Frequently Asked Questions
Answers about Trocola, the CT Framework, certification, shadow AI and risk. Can't find what you need? Contact us.
Showing 19 of 19 questions
Trocola does not guarantee specific outcomes including insurance premium reductions, coverage decisions, litigation results, revenue, or regulatory safe harbor. Answers on this page are for information only and are not legal, financial, or insurance advice. Consult qualified counsel for advice specific to your organization.
About Trocola
What Trocola is, what we do, and why AI governance matters right now.
Trocola puts your AI decisions back with the people who run your business, using the controls they already know how to run. We place trained AI leadership inside organizations, find the AI already running unmanaged in the background, and build the operating discipline to use AI deliberately. Trocola publishes the CT Framework and issues Trocola certifications against it.
Three forces are converging. First, buyers are demanding it: enterprise RFPs increasingly ask for AI compliance documentation before awarding contracts. Second, litigation is accelerating: Workday lost $9.2 billion in market cap after courts certified a collective action covering 200,000 applicants who alleged bias in its AI hiring system. Third, insurers are enforcing it: 68% of cyber liability carriers either exclude AI claims outright or require documented compliance before covering them.
Forbes, Harvard Business Review, and McKinsey document the same 70-80% AI project failure rate. The failures are almost never technical. They are governance failures: no policies, no audit trails, no bias testing, no employee training. The CT Framework addresses exactly this gap.
The CT Framework is Trocola's methodology for AI governance and compliance. It is organized around three pillars:
- Know Your Stack: AI inventory, vendor due diligence, risk classification, and data flow documentation. You cannot protect what you cannot see.
- Protect AI: Bias testing, human oversight requirements, incident response, and employee training. AI without controls creates liability.
- Compliance Lock: Ongoing monitoring, audit evidence, and trails that demonstrate continuous compliance over time.
Every control in the CT Framework maps to an existing regulation or standard: NIST AI RMF, ISO 42001, EEOC guidelines, GDPR, CCPA, HIPAA, or the EU AI Act. Nothing is invented. Built in the field across 27 companies in six industries, the CT Framework has protected more than $500 million in regulated contracts.
SOC 2 asks: "Do you have access controls?" and accepts yes or no. The CT Framework asks: "Show me your OAuth revocation SLA, test it live, prove it terminates within 24 hours, and document the evidence chain." SOC 2 is a snapshot of IT controls. The CT Framework is AI-specific and built for ongoing monitoring.
ISO 42001 is a framework developed in Europe that commonly takes two or more years to implement and is built for large enterprises. The CT Framework is built on US regulatory requirements including NIST AI RMF, EEOC guidelines, CCPA, and HIPAA. The two are complementary, not competitive.
No. Trocola certification is attestation against the CT Framework. It is not a government-issued certification, does not create a legal safe harbor, and does not guarantee immunity from regulatory enforcement or litigation.
What it does is create a defensible audit trail demonstrating reasonable care. When a lawsuit is filed or a regulator investigates, certified organizations can show they built governance systems, tested for bias, trained employees, and maintained documentation. We recommend that every organization also retain qualified legal counsel appropriate to its jurisdiction and industry.
Certification
The Trocola catalog, how to choose a level, and what certification does and does not do.
The Trocola catalog includes Shadow AI Practitioner, AI Professional Series 1, Series 2 and Series 3, AI Strategist, and Corporate AI Strategist. More than 100 people are certified against the CT Framework across the catalog. See Certifications for each level.
Series 1 (AI Professional) is the starting point and the prerequisite for the advanced levels. If you are not sure, book a call and we will walk through your experience, your goals, and which certification gets you there.
The AI Corporate Strategist Certification Seminar runs January 27, 28, 29, 2027 in Tucson, Arizona. Every seat includes the Trocola AI Corporate Strategist Certification, live training, breakout sessions with certified consultants, the tool library, and a Q1 action plan. See the seminar page for packages.
No. Certification reduces documented risk. It does not eliminate it. Anyone can file a lawsuit, and regulators can always investigate. What certification creates is a defensible position: documented evidence of bias testing, vendor due diligence, employee training, incident response, and an audit trail that demonstrates reasonable care.
Working With Trocola
How engagements are scoped and what happens when they end.
Every engagement is scoped before it begins. Cost and timeline depend on the number of AI systems, their risk, and how much remediation is needed. Trocola provides a specific estimate during the scoping conversation, before any engagement starts.
Yes. Organizations can implement the three pillars on their own, and many start that way. Self-implementation does not result in Trocola certification. If you complete the work yourself and later want certification, Trocola can review your existing work and credit it toward the engagement.
The organization keeps the trained leadership and the documentation, with the option to retain Trocola in an advisory capacity if wanted. We build the department, train your operators, and leave.
Shadow AI
Understanding unauthorized AI use and how to find and govern it in your organization.
Shadow AI is any AI tool, model, agent, or AI-powered feature used by employees or contractors for work without explicit organizational approval, documentation, or governance oversight. This includes tools that were individually approved by a manager but never formally vetted at the organizational level.
The highest-risk shadow AI processes organizational data, including client records, financial information, HR data, or proprietary business information, without IT knowledge or security review. A common example is an employee using a consumer chatbot account to draft client communications or analyze internal data.
Shadow AI creates three categories of concrete risk:
- Data leakage: client data, proprietary processes, or personal information submitted to consumer AI tools may be stored outside your data processing agreements. This can violate GDPR, CCPA, HIPAA, and client confidentiality obligations at the same time.
- Bias and accuracy exposure: outputs from ungoverned tools used in hiring, lending, or customer decisions create the same legal exposure as formally deployed systems.
- Policy and practice misalignment: if your privacy policy promises customers their data is not processed by third-party AI and employees are doing it anyway, the policy is false.
Most AI vendor agreements state that the client organization is responsible for ensuring its use of the tool complies with applicable law.
Trocola's discovery protocol uses six methods in sequence: an anonymous, non-punitive employee survey; an IT asset management review; network traffic analysis; expense report review; code repository scanning; and structured department manager interviews.
The goal is comprehensive disclosure, not punishment. The objective is to find the tools, govern them, and build an approved list.
Discovery is the beginning of governance, not the end. Classify each tool by risk using the CT Framework's four-question method. Approve what can be approved, with vendor due diligence and a data processing agreement. Replace what cannot be approved with sanctioned alternatives, and communicate the change clearly. Publish an AI approved list, and keep an anonymous disclosure channel open so new shadow AI is reported before it becomes an audit gap.
Insurance & Risk
How documented AI governance connects to insurance and risk.
Trocola does not guarantee any specific insurance outcome, premium reduction, or coverage decision. Coverage determinations are made by your carrier based on your policy, your organization, and the carrier's own underwriting. Certified organizations have documentation of their compliance posture they can bring to a coverage conversation. What a carrier does with it is the carrier's decision.
Review your policy language now. Many cyber liability carriers have added AI exclusions or compliance preconditions since 2024. Common patterns exclude claims from AI systems not disclosed at policy inception, bias claims where the insured had no documented bias testing, and AI deployed in a regulated industry without compliance documentation. Ask your broker for a coverage review that specifically covers AI-related claims before an incident occurs.
Any organization deploying AI in decisions that affect people has exposure. The most urgent are financial services (FCRA, ECOA), healthcare (HIPAA, FDA), human resources and staffing (EEOC enforcement and cases like Mobley v. Workday), technology companies building AI features, and legal and professional services.
No questions match your search. Try different keywords, or contact us.