ISO/IEC 42001 · NIST AI RMF · EU AI Act

Stop answering the same AI question three times.

Govliance is the AI management system for teams carrying more than one framework. Register your AI estate, assess and close the gaps — and turn one set of controls into audit-ready proof for every auditor, customer questionnaire and regulator.

Built for compliance and risk teams at mid-market organisations — and for the auditors who review them.

One control, evidenced once

Training data sources are documented and reviewed

3 evidence items · v4 · owner assigned

Counts toward
  • ISO/IEC 42001:2023Satisfied
  • NIST AI RMF 1.0Satisfied
  • EU AI ActSatisfied

The crosswalk resolves the overlap, so the work counts once and reports everywhere.

Founding Customer slots remaining: 10 of 10

Most teams pay for the same control three times over.

One standard invites certification. Another gets written into your customers’ procurement questionnaires. A third is law. Each asks for much the same thing in an entirely different vocabulary.

So the same control gets recorded in a spreadsheet for the certification audit, again in a register for the customer questionnaire, and a third time for the legal classification. The evidence proving any of it sits across shared drives and inboxes. When someone finally asks a question, the answer has to be reassembled from fragments — and nobody can show that today’s answer matches the one given six months ago.

Govliance holds one governed record and projects it into whichever framework the reader needs. Recorded once, evidenced once, reported everywhere.

Governed in 30 days, not a fiscal year.

Register, assess, remediate, prove — delivered with you, on your own systems, for a fixed $4,900 credited against any annual plan. Ten Founding Customer slots, list price locked for three years.

Week 1

Register

Week 2

Assess

Week 3

Remediate

Week 4

Prove

See what's in the Sprint

Four stages, one source of truth

The lifecycle runs the same way for every AI system you bring in, whichever frameworks you are answering to.

  1. 01

    Register

    Inventory every AI system and the models inside it — lifecycle stage, deployment environment, data categories, affected parties, vendor dependencies.

  2. 02

    Assess

    Run risk and impact assessments, score on a 5×5 scale, and let the engine suggest the controls that fit what you registered. You confirm; it never decides for you.

  3. 03

    Remediate

    Work controls to a maturity rating, assign remediation tasks, and gate high-risk systems behind an approval that has to be recorded before production.

  4. 04

    Prove

    Hand over a Statement of Applicability, a board report, or a scoped audit pack — each stamped with the framework content version it was built from.

The frameworks, already mapped

Content is versioned, so a standard’s revision doesn’t invalidate the assessments you have already finished.

ISO/IEC 42001:2023

35 management-system clauses and 47 Annex A controls

The certifiable AI management system standard

NIST AI RMF 1.0

95 outcomes across Govern, Map, Measure and Manage

Increasingly written into procurement

EU AI Act

16 obligations, applied by classification tier

Prohibited, high-risk, transparency or minimal

The high-risk deadline moved to December 2027. The transparency obligations didn’t — 2 December 2026 is the date on your calendar.

Download the crosswalk excerpt →

A short excerpt showing how one control maps across ISO/IEC 42001, NIST AI RMF and the EU AI Act.

Every control description is an original plain-language summary of what the provision asks for. Govliance does not reproduce the text of any standard — your organisation holds its own licensed copies.

Built to survive the review

An auditor is not only asking what you did. They are asking whether the record can be trusted.

An audit log that cannot be edited

Every change writes an immutable event. The append-only rule is enforced by the database itself, so it binds every account — including the one the application connects as.

Evidence that keeps its history

A new upload creates a new version and never overwrites the last one. An auditor reviewing a closed period sees the evidence as it stood then, not as it stands today.

Audit Mode for outside auditors

Scoped, time-boxed, read-only access. External auditors can examine the record and raise findings — and can do nothing else to your governance data.

Your auditor works inside it

Certification bodies and consultants run engagements in Govliance through the Partner Programme — so the record they review is the one you keep.

See partners

Where do you stand?

Two minutes. Three bands. One honest answer.

Eight questions tell you how many places your AI inventory lives, whether you can show an auditor what the record looked like six months ago, and which frameworks you’re paying for twice.