NIST AI Governance for Law Firms

From ABA Rule
to NIST AI RMF — documented.

Your firm's AI adoption is outpacing its governance. Modern Data Decisions translates the ABA Rules of Professional Conduct into concrete, documented controls aligned with the NIST AI Risk Management Framework — giving your firm the governance portfolio it needs to evidence reasonable practices and move forward with confidence.

Federal-grade governance. Built for legal practice.

Not ready for an engagement? Begin the same methodology yourself — today.

The Firm

Governance built for the adversarial environment.

"Most firms are paralyzed — they see the efficiency gains AI offers, but they cannot quantify the risk. We eliminate that paralysis by replacing ambiguity with documented, auditable controls."

Modern Data Decisions exists to bridge the gap between the rapid adoption of generative AI and the stringent ethical and security demands of legal practice. We move law firms from a state of prohibited or reckless use to defensible, governed integration — using the same governance frameworks trusted by the federal government.

Our singular differentiator is the ability to map ABA Rules of Professional Conduct directly to NIST AI Risk Management Framework controls. We do not offer general advice. We build the evidence of reasonable governance practices — the documented, testable record that positions your firm before an insurance carrier, a disciplinary board, or a demanding corporate client ever asks the question.

What we are not

A law firm, a technology vendor, or a training provider. We do not sell software, provide legal advice, or receive referral fees from AI companies.

What we are

An independent AI governance advisory. We build the governance portfolio that lets your firm demonstrate — not just claim — that its AI use meets the highest professional standards.

Start Here  ·  Self-Serve

The AI Governance Baseline Toolkit

The first rung of our methodology — in your hands, today. A professional, NIST-aligned self-assessment your firm completes itself, producing the dated documentation that helps demonstrate you took AI governance seriously before anyone asks.

$299 one-time · yours to keep
Get the Toolkit — $299 →

Designed to support your firm's insurance applications and help evidence reasonable AI governance practices consistent with ABA Formal Opinion 512 and your jurisdiction's Rules of Professional Conduct. Self-serve and self-attested — not independently validated.

What's Inside

  • AI Acceptable Use Policy — fillable, ready to adopt and sign
  • AI tool inventory with a plain-English risk-scoring matrix
  • Vendor Due Diligence Checklist for every tool that touches client data
  • Incident Response Mini-Plan a non-technical office manager can run
  • Red / Yellow / Green governance scorecard for your carrier and managing partner
  • Roadmap showing precisely where self-service ends and an engagement begins

Delivered as a polished fillable PDF and an editable Word document. Built on the four functions of the NIST AI Risk Management Framework — the same framework our professional engagements run on.

Guided

The Guided Self-Assessment — $950

The bridge between doing it yourself and a full engagement. You complete the Baseline Toolkit; we join you for a focused working session to validate your highest-risk findings and tell you, precisely, where to act first.

$950
Book a Guided Session →

For firms that want an expert's eyes — and a clear next step — without committing to a full assessment.

What's Included
  • A guided working session with your team — and your IT lead, if you have one
  • Live review of your completed inventory and scorecard
  • Your top exposure points, identified and prioritized
  • A short written summary of findings for your file

When your firm needs independent validation — because a carrier, a board, or a client is asking — the engagements below carry it the rest of the way.

Services & Pricing

Every step. One standard of rigor.

Most firms start where they are and move up as the stakes rise. Every step builds on the same framework — so nothing is ever "starting over."

Self-Serve

AI Governance Baseline Toolkit

$299 one-time

A complete, NIST-aligned self-assessment your firm runs on its own — producing the dated documentation that helps evidence reasonable AI governance practices before anyone asks.

  • AI Acceptable Use Policy, ready to adopt and sign
  • AI tool inventory with plain-English risk-scoring matrix
  • Vendor Due Diligence Checklist and Incident Response Mini-Plan
  • Red / Yellow / Green governance scorecard
  • Roadmap to professional assessment
Fillable PDF + Editable Word document  ·  Self-attested
Get the Toolkit — $299 →
Guided

Guided Self-Assessment

$950 per session

You complete the Baseline Toolkit. We join you for a focused working session to validate your highest-risk findings and tell you precisely where to act first.

  • Live review of your completed inventory and scorecard
  • Top exposure points identified and prioritized
  • Guided session with your team and IT lead
  • Written summary of findings for your file
Working session + written summary  ·  Expert-reviewed
Book a Guided Session →

Engagements are project-based and scoped to your firm's size and complexity. All engagement pricing is discussed during your initial consultation — there is no obligation.

How We Work

The Governance Artifacts.

In the legal profession, if it isn't documented, it didn't happen. Every Modern Data Decisions engagement produces a governance portfolio — a structured, defensible record of your firm's AI competence that you can present to your insurance carrier, your board, or your most demanding corporate client.


Begin an Engagement

AI Governance Baseline Report The Audit

A comprehensive gap analysis document. We place your current AI usage side-by-side against NIST AI Risk Management Framework standards, identify specific high-risk areas, categorize them by exposure level, and produce a prioritized remediation roadmap. This is your evidence of due diligence — the document you present if an insurance provider, bar association, or client ever questions your security posture.

