Federal NAICS Codes - Cijara Group
Cijara Group operates as a small-business federal subcontractor across seven NAICS codes spanning management consulting, computer systems and IT services, professional and scientific services, and management training. Each page below details capabilities, agencies served, and contract vehicles.
Administrative & General Management Consulting
NAICS 541611 covers firms that advise on organizational strategy, policy, planning, and general operations. Cijara Group operates under 541611 as a small-business subcontractor supporting federal prime contractors and direct-to-agency engagements across civilian and defense missions.
View NAICS 541611 →Other Management Consulting Services
NAICS 541618 captures management-consulting work that doesn't fit neatly into 541611, 541612, 541613, or 541614 - specialty advisory across regulatory, telecommunications, agricultural, and cross-functional operations. Cijara Group supports federal primes and agencies under 541618 with focused, defensible deliverables.
View NAICS 541618 →Computer Systems Design Services
NAICS 541512 covers planning and designing computer systems that integrate hardware, software, and communication technologies. Cijara Group supports federal IT primes under 541512 with systems-engineering planning, AI integration advisory, and modernization roadmaps aligned to OMB, NIST, and agency CIO guidance.
View NAICS 541512 →Other Computer Related Services
NAICS 541519 covers computer-related services not classified elsewhere - including disaster recovery planning, software installation, computer system management, and IT consulting. Cijara Group supports federal IT primes under 541519 with assessment, planning, and advisory work that strengthens delivery against agency CIO requirements.
View NAICS 541519 →Other Scientific & Technical Consulting Services
NAICS 541690 covers scientific and technical consulting that doesn't fall under environmental, agricultural, biological, or physical-science codes - including security, AI governance, and cross-disciplinary technical advisory. Cijara Group supports federal primes under 541690 with Responsible AI assessments, cybersecurity governance reviews, and SME-led technical opinions.
View NAICS 541690 →All Other Professional, Scientific & Technical Services
NAICS 541990 is the catch-all for professional, scientific, and technical services that don't fall under other 5419 codes - including specialized research, expert testimony, and bespoke advisory work. Cijara Group supports federal primes under 541990 with embedded analyst support, briefing development, and mission-specific research.
View NAICS 541990 →Professional & Management Development Training
NAICS 611430 covers professional and management development training programs - leadership, executive education, and specialized professional curricula. Cijara Group designs and delivers federal-grade training under 611430, including custom curricula for AI literacy, acquisition fundamentals, and compliance.
View NAICS 611430 →Responsible AI
Governance is the differentiator.
Plenty of firms can stand up an AI tool. Far fewer can hand your board the paper trail that lets a regulated institution deploy it - and defend it. Cijara Group turns Responsible AI obligations into deliverables that close the gap between a technical capability and an approved deployment.
Governance-led, not model-led
We lead with risk discipline and regulatory alignment, then apply AI inside that structure. Regulated businesses need defensible process; the model is the easy part.
Artifacts an examiner can accept
Use-case inventories, risk-management plans mapped to the NIST AI RMF Govern/Map/Measure/Manage functions, model documentation, and human-oversight runbooks - written to survive supervisory review.
Built for regulated environments
Community banks and regulated SMBs face the same expectations as the largest institutions. Our frameworks are calibrated to banking regulatory standards from day one, not adapted after the fact.
Right-sized obligations
Each use case carries only the controls that actually apply, and your team can defend that calibration on review. Governance that slows delivery is governance that gets bypassed.
AI Governance FAQ
What regulators expect on AI.
AI adoption inside a regulated institution is a governance question before it is a technology question. These are the frameworks and expectations that shape a defensible program.
See our AI Governance capability →What is the NIST AI Risk Management Framework?
The NIST AI RMF is a voluntary framework for managing AI risk, organized into four functions: Govern, Map, Measure, and Manage. It is the reference most regulators and examiners recognize for AI risk programs, which makes it the natural backbone for a defensible governance structure.
What do banking examiners expect on AI?
Examiners expect AI use to fit inside your existing risk management framework: a documented inventory of use cases, risk assessments that distinguish inherent from residual risk, effective controls, and board-level oversight. 12 CFR Part 30 (OCC) and Part 364 (FDIC) safety and soundness standards apply to AI the same way they apply to any other material technology risk.
What is ISO/IEC 42001?
ISO/IEC 42001 is the international standard for AI management systems. It defines the policies, roles, and controls an organization should operate to develop and use AI responsibly. It pairs well with NIST AI RMF: the RMF structures risk thinking, 42001 structures the management system.
What counts as a high-risk AI use case?
Any use case whose output materially affects customers, financial decisions, compliance obligations, or the institution's safety and soundness. Credit, fraud, and customer-facing decisions carry the heaviest obligations: pre-deployment testing, ongoing monitoring, human oversight, and documented review. Getting that classification right is what keeps obligations right-sized.
How does a small institution govern AI without a dedicated team?
By right-sizing the program: a use-case inventory, a policy defining acceptable use, risk assessments proportionate to materiality, and a monitoring routine that actually runs. The framework does not need to match a national bank's - it needs to be documented, followed, and defensible.
How does Cijara Group support these requirements?
We lead with governance discipline built inside regulated institutions, then apply AI implementation and security work inside that structure. Deliverables are the artifacts a board or examiner can accept: use-case inventories, risk-management plans mapped to the NIST AI RMF, model documentation, and human-oversight runbooks - sized so your institution carries only the controls that actually apply.
