Defensible AI-risk posture for organisations already using AI — without another year of spreadsheet audits.
Vendor swapped its underlying model without notice
ChatGPT, Copilot, vendor-embedded AI, agentic tools — adopted team by team, mostly without a control decision. Meanwhile NIST AI RMF, ISO 42001, the EU AI Act, and sectoral law each expect evidence you probably aren't collecting yet. And what could go wrong across prompts, models, or agents has no one good owner — and no one good answer.
Why one-off audits don't close the gap
Passes the audit, misses jurisdictional exposure — EU AI Act, US state law, FDA, HIPAA.
A snapshot only. No provenance, no evidence trail, no second-pass review — and it ages in weeks.
Misses the AI features your vendors quietly added — model changes, new sub-processors, agentic behaviour.
Stalls on "which framework do we map to first".
Your team answers a question once. We tell you what it means under every regime that applies to you.
Plus the NIST Generative AI Profile.
The AI management system standard.
Provider, deployer, and GPAI obligations.
Clinical, life sciences, financial services, public sector.
EU, UK, IE, US (federal + CA / CO / NY), Canada, Australia, Singapore.
The cyber underlay, where it touches AI.
Cyber controls are assessed where they touch AI. A full cyber review can be added on request.
Every finding flows into a custom AI-powered Risk Register, configured for your organisation — owners, control mappings, and statuses, ready for the GRC process you already run.
Industry, size, scope, jurisdiction, model types in use — drives which questions you actually see.
A filtered question set across 16 sections. Existing policies and contracts pre-populate evidence via document analysis.
Every finding is triaged by an assessor — accepted findings become Risk Register entries with an owner and a control mapping, carried over automatically.
Scored findings, prioritised mitigations, and a 12-month roadmap — Word export for board and audit, register entries tracked to closure.
The assessment identifies. The register manages. Nothing falls through the gap.
Provenance on every question — each carries the frameworks and clauses it maps to.
Findings link to evidence — every conclusion points back to the document behind it.
Reviewer sign-off — nothing reaches the report without second-pass human review.
Document analysis does the heavy lifting — your policies are read for you, and cited where they count.
Scored maturity across the 7 executive domains your board cares about — Governance, Risk & Controls, Data & Privacy, Model Lifecycle, Workforce, Third-Party Risk, Responsible AI.
Every finding traced to the specific NIST / ISO / EU AI Act control that puts you on the hook — so legal, risk, and the business each know what they own.
Prioritised mitigations and a 12-month roadmap, sized to your risk appetite — register entries ready for the GRC tool your team already uses.
Existing policies, contracts, and controls surfaced as evidence behind every relevant finding — no starting from zero.
A Word document built for committee, audit, and regulator-facing use — a story about the business, not a spreadsheet of controls.