Artifact: AI Governance Baseline Report

The Defensible AI Policy Playbook The Governance

A living document of firm-wide AI governance policy. It contains clear, actionable directives on acceptable AI use, sensitive data handling protocols, and mandatory human-in-the-loop verification requirements for AI-generated work product. It directly maps each policy directive to its corresponding ABA Rule and NIST control, so the chain of documented governance is unambiguous and auditable. This standardizes behavior across the entire firm — eliminating rogue-use risk at every level.

Artifact: Defensible AI Policy Playbook

AI Workflow Architecture The Implementation

A series of documented procedural diagrams showing exactly how your firm's research, drafting, and discovery workflows are governed. Each diagram identifies where human review checkpoints occur and maps them to the ABA supervisory requirements under Rule 5.3. This demonstrates to regulators that your firm is not simply using AI — it is systematically supervising it in accordance with professional conduct rules.

Artifact: AI Workflow Architecture Diagrams

AI Readiness Scorecard The Ongoing Metric

A dynamic governance health metric delivered quarterly to retainer clients. It quantifies your firm's AI risk exposure, tracks the controls implemented to mitigate it, and provides an executive-level summary your managing partners can present to clients, insurers, or boards. As the regulatory landscape evolves, your scorecard evolves with it — ensuring your governance posture never falls behind the standard of care.

Artifact: Quarterly AI Readiness Scorecard
Tamara Jones, Founder of Modern Data Decisions

Portrait generated by AI. Modern Data Decisions embraces the power of AI, while maintaining the human oversight required to govern it safely.

Founder & Principal Advisor

Tamara Jones

Information System Security Manager (ISSM) · CGRC · Security+

Tamara J. Jones brings 24 years across cybersecurity, governance, and regulated federal environments to Modern Data Decisions. Her career has been defined by applying federal security frameworks to live environments where the documentation has to survive real scrutiny — including systems supporting the Department of Defense and the Intelligence Community at the highest levels of federal trust and vetting.

As a Certified in Governance, Risk, and Compliance (CGRC) professional and Information Systems Security Manager (ISSM), Tamara specializes in AI Risk Governance, NIST Risk Management Framework implementation, security compliance posture management, and Agile Leadership. She holds CompTIA Security+ and brings the governance rigor of the most demanding federal compliance environments to every engagement.

As founder of Modern Data Decisions, Tamara translates that federal-grade discipline to the legal sector — helping law firms build defensible AI governance frameworks that can withstand regulatory scrutiny, bar inquiries, and client challenge.

Education: M.S. in Management Information Systems, B.S. in Computer Technology — Bowie State University

Read the full bio →

ISSM ISC2 CGRC CompTIA Security+ NIST RMF / 800-53 DoD & IC Experience AI Risk Governance Agile Leadership
Free Resource

Can your firm defend its AI use?

Download the free AI Governance Risk Check — a 10-point self-assessment for small law firms. See your exposure before a carrier, client, or court asks.

Takes about two minutes to complete
Identifies the gaps most small firms don't know they have
Shows you exactly where the Baseline Toolkit picks up
Delivered immediately to your inbox — no account required

This checklist is a high-level diagnostic tool, not legal advice, and does not by itself establish or help evidence compliance or coverage. Modern Data Decisions provides governance guidance only and creates no attorney-client relationship.

Free — Instant Download
The AI Governance Risk Check

A 10-point self-assessment that shows you exactly where your firm's AI exposure sits — before a carrier, client, or court asks. Takes about two minutes.

✓  Identifies gaps most small firms don't know they have
✓  Shows where the Baseline Toolkit picks up
✓  Delivered instantly — no account required
Get the Free Risk Check →

You'll enter your email at checkout to receive the download. We may send occasional governance updates — unsubscribe anytime.

Advisory Board

Practitioners who have built the field.

Our advisors bring decades of hands-on experience in AI research, cybersecurity, encryption, and technology education — the disciplines that underpin every governance decision we make.

Dr. Lethia S. Jackson

Dr. Lethia S. Jackson

Academic Advisor — Artificial Intelligence & Cybersecurity

Associate Dean of the School of Cybersecurity and Information Technology at the University of Maryland Global Campus, and former Founding Chair of the Department of Technology & Security at Bowie State University. Over two decades of academic leadership spanning Artificial Intelligence, Data Science, Quantum Computing, Cybersecurity, and Internet of Things research. Principal Investigator or Co-PI on more than $4 million in funded projects from the National Institutes of Health, the National Science Foundation, the National Security Agency, and other federal agencies — supporting cybersecurity workforce pipelines, digital transformation, and STEM research programs. Led institutional efforts for ABET accreditation and National Centers of Academic Excellence in Cybersecurity designation.

