Skip to content
ComplyIndex
Listed · unverifiedConsultancy

risk3sixty

US GRC boutique for ISO 42001 implementation, internal audit and risk assessment alongside ISO 27001 and SOC 2 programs.

Roswell, United States

Listed from public sources · not yet verified · Is this you? Claim this profile

Request an intro

At a glance

Frameworks
  • ISO/IEC 42001
  • ISO/IEC 27001
  • SOC 2
Services
Implementation · Readiness assessment · Gap analysis
Jurisdictions served
United States
Headquarters
Roswell, United States
Industries
Cross-industry
Firm size
11–50 people
Gap-analysis price band
Undisclosed
Retainer price band
Undisclosed
Engagement models
Fixed-scope project
Remote / on-site
Hybrid
Languages
English
Notable clients
FullStory

About

risk3sixty is a governance, risk and compliance consultancy in Roswell, Georgia, whose ISO/IEC 42001 practice is aimed at technology companies adding an AI management system certificate to an existing ISO 27001 or SOC 2 program. The firm sells three distinct ISO 42001 services: an end-to-end implementation program, a clause 9.2 internal audit positioned as preparation for the external certification audit, and an AI risk assessment addressed at clauses 6 and 8, with the management system harmonized against the rest of a client's framework stack. The wider practice covers ISO 27001, SOC 2, PCI DSS, HITRUST, FedRAMP and CMMC work plus penetration testing, and engagements include access to the firm's own fullCircle GRC platform. Delivery is by US-based consultants who work with client teams over shared Slack channels, operating from a single Georgia office. The team page names Josh Smith, a director in the advisory practice, as the firm's first certified ISO 42001 Lead Implementer. EU AI Act advisory is not part of the published offering, and no pricing is disclosed.

Credentials

  • Not verified

    ISO/IEC 42001 Lead Implementer

    Held by Josh Smith

    ISO/IEC 42001 Lead Implementerpublic profile cross-checked

✓ marks credentials we confirmed against the issuing registry or a reviewed certificate. Self-attested and public-profile credentials are shown for completeness but do not count toward verification. How we verify

Similar practitioners

Other listings covering the same frameworks, based in United States or focused on the same industries. Verified listings first.

Verified July 2026Consultancy

Oxbow Ridge Advisory

AI governance and LL144 compliance for HR tech vendors and their employer customers, in New York and Toronto.

Frameworks
NYC LL144 · Colorado AI Act · NIST AI RMF +1
Serves
US, Canada
Gap analysis
$5k–$15k
Retainer
$5k–$15k / month
Firm size
11–50 people
HQ
New York, United States
IAPP AIGPISO/IEC 42001 Lead Implementer
Verified July 2026Consultancy

Fogline Systems Assurance

Remote ISO 42001 and EU AI Act conformity programmes for fintech and medtech companies selling on both sides of the Atlantic.

Frameworks
ISO 42001 · EU AI Act · NIST AI RMF +1
Serves
Global
Gap analysis
$15k–$50k
Retainer
$15k–$30k / month
Firm size
11–50 people
HQ
San Francisco, United States
ISO/IEC 42001 Lead ImplementerIAPP AIGP
Verified July 2026Consultancy

Saddleback Compliance Works

Colorado AI Act gap analysis and implementation for insurers, lenders and other Colorado deployers.

Frameworks
Colorado AI Act · NIST AI RMF · ISO 42001
Serves
US
Gap analysis
$5k–$15k
Retainer
Undisclosed
Firm size
2–10 people
HQ
Denver, United States
ISO/IEC 42001 Lead Implementer
Verified August 2026Fractional AI governance officer

Beacon Row Governance

Fractional AI governance lead for growth-stage medtech and clinical software companies, six-month minimum retainers.

Frameworks
ISO 42001 · NIST AI RMF · EU AI Act +1
Serves
US, EU
Gap analysis
Undisclosed
Retainer
$15k–$30k / month
Firm size
Solo practitioner
HQ
Boston, United States
IAPP AIGP