Features

Everything your governance programme needs.

Built for compliance teams. Not data scientists.

Records

Structured records for AI systems and vendors.

AI System records

A structured record for every AI system: category, hosting, owner, vendor, whether it influences decisions about people, and whether it processes personal or sensitive data.

Vendor and dependency records

Third-party AI vendor records with risk tier, data processing agreement status, contract review date, data residency, and the systems that depend on the vendor.

Discovery of unregistered tools

Optional discovery capabilities surface AI tools that were never registered. Availability depends on the configured product deployment.

Planning

Risks, gaps, controls, and their relationships.

Risk and compliance planning

Draft system-specific risks and compliance gaps, connect them to controls, and submit the package for review. Planning items are frozen during review.

Controls and control relationships

Controls connect risks and policy clauses to operational work. A control can carry an owner, lifecycle state (Designed / Operational / Failed / Retired), and named evidence requirements.

Compliance gaps

A compliance gap represents an unmet obligation for a system, resolved through controls and supporting evidence rather than by changing a score.

Exceptions and deferrals

Time-bound, control-specific exceptions. An exception does not resolve a gap by itself.

Library

Policies and regulations as templates.

Policy and regulation library

Regulation, risk, control, policy, and use-case items in the platform library are templates. Importing a template creates an independent, organisation-owned copy.

Control-specific evidence requirements

A control can define named evidence requirements - for example a bias test report, human oversight procedure, vendor agreement, or monitoring record.

Evidence links

Evidence is a storage record. It can be associated with a system, a system control, or a named control evidence requirement.

Review and sign-off

Workflow gates with assigned people.

Governance review gate

Submit the planning package to an assigned reviewer. Approve, approve with conditions, request changes, or reject. Submitter and reviewer are normally different people.

Final sign-off gate

Submit operational readiness for final approval. Readiness checks cover approved control status, required evidence, pending deferrals, and approval conditions.

Reassessment workflow

One reassessment per system at a time, routed to the phase that needs attention - Context, Planning, or Verification.

Audit activity

Recorded activity, exported for review.

Audit activity

Append-only record of who did what, on which entity, and whether it was allowed or blocked - with reasons where available.

Audit activity exports

CSV exports designed for human review; JSON exports with raw, normalised, narrative, context, and change sections. Exported records support review; they do not guarantee audit acceptance.

AI assistance

Drafting help for risks, controls, and policy clauses; search over recorded audit history; regional context assistance - where enabled in the deployment. Every AI output is a draft for human review.

Access

Roles, assignments, and permission bundles.

Organisation roles

Admin, Manager, and Member roles with distinct organisation-level privileges.

System assignments

Per-system Owner, Contributor, and Viewer assignments.

Permission bundles

Additive organisation-level access bundles such as Auditor, Access Admin, and Policy Author. Bundles do not replace the base organisation role.

See it in action.