Doctor of Science, Computer Science — George Washington University M.S. Computer Science — North Carolina State University B.S. Computer Science — North Carolina A&T State University
Charles Jackson III

Charles Jackson III

Technical Advisor — Cloud Security & AI Security Architecture

Currently serving as a Cloud Security Consultant at Epic Cyber, where he supports enterprise cloud security operations across three organizations simultaneously — centralizing security and vulnerability management logs, designing alerting strategies based on industry best practices, and automating response workflows using AI-assisted automation tools. He strengthens executive decision-making by consolidating vulnerability data into cleaner, more actionable dashboards for leadership and cross-functional teams. His broader career spans Northrop Grumman supporting Department of Defense systems, Glassdoor, eBay, Omnicell, Blue Apron, and Forward Edge AI. Co-architect of a Tier 1/Tier 2 AI Security Automation framework for intelligent alert triage. Encryption expertise spans enterprise key management via Vormetric Data Security Manager, multi-layered encryption protocol architecture, and quantum-resistant encryption device development for Department of Defense environments. Built vulnerability management and incident response programs from the ground up, and has led governance framework implementation for SOC 2 and CIS20.

B.S. Computer Networking & Systems Administration — Bowie State University AWS Security Specialty GIAC Certified Incident Handler (GCIH) CompTIA Advanced Security Practitioner (CASP) Certified Ethical Hacker (CEH) Certified Hacking Forensic Investigator (CHFI)
Alauna Jackson

Alauna Jackson

Technical Advisor — Information Systems Security & Federal Compliance

Information Systems Security Officer with over a decade of experience maintaining security posture and operational compliance for systems supporting Department of Defense and federal agency environments. Currently serving as an ISSO at AT&T through VikTech LLC, her work spans the full Authority to Operate lifecycle — developing System Security Plans, enforcing NIST SP 800-53 security controls through continuous monitoring, validating system patches, managing vulnerability mitigations, and obtaining final ATO status for classified and sensitive systems. At the U.S. Census Bureau Security Operations Center, she built and maintained Splunk dashboards for security analytics and incident metrics, monitored compliance per the NIST Risk Management Framework, and led incident detection and response across the enterprise. At Chenega Federal Systems, she developed and implemented processes and procedures for NIST 800-171 and NIST 800-53 compliance from the ground up — running vulnerability scans, producing findings documentation, and building the security practices that brought federal systems into alignment with DoD cybersecurity requirements. Technical capabilities span Splunk SIEM engineering and tuning, AWS cloud security and C2S environment compliance, Python scripting, Selenium automation, MySQL database administration, and systems engineering at Northrop Grumman. A Software Engineer alumna of both NASA Goddard Space Flight Center and the National Institute of Standards and Technology SURF program.

M.S. Information Systems — Bowie State University B.S. Computer Technology — Bowie State University CompTIA Advanced Security Practitioner (CASP+) CompTIA Security+ Certified Ethical Hacker (CEH) Certified Network Defense Architect AWS Certified Cloud Practitioner
Elesha Jackson

Elesha Jackson

Technical Advisor — Artificial Intelligence, Machine Learning & Secure Systems

Technical Product Manager at Forward Edge AI, where she leads development of quantum-resistant encryption devices for Department of Defense and National Security Agency environments. Former Artificial Intelligence and Machine Learning Engineer delivering anomaly detection, edge AI, and federated learning solutions for defense and healthcare. Applied Explainable AI and federated learning techniques to enhance model transparency and data privacy in mission-critical systems. Integrated Microsoft Azure Cognitive Services and natural language processing capabilities into Department of Defense and healthcare interfaces. Former Adjunct Professor at Bowie State University teaching Linux Systems and Security Foundations. Holds an Active Public Trust Clearance.

M.S. IoT Security & Internet Technologies — Bowie State University B.S. Computer Technology & Security — Bowie State University EC-Council Certified Ethical Hacker CompTIA Security+ AWS Security Specialty NIST Risk Management Framework
Saniha Jackson

Saniha Jackson

Advisor — Artificial Intelligence Education & Emerging Technology

Foundation of Technology and Engineering Teacher at Bowie High School, developing project-based curriculum in cybersecurity, web development, and engineering design. Former Program Manager of the Xtreme Research Team at Bowie State University, leading industry-focused technology research over a four-year period. Artificial Intelligence Project Facilitator developing curriculum at the intersection of hardware, software, and responsible AI integration — with direct experience managing AI internship programs with industry partners. Author of the graduate thesis What is Automated Artificial Intelligence Doing with My Data?, examining data privacy in automated AI systems.

M.S. Internet of Things & Internet Technologies — Bowie State University B.S. Technology & Security — Bowie State University

Portraits generated by AI. Modern Data Decisions embraces the power of AI, while maintaining the human oversight required to govern it safely.

Request a Consultation

The first conversation is always confidential.

Engagements begin with a 30-minute intake call with Tamara Jones directly. There is no obligation and no sales process. Send a message below or select a time on the calendar — whichever works best for you.

Modern Data Decisions maintains a selective engagement model to ensure each firm receives dedicated, executive-level oversight. We are currently accepting inquiries for Q3 and Q4 2026 governance assessments.

Secure email
contact@moderndatadecisions.com
Service Area
Serving law firms nationally
Washington, D.C. Metro Area
Send a Message
Schedule Directly

Prefer to go straight to booking? Select a time below and we will send a confirmation with everything you need to prepare.