About
The Firm
AI is already running in production. Whether it is governed, reliable, and worth its cost is harder to prove.
That gap is where the practice works. AI touches business processes and decisions, and that creates exposure under the EU AI Act, and gaps against NIST AI RMF and ISO/IEC 42001. We help organizations see where that exposure sits, then close it: governance readiness, ISO/IEC 42001 gap analysis, AIMS implementation, and audit readiness.
But governed AI is not the same as AI that delivers. Models drift, hallucinate, and degrade under context load, a compliance risk and a business failure at once. We build the evaluation, monitoring, and traceability that keep AI dependable and worth running, not just compliant on paper. Value also runs the other way: finding where AI can deliver more and weighing that opportunity against its risk, so the AI portfolio is managed for value, not only for safety.
What separates this from policy-led governance is the architecture underneath. Guardrails that live only in documents do not survive contact with production. We design the provenance, lineage, traceability, human oversight, and logging that turn an organization's existing enterprise platforms into governed landscapes where AI and agentic workloads run within defined boundaries.
Our approach is execution oriented. We start with evidence, not assumptions, and prefer first principles over defaulting to frameworks. We support enterprises, startups, and AI-native organizations across the DACH region and North America — in English and German.
What we are and what we are not
What kind of practice is this?
The scope says more than the label: what the work covers, and what it deliberately leaves out.
What we are
An AI risk, value, and governance practice. We help enterprises, startups, and AI-native organizations answer three linked questions about the AI they run — most of which they bought rather than built: where it creates exposure, what it actually returns, and whether the controls around it work. That means classifying systems under the EU AI Act and assessing them against NIST AI RMF and ISO/IEC 42001, establishing whether each one makes you a provider or a deployer, valuing use cases before they are committed to, and standing up the management system that makes the answers auditable. Underneath sits two decades of enterprise architecture and delivery for Fortune 500 organizations across Europe, North America, and Asia — which is what keeps governance working once it meets production.
What we are not
A compliance shop that hands over a policy binder and leaves. A slide-deck consultancy that disappears after the strategy document. A staff-augmentation channel filling seats. A vendor sales motion disguised as advisory. Nor an AI-at-any-cost practice. We do not measure AI progress by the number of processes automated, agents deployed, or people removed from a workflow. A use case has to earn its place: useful enough to justify its cost, controlled enough to justify its risk, and accountable enough to defend its consequences. We do not treat governance as documentation. We design the architectural guardrails — provenance, lineage, traceability, human oversight, logging — that survive contact with production, so AI runs inside defined boundaries across whatever platforms the organization already runs.
Managing Partner
Reinhardt Mühlhäusser
Reinhardt Mühlhäusser combines current expertise in AI risk management and AI governance frameworks — ISO/IEC 42001, NIST AI RMF, and the EU AI Act — with two decades of designing enterprise architectures and delivering technology programmes for Fortune 500 organizations across Europe, North America, and Asia.
His work has always sat at the intersection of architecture, delivery, and risk. He has built risk management applications for product development processes, led complex implementation programmes, and worked in environments where governance was not theory — it had to work in real projects, with real deadlines, real dependencies, and real business impact. He started at SAP in Germany, co-founded and ran a 30-person consultancy serving Fortune 500 clients including BMW Group, Volvo, and Mettler-Toledo, and has led global transformation programmes across three continents.
Today he helps enterprises, startups, and AI-native organizations assess AI risk, understand where AI systems create exposure, and build a practical path toward governed AI — including AI risk assessments, EU AI Act and NIST AI RMF alignment, ISO/IEC 42001 gap analysis, AIMS implementation, and audit readiness.
He holds master's degrees in Information Technology and Business Administration from TU Berlin. On AI governance he is a PECB Certified ISO/IEC 42001 Provisional Implementer and Provisional Auditor — the grade PECB issues on passing its Lead Implementer and Lead Auditor exams, with the higher grades adding documented professional-experience requirements — and holds the OCEG GRCA and GRCP credentials; he works to the NIST AI RMF, ISO/IEC 23894, ISO/IEC 38507, and the EU AI Act as standards rather than certifications. On AI specifically he is a Databricks Certified Generative AI Engineer and Machine Learning Engineer, and holds IBM's Data Science and Machine Learning Professional credentials. His architecture and delivery credentials span TOGAF, Databricks Certified Data Engineer, and SAP (LeanIX, Signavio, BTP, Business Data Cloud).
Credentials & ecosystem
What stands behind the work?
Standards worked to, platforms worked on, and the qualifications actually held — stated precisely, because in a field this new the difference between a credential and a framework matters.
PECB Certified ISO/IEC 42001 Provisional Implementer & Provisional Auditor — AI management systems, gap analysis, AIMS implementation, and audit readiness
Applying ISO/IEC 42001, 23894, and 38507, the NIST AI RMF, and the EU AI Act to classify and govern AI risk — extending the risk and compliance practice an organization already runs rather than duplicating it alongside
The foundational capability underneath the governance work — mapping how business processes, data, applications, and AI actually connect, so controls are designed where they can be enforced rather than requested
PECB Certified ISO/IEC 42001 Provisional Implementer & Provisional Auditor · OCEG GRCA (GRC Auditor) · OCEG GRCP (GRC Professional)
TOGAF Enterprise Architecture · Databricks Certified Data Engineer · SAP LeanIX Enterprise Architecture · SAP Signavio Process Management & Analysis · SAP BTP Solution Architect · SAP Business Data Cloud (Datasphere)
Databricks Certified Generative AI Engineer · Databricks Certified Machine Learning Engineer · IBM Data Science Professional · IBM ML Professional
AI use in the practice
Valment uses AI systems in its own research and drafting, under the same governance it advises on. Published analysis is reviewed and approved by Reinhardt Mühlhäusser before release.
Work with us
Tell us where AI sits in your organization and the context you are working in. We will respond with a clear read on where you stand and a sensible first step — often a bounded AI risk assessment or an ISO/IEC 42001 gap analysis.