Platform
AI governance, plus every other part of a complete GRC program.
Not a checklist with a dashboard: an operating system for governance. Everything flows from one place, the client's profile, down two spines: compliance, from applicability to obligations to evidence to reports, and AI governance, from intake to gates to incidents to maturity. Both converge on a single 0 to 100 posture score, the same number on the dashboard, the client page, and every document that reports it.
Each module below is live product, not roadmap.
Govern AI
01
AI system registry and lifecycle
The atomic unit of AI governance: a living inventory of every AI system in the company, owned and risk-tiered, with the documentation an examiner or customer expects.
- Lifecycle from concept to production to decommissioned, with model cards and a documented off switch
- Five-dimension risk classification scored in plain English, with automatic tier upgrades for sensitive cases
- Periodic reviews scheduled by tier, so high-risk systems get looked at quarterly without anyone remembering to
- Shadow-AI discovery import: drop in a CSV or JSON export from SaaS Alerts, Umbrella, Defender, or Nudge, and the AI tools your monitoring already sees are classified against the AI catalog and proposed as intake requests for your review
02
Intake front door and four approval gates
Employees ask for AI tools somewhere; better here than in a hallway. Requests are triaged, and systems that matter move through four documented decision gates. Gates run in order, outcomes are fixed, and the record is permanent.
- Employee tool requests triaged to approved, declined, or routed to the registry
- Prioritize, Fund, Validate, Deploy, in that order, with fixed scorecard criteria per gate; Gate 3 has three honest outcomes: Scale, Extend, or Stop
- A gate decision can never be edited or deleted, only added to: withdrawing one records the withdrawal rather than erasing the decision, and a decision made on a system with an impact assessment carries a frozen copy of it exactly as it stood that day
- The hard block: a High Risk or lending system cannot pass Gate 3 or Gate 4 without a completed Fundamental Impact Assessment and no active fair-lending hold. The platform itself enforces it, and there is no override
- Extra fair-lending criteria for systems that influence credit decisions
03
Impact assessments and AI incidents
High-risk and lending systems get a structured impact assessment before validation. When AI produces a wrong, unsafe, or biased outcome, it gets logged, triaged, and resolved like the operational event it is.
- A Fundamental Impact Assessment is required for High Risk and lending systems before Gate 3; a frozen copy rides with each gate decision that used it
- Incident severity levels with regulatory-reportability tracking
- Employee grievance channel for AI-related concerns
Run the program
04
Obligation register from plain-English questions
Answer a short qualifying profile and the applicability engine selects from a researched catalog of 70+ regulations: which rules apply, what each one obliges you to do, when, and what it costs to miss. Only what applies generates work.
- Researched catalogs for twelve industries, banking and mortgage to healthcare, defense, and general business, with citations and penalty exposure
- Dated, owned, prioritized duties with recurrence that rolls the next cycle forward on completion
- Task checklists generated per obligation, plus custom obligations for exam commitments and board resolutions
05
Policies with grounded AI drafting
Grace AI, the platform's assistant, drafts from your actual context: your systems, vendors, risks, and roles, so the output names real things and ends enforceable. Review, edit, sign. A human always has the final say. Then versioning, approval, and attestation make it operational.
- Nine policy templates from acceptable use to vendor AI, drafted against your live data
- Version history, approval metadata, review cadence, and staff attestation campaigns; attestation records are never deleted, though a signature made in error can be cleared
- Every Grace AI draft, policies, model cards, and impact-assessment narratives, carries a confidence band and citations to the records that grounded it
06
Risks, controls, and testing
A scored risk register tied to a control library that is cross-walked to NIST AI RMF, ISO/IEC 42001, SOC 2, and HIPAA, so one control satisfies many frameworks.
- Inherent and residual scoring with review cadences that keep themselves wound
- Control tests on a schedule, with effectiveness rollups and evidence attached to the control
- A coverage view that shows which framework requirements are met, by which controls, with no double counting
07
Vendors and AI due diligence
Third parties are where AI sneaks in. The vendor register tracks criticality, data access, contracts, and review cadence, with a standard diligence checklist seeded on every vendor.
- Due-diligence checklists including AI-specific items for vendors that use or provide AI
- Contract end and review dates surface in the attention inbox before they bite
- Diligence documents filed against the vendor
Prove it and keep it running
08
Evidence, exam packs, and audit readiness
Evidence is collected as work happens, tracked for freshness, and assembled into exam-ready packages on demand. The product was built by people who sit across the table from examiners.
- Evidence register with collection and expiry dates; stale evidence surfaces itself
- Evidence requests (PBC lists) your auditor or examiner can track to done
- Quarterly audit-pack snapshots captured automatically, plus an append-only audit trail and legal hold
09
Reports, board decks, and share links
Deliverables generated from live data, branded to your company: documents you hand to a board, a buyer, or a regulator without rework.
- Branded Word reports: readiness assessments, governance framework, AI inventory, remediation, and the full policy suite
- An eleven-slide board deck built from your actual posture, plus CSV and full-register exports
- Tokenized read-only share links so examiners see a live summary without an account
10
Advisor escalation and guided decisions
Software where you can, humans where it counts. Ask an advisor from any record and get an answer in a logged thread that becomes part of your governance evidence. For recurring judgment calls, guided decisions document the call in minutes.
- One-click escalation from obligations, policies, and AI systems to a compliance advisor
- Guided workflows: classify an AI use case, triage an incident, decide vendor diligence depth, check impact-assessment need
- Every run logged with its inputs and outcome: a decision log you can show
11
The 90-day program
A governance program is a sequence, not a checklist. Engagements run a phased clock: assess, establish, operationalize, hand off, with readiness criteria that warn rather than block, and a portfolio view for advisors.
- Phase targets computed from your start date; slipping phases surface in the attention inbox
- Readiness checklists per phase, deep-linked to where each gap gets fixed
- Advance with open criteria when you choose to: the accepted warnings become part of the record
12
The operating rhythm
Governance fails in the gaps between quarterly panics. One attention inbox unifies due dates, reviews, tests, gates, intakes, and incidents across every module, with a daily digest that matches the dashboard exactly.
- One feed across every module, ranked by urgency, deep-linked to the fix
- A daily email digest scoped per company, built from the same feed so email and dashboard never disagree
- A value recap that shows what the program produced: deliverables, policies, completions, and hours saved
Prefer the whole story in order? Read the full walkthrough
Want to see a module in your own terms?
Bring a real obligation, policy, or AI tool question to the demo and we will run it through the platform live.
Pricing is published. Partner onboarding runs through a short demo, no quote runaround.