MSSPs, MSPs, and vCISOs

Adding an AI governance service line to an MSSP

Sources verified Sanitized Ai Team

The short answer

Package it as four parts clients already understand: a fixed-scope AI use assessment, a policy and sanctioned-tool decision, managed data-level controls in the browser, and a monthly report with a regular review. Measure outcomes the client can see, such as AI tools discovered, sensitive-data events caught before submission, and repeat events by department, and map the program to the NIST AI RMF or ISO/IEC 42001 so it speaks the language auditors recognize.

The situation

Three clients asked about AI this quarter, and each got a different answer. One received a policy your vCISO wrote over a weekend. Another got a firewall rule blocking a few chatbot domains, followed by a stream of exception tickets. The third is still waiting. Leadership now wants a repeatable offering: a defined scope, clear deliverables, a reporting rhythm, and a way to deliver it with the team you already have.

That is a reasonable goal. The question clients ask, covered in what to tell clients who ask what to do about AI, is the same across industries. What changes from client to client is the data they handle and the rules that attach to it. A service line lets you answer the common part once and tailor the rest.

What the rules actually say

The frameworks your clients may already track give you a ready-made structure for a recurring service, and Canadian privacy law explains why clients should care.

  • NIST AI RMF. The AI RMF 1.0 is voluntary and organizes AI risk work into four functions: Govern, Map, Measure and Manage. It calls for ongoing monitoring and periodic review of the risk management process, with roles and review frequency defined (GOVERN 1.5), an inventory of AI systems (GOVERN 1.6), and training for personnel and partners (GOVERN 2.2). A monthly report and a quarterly review meeting fit that pattern directly.
  • ISO/IEC 42001. ISO/IEC 42001:2023 sets requirements for establishing, implementing, maintaining and continually improving an AI management system. The continual-improvement cycle is, in practice, a recurring service.
  • PIPEDA. For clients subject to PIPEDA, Schedule 1 makes an organization responsible for personal information it transfers to a third party for processing, and requires contractual or other means to keep comparable protection (clause 4.1.3). It also calls for staff training (clause 4.1.4) and safeguards that include technological measures (clause 4.7.3). Staff pasting personal information into a public AI tool engages all three. Quebec's Law 25 and provincial health privacy laws add their own requirements.
  • Canadian Centre for Cyber Security. Its generative AI guidance recommends that organizations set policies on how AI is used and that staff avoid entering personal or proprietary information.

None of this makes the MSSP responsible for a client's compliance, and your service description should not suggest it does. The service helps a client show that it took reasonable steps. Ask your own counsel to review how the offering is described and contracted.

Why policies and bans fall short

As a product, a policy-only engagement is a one-time document. It produces no evidence that anything changed, and nothing to review next month. A ban-only engagement is worse for the provider: it generates exception requests, pushes staff to personal devices where you have no visibility, and leaves you owning the friction.

The gap clients actually have is a control at the point of entry. IBM's 2025 Cost of a Data Breach Report found that only 17% of organizations have technical controls that block or redact sensitive data at that point. That is the part of the service that is hardest for a client to build alone, and it is what makes the monthly report meaningful.

It also addresses the problem a policy cannot: once content is submitted to a public AI tool, it cannot be recalled. It becomes subject to the provider's terms, which can permit retention, sub-processing and in some cases training.

What a practical control looks like

Package the service in four parts

  1. Assessment. A fixed-scope engagement: which AI tools are in use and by which teams, what sensitive data those teams handle, what policy exists, and what the sanctioned tools' contracts say about data. Deliver a findings report mapped to the NIST AI RMF Govern categories.
  2. Policy and sanctioned tools. A short acceptable-use policy, an approved tool list, an incident path for when something sensitive is submitted, and a staff announcement the client can send.
  3. Managed controls. Deploy and tune a data-level control in the browser, using the client's existing browser management. The mechanics are covered in deploying browser AI controls across many client environments.
  4. Monthly reporting and quarterly review. A report the client's leadership can read in five minutes, followed by a review meeting that turns findings into decisions. See the sample client AI risk report for the sections.

Measure what the client can see

  • Coverage: the share of managed browsers where the control is installed and reporting.
  • Tools in use: AI tools seen, and which of them are sanctioned.
  • Events caught before submission: by data type and by policy, with the trend over time.
  • Behaviour change: repeat events per team after people have seen the in-the-moment explanation.
  • Response: time to assess incidents that staff report, and policy exceptions requested and granted.

Fit it into what you already run

Add the browser control to your standard onboarding checklist, next to endpoint and email protection. Decide with each client which events, if any, warrant a ticket, and handle the rest in the monthly review. Give the quarterly review to your vCISO, who can carry the results into board reporting and client security questionnaires. Price it the way you price your other per-user managed services.

Sanitized Ai covers the managed-controls part of the package and supplies the data for the monthly report. It is a browser extension for Chrome, Edge and Firefox that detects sensitive data in AI prompts and file uploads (client names and identifiers, personal information, health and financial data, source code, deal terms) and redacts or blocks it before submission. The person sees a plain-language explanation of what was flagged and why, which is the user education your behaviour-change metric depends on. Administrators see a dashboard of flagged-event metadata (which tool, what type of data, which policy, when) that never shows prompt content, so your reports rest on audit-ready records rather than on anyone reading client staff's prompts.

To talk about building this service with Sanitized Ai, contact us through the intake form.

Frequently asked questions

Do we need data scientists or AI specialists to run this service?

No. The service governs how client staff use AI tools, not how AI models are built. The skills it needs are the ones an MSSP already has: discovery, policy writing, browser and endpoint management, and reporting to non-technical leaders.

Should the assessment be sold separately from the ongoing service?

Selling it separately gives the client a smaller first decision: a fixed-scope assessment produces a findings report the client can act on even if it stops there. It also gives you the baseline you need to show progress once managed controls and monthly reporting begin.

Can we promise clients that the service makes them compliant?

Avoid that promise. Frameworks such as the NIST AI RMF are voluntary, and legal obligations depend on the client's sector and province. Describe the service as helping the client show reasonable safeguards, and have your own counsel review service descriptions and contracts.

What should we avoid measuring?

Avoid treating a rising count of blocked events as proof of rising risk. Counts often rise simply because more browsers are covered. Pair event counts with coverage and with repeat events per team, so the trend reflects behaviour rather than rollout progress.

Close the gap between the rule and the prompt box.

Sanitized Ai is a browser extension that coaches staff at the moment they type, redacts or blocks sensitive data before it reaches an AI tool, and gives administrators audit-ready records of flagged events without showing prompt content.

Talk to us

Primary sources

This guide summarizes the cited sources as of the verification date. It is practical guidance, not legal advice. Confirm your obligations with your regulator or counsel.

Standards that apply

Related guides

Further reading