ISO/IEC 42001 · NIST AI RMF · EU AI Act
Stop answering the same AI question three times.
Govliance is the AI management system for teams carrying more than one framework. Register your AI estate, assess and close the gaps — and turn one set of controls into audit-ready proof for every auditor, customer questionnaire and regulator.
Built for compliance and risk teams at mid-market organisations — and for the auditors who review them.
One control, evidenced once
Training data sources are documented and reviewed
3 evidence items · v4 · owner assigned
- ISO/IEC 42001:2023Satisfied
- NIST AI RMF 1.0Satisfied
- EU AI ActSatisfied
The crosswalk resolves the overlap, so the work counts once and reports everywhere.
Founding Customer slots remaining: 10 of 10
Most teams pay for the same control three times over.
One standard invites certification. Another gets written into your customers’ procurement questionnaires. A third is law. Each asks for much the same thing in an entirely different vocabulary.
So the same control gets recorded in a spreadsheet for the certification audit, again in a register for the customer questionnaire, and a third time for the legal classification. The evidence proving any of it sits across shared drives and inboxes. When someone finally asks a question, the answer has to be reassembled from fragments — and nobody can show that today’s answer matches the one given six months ago.
Govliance holds one governed record and projects it into whichever framework the reader needs. Recorded once, evidenced once, reported everywhere.
Governed in 30 days, not a fiscal year.
Register, assess, remediate, prove — delivered with you, on your own systems, for a fixed $4,900 credited against any annual plan. Ten Founding Customer slots, list price locked for three years.
Week 1
Register
Week 2
Assess
Week 3
Remediate
Week 4
Prove
Four stages, one source of truth
The lifecycle runs the same way for every AI system you bring in, whichever frameworks you are answering to.
- 01
Register
Inventory every AI system and the models inside it — lifecycle stage, deployment environment, data categories, affected parties, vendor dependencies.
- 02
Assess
Run risk and impact assessments, score on a 5×5 scale, and let the engine suggest the controls that fit what you registered. You confirm; it never decides for you.
- 03
Remediate
Work controls to a maturity rating, assign remediation tasks, and gate high-risk systems behind an approval that has to be recorded before production.
- 04
Prove
Hand over a Statement of Applicability, a board report, or a scoped audit pack — each stamped with the framework content version it was built from.
The frameworks, already mapped
Content is versioned, so a standard’s revision doesn’t invalidate the assessments you have already finished.
ISO/IEC 42001:2023
35 management-system clauses and 47 Annex A controls
The certifiable AI management system standard
NIST AI RMF 1.0
95 outcomes across Govern, Map, Measure and Manage
Increasingly written into procurement
EU AI Act
16 obligations, applied by classification tier
Prohibited, high-risk, transparency or minimal
The high-risk deadline moved to December 2027. The transparency obligations didn’t — 2 December 2026 is the date on your calendar.
Download the crosswalk excerpt →
A short excerpt showing how one control maps across ISO/IEC 42001, NIST AI RMF and the EU AI Act.
Every control description is an original plain-language summary of what the provision asks for. Govliance does not reproduce the text of any standard — your organisation holds its own licensed copies.
Built to survive the review
An auditor is not only asking what you did. They are asking whether the record can be trusted.
An audit log that cannot be edited
Every change writes an immutable event. The append-only rule is enforced by the database itself, so it binds every account — including the one the application connects as.
Evidence that keeps its history
A new upload creates a new version and never overwrites the last one. An auditor reviewing a closed period sees the evidence as it stood then, not as it stands today.
Audit Mode for outside auditors
Scoped, time-boxed, read-only access. External auditors can examine the record and raise findings — and can do nothing else to your governance data.
Your auditor works inside it
Certification bodies and consultants run engagements in Govliance through the Partner Programme — so the record they review is the one you keep.
See partnersWhere do you stand?
Two minutes. Three bands. One honest answer.
Eight questions tell you how many places your AI inventory lives, whether you can show an auditor what the record looked like six months ago, and which frameworks you’re paying for twice.
Prefer a conversation? Request a walkthrough.

