NIST AI Governance for Law Firms

From ABA Rule
to NIST Control — documented.

Your firm's AI adoption is outpacing its governance. Modern Data Decisions translates the ABA Rules of Professional Conduct into concrete, auditable NIST AI Risk Management Framework controls — giving your firm the compliance portfolio it needs to move forward with confidence.

Federal-grade governance standards. Built for legal practice.

The Firm

Governance built for the adversarial environment.

"Most firms are paralyzed — they see the efficiency gains AI offers, but they cannot quantify the risk. We eliminate that paralysis by replacing ambiguity with documented, auditable controls."

Modern Data Decisions exists to bridge the gap between the rapid adoption of generative AI and the stringent ethical and security demands of legal practice. We move law firms from a state of prohibited or reckless use to defensible, governed integration — using the same compliance frameworks trusted by the federal government.

Our singular differentiator is the ability to map ABA Rules of Professional Conduct directly to NIST AI Risk Management Framework controls. We do not offer general advice. We build the evidence of compliance — the documented, testable record that protects your firm before an insurance carrier, a disciplinary board, or a demanding corporate client ever asks the question.

What we are not

A law firm, a technology vendor, or a training provider. We do not sell software, provide legal advice, or receive referral fees from AI companies.

What we are

An independent AI governance advisory. We build the compliance portfolio that lets your firm demonstrate — not just claim — that its AI use meets the highest professional standards.

Services

Three engagements. One compliance portfolio.

Every engagement produces documented, testable governance artifacts — the kind of evidence that holds up to scrutiny from insurance carriers, bar associations, and your most demanding clients.

Fractional AI Governance Officer

We serve as your firm's executive authority on AI risk — on an ongoing retainer basis. We draft and maintain AI usage policies, oversee the vetting of new tools as they emerge, conduct continuous monitoring of your AI posture, and act as the primary point of contact for every AI-related ethical and security question that arises. Your partners get a dedicated governance expert without the cost of a full-time hire.

Begin a retainer engagement

NIST-Aligned AI Readiness Audit

An objective, data-driven assessment of your firm's current AI security posture. We evaluate your existing technology stack against the NIST AI Risk Management Framework, identify data leakage points, map internal workflows, and conduct a gap analysis that tells you precisely where the firm is exposed to ethical or security breaches. The output is a written report your leadership can act on — and your insurance carrier can review.

Schedule an audit

Policy & Workflow Architecture

We design and document the human-in-the-loop systems that keep AI within enforceable guardrails. This includes step-by-step workflow maps for AI-assisted drafting, discovery, and research; direct mapping of ABA ethical rules to specific NIST technical controls; and the creation of compliance documentation that constitutes demonstrable evidence of supervision — precisely what ABA Rule 5.3 requires.

Build your framework
Our Differentiator

The ABA-to-NIST Bridge

Any consultant can tell you to "be careful with AI." Modern Data Decisions tells you exactly which NIST AI Risk Management Framework control satisfies ABA Rule 5.3, and produces the audit trail that documents your compliance. We translate abstract ethical obligations into concrete, testable, defensible systems — so your firm can truthfully state to clients, regulators, and insurers that its AI governance meets federal-grade standards.

Engagement Options

Three tiers. One standard of rigor.

Every engagement is scoped to produce a compliance portfolio your firm can stand behind. Pricing is engagement-based — structured around the value of the outcome, not the clock.

Foundation

The AI Governance Assessment

A thorough, NIST-aligned assessment of where your firm stands today — and a clear roadmap of what needs to change.

  • Full inventory of AI tools in use across practice groups
  • Gap analysis: current posture vs. NIST AI Risk Management Framework standards
  • Mapping of ABA Rules of Professional Conduct to identified risk areas
  • Identification and categorization of high-risk exposure points
  • Prioritized remediation roadmap with 30/60/90-day action plan
Primary Deliverable
AI Risk & Governance Assessment Report
Your evidence of due diligence — the document you present to insurers, bar associations, or clients who ask about your AI security posture.
Enterprise

Fractional AI Governance Officer

Ongoing executive-level governance authority — keeping your firm ahead of a regulatory landscape that changes faster than policy cycles.

  • Dedicated AI governance authority for all firm AI risk questions
  • Continuous monitoring and policy maintenance as regulations evolve
  • Vetting of new AI tools before firm-wide deployment
  • Quarterly AI Readiness Scorecard — executive-level governance health metric
  • Priority access for emerging compliance concerns
Recurring Deliverable
Quarterly AI Readiness Scorecard
A dynamic governance health metric that quantifies your risk exposure and documents every step taken to mitigate it — over time, as the standard of care evolves.

Engagements are project-based and scoped to your firm's size and complexity. All pricing is discussed during your initial consultation — there is no obligation.

How We Work

The Governance Artifacts.

In the legal profession, if it isn't documented, it didn't happen. Every Modern Data Decisions engagement produces a compliance portfolio — a structured, defensible record of your firm's AI competence that you can present to your insurance carrier, your board, or your most demanding corporate client.


Begin an Engagement

AI Governance Baseline Report The Audit

A comprehensive gap analysis document. We place your current AI usage side-by-side against NIST AI Risk Management Framework standards, identify specific high-risk areas, categorize them by exposure level, and produce a prioritized remediation roadmap. This is your evidence of due diligence — the document you present if an insurance provider, bar association, or client ever questions your security posture.

Artifact: AI Governance Baseline Report

The Defensible AI Policy Playbook The Governance

A living document of firm-wide AI governance policy. It contains clear, actionable directives on acceptable AI use, sensitive data handling protocols, and mandatory human-in-the-loop verification requirements for AI-generated work product. It directly maps each policy directive to its corresponding ABA Rule and NIST control, so the chain of compliance is unambiguous and auditable. This standardizes behavior across the entire firm — eliminating rogue-use risk at every level.

