How it works

The governance lifecycle, in five stages.

Register and catalog the system, establish its operational context, develop the governance plan, verify active controls and evidence, then sign off and monitor continuously.

Step
01

Register and catalog

The governance lifecycle begins by establishing a clear record in the central AI registry for each model, system, or software integration. Organizations document key structural parameters to establish immediate administrative accountability.

  • System category recorded for every model, tool, and integration
  • Deployment type: cloud, on-premise, or air-gapped
  • Designated business owner assigned from day one
Assessment Engine
Privacy
55
Security
63
Bias
71
Reliability
79
Compliance
87
Optional add-on

Find AI tools nobody registered

Optional discovery capabilities surface AI tools that were never registered. Which sources are available depends on your deployment. Anything found lands in the same review queue as systems you added manually.

Step
02

Establish operational context

Before assigning controls or assessing hazards, teams complete a comprehensive context profile mapping critical operating conditions, such as the classification of processed data, geographic reach, and the presence of automated decision-making that could affect individuals.

  • Data classification, geographic reach, and decision impact captured
  • Structured fields, not free-text notes
  • Context must be finalized and locked before planning begins
Copilot
GPT-4
Claude
Gemini
LLM API
Step
03

Develop the governance plan

Using pre-built templates aligned with global regulations, risk managers identify potential system hazards and flag outstanding compliance gaps, mapping those risks and obligations directly to specific operational controls.

  • Templates aligned with global regulations
  • Risks and obligations mapped to operational controls
  • The system-level workflow locks once the plan is compiled
Policy Hub
Approved
Review
Blocked
Step
04

Verify active controls and evidence

Under a strict segregation-of-duty protocol, the team member who drafted the plan cannot approve it. Once an authorized reviewer approves the package, operational owners implement the designated controls and attach required evidence, such as validation test reports, human oversight logs, or vendor agreements, to the central repository.

  • Drafter and approver are always different people
  • Every control names the evidence it needs
  • The system stays in this phase until all mandatory evidence is verified and linked
Open ObligationsSLA
DPIA missing●
Owner assign●
Model card●
Step
05

Formal sign-off and ongoing monitoring

A final sign-off gateway reviews the system's operational readiness, verifying that all controls are active and all evidence is complete. Once approved, the system moves into a continuous monitoring state.

  • Sign-off confirms active controls and complete evidence
  • Changed parameters or updated regulations trigger reassessment
  • A failed control check routes the system back to the right earlier phase
Live Governance
Compliance
98%
Alerts
2 open