govrnplatform
Grace HillReal-estate technology · multifamily SaaS (PE-owned) · 350 staff
Grace HillBCBS of Illinois (HCSC)
MONITORING · NOT CONNECTED
34/100overall posture

Governance across all three lenses over one technology fleet. 5 high/critical findings open

Governance posture

IT-Rationalization

33/100

inventory · duplication · disposition · roadmap

  • 0 pass
  • 2 partial
  • 1 fail
  • 0 n/a

Cybersecurity

63/100

NIST CSF 2.0 · CIS v8.1 · privacy

  • 1 pass
  • 3 partial
  • 0 fail
  • 0 n/a

AI-Governance

6/100

AI-BOM · bias · oversight · provenance · drift

  • 0 pass
  • 1 partial
  • 7 fail
  • 0 n/a

AI-BOM · 4 models · the surface security misses

ModelUse caseRiskOversightOwnerReviewed
Gracie (Ask Gracie)Undisclosed LLM (vendor not public) · in-product 2026Conversational AI answering policy, training & fair-housing/compliance questions from company policy content; reasons even when the answer is not explicitly stated critical no HITL Product253d ago
Intelligence+Internal + vendor analytics · GA 2H-2025Prescriptive analytics ranking priorities/action plans from 35 yrs of resident-survey data high HITL ✓ Data / Insights147d ago
PerformanceHQ AI-driven insightsInternal · in-product 2026Recommendation/insight engine across training + survey + policy data high no HITL Product222d ago
Reputation sentiment AIVendor sentiment model · in-product 2026Flags risky resident feedback + drafts responses across review platforms med HITL ✓ Product130d ago

Cost & Efficiency · AI tokenomics — the governance that de-risks AI also makes it cheaper

$34.2kmonthly AI spend
$15krecoverable / mo
56%efficient
2over-provisioned
ModelTierMonthlyTokens/moRight-sizingRecoverable
Gracie (Ask Gracie)Conversational AI answering policy, training & fair-h… frontier $18k/mo 240M over-provisioned $11k/moFrontier model for policy/compliance Q&A — most queries fit a workhorse tier
Intelligence+Prescriptive analytics ranking priorities/action plan… workhorse $6k/mo 90M right-sized ✓
PerformanceHQ AI-driven insightsRecommendation/insight engine across training + surve… frontier $9k/mo 120M over-provisioned $4k/moNo caching on repeated insight prompts; partial down-tiering available
Reputation sentiment AIFlags risky resident feedback + drafts responses acro… lightweight $1.2k/mo 40M right-sized ✓

Monitoring & findings · systems & vendors & public chatter — never individuals

Monitoring: not connected. The signals below are sample / discovery findings from the baseline assessment — not a live feed. Continuous monitoring activates when connectors are wired to this tenant's stack. We mark what's real.

Signals · sample / discovery

0 critical2 high0 medium0 low0 info
SevSignalSourceTargetSeenStatus
highAdvisory affects a video-leasing dependencyPublic advisory matches a Realync media dependency — confirm version exposure. cveRealync (video leasing)5d ago new
highShadow GenAI handling policy draftsUnsanctioned public-LLM use for content drafting; possible confidential data egress. shadow-aiUnsanctioned GenAI tools (shadow)5d ago new

Findings · HITL-gated — display only, no action without client GO

0 none6 proposed0 approved0 applied
SevFindingTypeAffectsAction
criticalGracie answers fair-housing/compliance questions with no documented oversight or accuracy basisDocument model + data handling; add human-in-the-loop validation on fair-housing/leasing answers; run disparate-impact review. HUD 2024 guidance puts AI advisory in FHA scope and reaches the tech provider. gapGracie (Ask Gracie)proposed
highNo public model disclosure, accuracy metric, or data-handling doc for GraciePublish a model card (purpose, data, limits, accuracy) — CHAI-style — and a data-handling statement. gapGracie (Ask Gracie)proposed
highResident survey data used by Intelligence+ without documented consent/secondary-use governanceDocument consent basis + secondary-use limits + anonymization for model use of 35-yr survey data. gapIntelligence+proposed
highAI-influenced policy/training content lacks documented 50-state legal validation + versioningAdd provenance + human legal-validation sign-off + version history for AI-touched compliance content. gapPolicies platformproposed
mediumUndisclosed foundation model behind Gracie; data-flow to provider undocumentedDisclose the model provider internally; govern data-flow + GPAI/supplier terms; define fallback. gapGracie (Ask Gracie)proposed
highShadow GenAI in use with no acceptable-use policyStand up an enforced AI acceptable-use policy; route staff to a sanctioned tool; run shadow-AI discovery. gapUnsanctioned GenAI tools (shadow)proposed

Attestations · Finding ≠ Attestation — signed independently of delivery & remediation (the conflict firewall)

AI-Governance0/100

DECLINED — AI-governance readiness is NOT attested. Open critical/high gaps (fair-housing oversight on Gracie, no model disclosure, resident-data secondary-use, shadow GenAI) preclude readiness. This is the gap to close on the path to ISO/IEC 42001 readiness — not a passing posture.

Assurance Authority (independent)independent ✓ basis: 4 findings · issued 5d ago
Cybersecurity58/100

Security posture is moderate and platform-strong (MFA, encryption). Conditional pending vendor/model-provider risk inclusion and remediation of the video-leasing advisory + shadow-tool exposure.

Assurance Authority (independent)independent ✓ basis: 1 finding · issued 5d ago
IT-Rationalization48/100

Inventory of products is clear; the gap is a consolidated AI-feature inventory with data-access mapping and a shadow-AI sweep. Sound pending those.

Assurance Authority (independent)independent ✓ basis: 0 findings · issued 5d ago

Fleet inventory · 9 assets

AssetKindOwnerAdoptionDispositionFlags
PerformanceHQUnified platform (training, policy, surveys, insights)applicationProduct / Eng 95%retaininternet
Training / LMS600+ industry courses incl. fair housingapplicationLearning & Enablement 90%retaininternet
Policies platform1,000+ policies/forms, e-sign, compliance dashboardapplicationCompliance 85%retaininternet
KingsleySurveys / Kingsley Index35-yr resident/employee survey + benchmark datasetdatabaseData / Insights 80%retain
Reputation ManagementAI sentiment monitoring across review platformsapplicationProduct 60%retaininternet
Realync (video leasing)Virtual leasing / video toursvendor-serviceProduct 50%retainno-MFAinternet
CRM / GTM stackSales + customer datavendor-serviceRevenue 70%retaininternet
Analytics / benchmarking warehouseResident + employee analytics, model featuresdatabaseData / Insights 65%retain
Unsanctioned GenAI tools (shadow)Staff using public LLMs for content draftingapplication(unowned) 30%tbdno-MFAunencryptedinternet