Artifact: Defensible AI Policy Playbook

AI Workflow Architecture The Implementation

A series of documented procedural diagrams showing exactly how your firm's research, drafting, and discovery workflows are governed. Each diagram identifies where human review checkpoints occur and maps them to the ABA supervisory requirements under Rule 5.3. This demonstrates to regulators that your firm is not simply using AI — it is systematically supervising it in accordance with professional conduct rules.

Artifact: AI Workflow Architecture Diagrams

AI Readiness Scorecard The Ongoing Metric

A dynamic governance health metric delivered quarterly to retainer clients. It quantifies your firm's AI risk exposure, tracks the controls implemented to mitigate it, and provides an executive-level summary your managing partners can present to clients, insurers, or boards. As the regulatory landscape evolves, your scorecard evolves with it — ensuring your governance posture never falls behind the standard of care.

Artifact: Quarterly AI Readiness Scorecard
Tamara Jones, Founder of Modern Data Decisions

Portrait generated by AI. Modern Data Decisions embraces the power of AI, while maintaining the human oversight required to govern it safely.

Founder & Principal Advisor

Tamara Jones

Information System Security Manager (ISSM) · CGRC · Security+

Tamara J. Jones brings 24 years of experience in Information Technology, Cybersecurity, and Systems Engineering to Modern Data Decisions. Her career has been defined by solving complex security challenges across highly regulated environments — including the Department of Defense and the Intelligence Community — with a steadfast commitment to mission effectiveness.

As a Certified in Governance, Risk, and Compliance (CGRC) professional and CompTIA Security+ holder, Tamara specializes in Information System Security Management, AI Risk Governance, NIST Risk Management Framework and 800-53 Compliance, and Agile Leadership. She combines deep technical expertise in secure architecture with the governance rigor required to operate in the most demanding compliance environments.

As founder of Modern Data Decisions, Tamara translates that federal-grade governance discipline to the legal sector — helping law firms build defensible AI frameworks that can withstand regulatory scrutiny, bar inquiries, and client challenge.

Education: M.S. in Management Information Systems, B.S. in Computer Technology — Bowie State University

ISSM ISC2 CGRC CompTIA Security+ NIST RMF / 800-53 DoD & IC Experience AI Risk Governance Agile Leadership
Advisory Board

Practitioners who have built the field.

Our advisors bring decades of hands-on experience in AI research, cybersecurity, and technology education — the disciplines that underpin every governance decision we make.

Dr. Lethia S. Jackson

Academic Advisor, Artificial Intelligence & Cybersecurity

Associate Dean, School of Cybersecurity and Information Technology, University of Maryland Global Campus. Former Chair of Computer Science and Founding Chair of the Department of Technology & Security at Bowie State University, where she led ABET accreditation and National Centers of Academic Excellence in Cybersecurity designation. Principal Investigator or Co-PI on more than $4 million in funded research from the National Institutes of Health, the National Science Foundation, the National Security Agency, and other federal agencies.

Doctor of Science — George Washington University M.S. Computer Science — North Carolina State University B.S. Computer Science — North Carolina A&T State University Artificial Intelligence & Machine Learning Quantum Computing Cybersecurity Internet of Things

Elesha Jackson

Technical Advisor, Artificial Intelligence, Machine Learning & Secure Systems

Technical Product Manager at Forward Edge-AI, where she leads development of quantum-resistant encryption devices for the Department of Defense and National Security Agency environments. Former Artificial Intelligence and Machine Learning Engineer delivering anomaly detection, edge AI, and federated learning solutions for defense and healthcare. Former Adjunct Professor at Bowie State University, teaching Linux Systems and Security Foundations. Holds an Active Public Trust Clearance.

M.S. IoT Security & Internet Technologies — Bowie State University B.S. Computer Technology & Security — Bowie State University EC-Council Certified Ethical Hacker CompTIA Security+ Microsoft Azure Machine Learning Explainable Artificial Intelligence NIST Risk Management Framework Federal Risk and Authorization Management Program (FedRAMP)

Saniha Jackson

Advisor, Artificial Intelligence Education & Emerging Technology

Foundation of Technology and Engineering Teacher at Bowie High School, where she develops project-based curriculum in cybersecurity, web development, and engineering design. Former Program Manager of the Xtreme Research Team at Bowie State University, leading industry-focused technology research. Artificial Intelligence Project Facilitator developing curriculum at the intersection of hardware, software, and responsible AI integration. Author of the graduate thesis What is Automated Artificial Intelligence Doing with My Data?

M.S. Internet of Things & Internet Technologies — Bowie State University B.S. Technology & Security — Bowie State University Artificial Intelligence Systems Integration Curriculum Design & Technical Instruction Published Researcher Python, Java, HTML/CSS, Raspberry Pi

Portraits generated by AI. Modern Data Decisions embraces the power of AI, while maintaining the human oversight required to govern it safely.

Request a Consultation

The first conversation is always confidential.

Engagements begin with a 60-minute intake call with Tamara Jones directly. There is no obligation and no sales process. Send a message below or select a time on the calendar — whichever works best for you.

Modern Data Decisions maintains a selective engagement model to ensure each firm receives dedicated, executive-level oversight. We are currently accepting inquiries for Q3 and Q4 2026 governance assessments.

Secure email
contact@moderndatadecisions.com
Direct line
+1 (301) 615-1430
Service Area
Serving law firms nationally
Washington, D.C. Metro Area
Send a Message
Schedule Directly

Prefer to go straight to booking? Select a time below and we will send a confirmation with everything you need to prepare.