • ISO 13485:2016 Internal Auditor training
  • IAPP AI Governance Professional (AIGP), in progress
  • Project Management Professional (PMP), in progress
  • Member, AI Governance Collective
  • Speaker, Responsible AI Summit North America 2026: “AI Literacy: A Shared Responsibility?”
Speaking
“AI Literacy: A Shared Responsibility?”
Responsible AI Summit North America, Chicago, 2026 →
Questions

Common questions

Who does the work?

Jasmine leads every engagement and brings in specialists when the work calls for it.

Do you work with small organizations?

Yes. Our services are sized for small and mid-size teams that do not have a dedicated AI governance function.

Do you replace our legal counsel?

No. We build the governance processes and documentation. Your legal counsel reviews anything with legal implications.

Can you work as a subcontractor or teaming partner?

Yes. We support consulting firms and prime contractors that need AI governance expertise on their teams.

Do you work remotely?

Yes. All engagements are remote, with scheduled working sessions and regular updates.

public sector

Government and contracting teams

JASTA Alliance is available for direct engagements, subcontracting, and teaming.

Download capability statement (PDF)

State and local

AI use policies and staff training for agencies, counties, cities, school districts, and colleges, aligned to the NIST AI Risk Management Framework and New Mexico’s generative AI guidelines.

Federal

Support for OMB M-25-21, including AI use case inventories, high-impact AI determinations, AI impact assessments, and ongoing governance operations.

Primes and consulting firms

AI governance subject matter expertise for your teams, as a subcontractor or teaming partner.

UEI
WVLYH6YXDGL8
CAGE
9V6J8
Business type
Woman-owned small business, owned by an Air Force veteran
PSC
R408 Program Management/Support
R406 Policy Review/Development
R410 Program Evaluation/Review/Development
R499 Other Professional Services
U099 Education/Training, Other
NAICS
541611 Administrative and General Management Consulting
541618 Other Management Consulting
541690 Other Scientific and Technical Consulting
contact

Let’s talk.

Tell us a little about what you are working on. You will hear back within one business day.

jasmine@jastaalliance.com (575) 489-6627
Start with a conversation