Everything your governance programme needs.
Built for compliance teams. Not data scientists.
Structured records for AI systems and vendors.
AI System records
A structured record for every AI system: category, hosting, owner, vendor, whether it influences decisions about people, and whether it processes personal or sensitive data.
Vendor and dependency records
Third-party AI vendor records with risk tier, data processing agreement status, contract review date, data residency, and the systems that depend on the vendor.
Discovery of unregistered tools
Optional discovery capabilities surface AI tools that were never registered. Availability depends on the configured product deployment.
Risks, gaps, controls, and their relationships.
Risk and compliance planning
Draft system-specific risks and compliance gaps, connect them to controls, and submit the package for review. Planning items are frozen during review.
Controls and control relationships
Controls connect risks and policy clauses to operational work. A control can carry an owner, lifecycle state (Designed / Operational / Failed / Retired), and named evidence requirements.
Compliance gaps
A compliance gap represents an unmet obligation for a system, resolved through controls and supporting evidence rather than by changing a score.
Exceptions and deferrals
Time-bound, control-specific exceptions. An exception does not resolve a gap by itself.
Policies and regulations as templates.
Policy and regulation library
Regulation, risk, control, policy, and use-case items in the platform library are templates. Importing a template creates an independent, organisation-owned copy.
Control-specific evidence requirements
A control can define named evidence requirements - for example a bias test report, human oversight procedure, vendor agreement, or monitoring record.
Evidence links
Evidence is a storage record. It can be associated with a system, a system control, or a named control evidence requirement.
Workflow gates with assigned people.
Governance review gate
Submit the planning package to an assigned reviewer. Approve, approve with conditions, request changes, or reject. Submitter and reviewer are normally different people.
Final sign-off gate
Submit operational readiness for final approval. Readiness checks cover approved control status, required evidence, pending deferrals, and approval conditions.
Reassessment workflow
One reassessment per system at a time, routed to the phase that needs attention - Context, Planning, or Verification.
Recorded activity, exported for review.
Audit activity
Append-only record of who did what, on which entity, and whether it was allowed or blocked - with reasons where available.
Audit activity exports
CSV exports designed for human review; JSON exports with raw, normalised, narrative, context, and change sections. Exported records support review; they do not guarantee audit acceptance.
AI assistance
Drafting help for risks, controls, and policy clauses; search over recorded audit history; regional context assistance - where enabled in the deployment. Every AI output is a draft for human review.
Roles, assignments, and permission bundles.
Organisation roles
Admin, Manager, and Member roles with distinct organisation-level privileges.
System assignments
Per-system Owner, Contributor, and Viewer assignments.
Permission bundles
Additive organisation-level access bundles such as Auditor, Access Admin, and Policy Author. Bundles do not replace the base organisation role.
