What Govliance is
Govliance is an AI Management System — one place where an organization registers every AI system it runs, assesses the risk and impact of each, closes the gaps a framework expects to be closed, and hands auditors a defensible, evidence-backed picture. It is built around ISO/IEC 42001, the NIST AI RMF and the EU AI Act, from one source of truth.
Govliance provides governance structure and evidence management. Certification decisions rest with accredited bodies — the product makes you ready for that conversation; it does not have it for you.
Who it's for
- Compliance leads run the whole lifecycle: frameworks, assessments, evidence, policies, audits.
- Risk managers keep the risk register honest — scoring, treatment and review dates in one place instead of a spreadsheet.
- System owners register the AI they build or buy and answer for its facts: purpose, data, models, deployment.
- Internal auditors plan audits, raise findings and track responses without chasing screenshots over email.
- External auditors get scoped, time-boxed, read-only access to exactly what they need — plus the ability to record findings.
- Executives see readiness, risk posture and open issues on one dashboard, exportable as a board report.
The lifecycle: Register → Assess → Remediate → Prove
Everything in Govliance serves one loop:
- Register. Put every AI system in the AI Registry — its purpose, owner, lifecycle stage, data, vendors and the models inside it.
- Assess. Run risk and impact assessments, classify under the EU AI Act, and score your controls in Gap analysis to see where you actually stand.
- Remediate. Work the gaps: treat risks, implement controls, publish policies, attach evidence, and route high-risk systems through the approval gate.
- Prove. Generate the Statement of Applicability, run audits, and export board reports and audit packs that show — with evidence — what was done and when.
Frameworks covered
ISO/IEC 42001 is the international management-system standard for AI: it asks an organization to govern AI deliberately — leadership, planning, controls, evidence and improvement. Govliance ships the full requirement and control structure as plain-language summaries you assess against.
NIST AI RMF is the US framework for trustworthy AI, organised around four functions — Govern, Map, Measure, Manage. Govliance tracks your coverage of each function on the dashboard.
The EU AI Act regulates AI by risk category. Govliance's EU AI Act module classifies each registered system and tracks the obligations that follow from its category.
The frameworks are crosswalked: where an ISO control and a NIST requirement ask for the same thing, Govliance records the mapping and shows it on every control in Frameworks. The EU AI Act module inherits evidence through it, so proof collected for ISO or NIST automatically appears against the EU obligations it supports.
On the roadmap
These capabilities are planned but not yet available — listed here so you know where the product is heading, not to suggest they exist today:
- Single sign-on (planned) — signing in with a Google or Microsoft account, with enterprise SAML for organisations that require it.
No dates are promised.
The user guide — module by module
Getting started
- Create an account. Sign up with email and password; the first account becomes your organization's Admin.
- Enter your access code. Govliance is currently onboarding customers directly, so creating an organization asks for an access code from the Govliance team — request access if you don't have one. Invited team members never need a code.
- Name your organization. Your organization is a private tenant — its data is isolated from every other customer's, and work is organised into workspaces.
- Invite your team. In Settings → Members, invite each person with a role. Invitations are links you share directly (they expire after 7 days), so nobody waits on an email.
- Secure your account. In Settings → Security, enable two-factor authentication with an authenticator app.
- Register your first AI system — the dashboard's getting-started checklist walks you through it.
Dashboard
The Dashboard is where board-sized questions get short answers: how ready are we, where are the gaps, what needs attention today.
- Framework readiness — the implemented share of applicable controls for ISO/IEC 42001 and NIST AI RMF, with coverage charts per NIST function and ISO clause.
- Systems by lifecycle and risk tier — the shape of your AI estate at a glance.
- Needs attention — overdue risks, audit nonconformities, overdue and due-soon evidence, systems awaiting EU AI Act classification, and systems with open insights. Every line links to the place where you fix it.
- Recent activity — the latest changes across your organization, drawn from the audit trail.
Monitoring
Monitoring sweeps the registry for signals worth a look, without enforcing anything itself: classification drift on systems whose risk tier came from the suggestion engine, the same open insight flags shown in the AI Registry, and evidence, policies and vendors whose review date has passed.
When there's something to report, a summary line joins the Monday posture digest email.
AI Registry
The AI Registry is the inventory every framework starts from. Registering a system captures its purpose, owner, workspace, lifecycle stage (concept through retired), model type, deployment environment, vendors, the data categories it touches and the people it affects.
From those facts Govliance suggests a risk tier — Minimal, Limited, High or Critical — and shows the written reasons behind the suggestion. You can accept it or set the tier manually; either way the classification and its source are recorded, and a manual classification is never changed by the system.
Each system also carries a model inventory — the actual models inside it (provider, role, modality, provenance, hosting, fine-tuned or not), because a real AI system is rarely one model. Auditors increasingly ask for exactly this decomposition. Each model can also carry its documented capabilities, known biases and known limitations.
Insights watch the facts and flag what's missing — a production system with no completed assessment, a high-risk system with no approval request, a vendor-hosted model with no vendor named. Every flag states what was noticed, why it matters and the step that clears it; flags clear themselves when the facts change. If new facts would change the suggested risk tier, the system shows a review hint — it never reclassifies anything on its own.
Assessments
Assessments turn "we should look at that system" into a recorded answer. Start from a template, work through the questions for a registered system, and complete it.
A completed assessment produces risks for the register and control recommendations — so assessment findings become tracked work, not a PDF nobody reopens.
Risks
The risk register scores every risk on a 5×5 grid — likelihood × impact — and tracks its treatment: mitigate, accept, transfer or avoid. Risks move through open → treating → monitored → closed, carry owners and due dates, and link back to the AI systems and controls they concern.
Overdue risks surface on the Dashboard's needs-attention list, so the register stays a working document rather than an archive.
Gap analysis
Gap analysis is where you score yourself against a framework, control by control: a status (not started, in progress, implemented) and a maturity score from 0 to 5. A control marked not applicable on the SoA — with its justification — shows here read-only, so the two views never disagree.
These scores are the source of the Dashboard's readiness percentages, calculated separately for each framework. The crosswalk doesn't move that needle for you, but it does let you see, on every control in Frameworks, which controls in the other framework ask for the same thing.
Applicability (SoA)
The Statement of Applicability is the document an ISO audit starts with: for every control in the standard's annex, is it applicable to you, why, and what's its implementation status. Govliance generates it from your gap-analysis work — applicability, justification and status per control — and keeps it current as the underlying scores change.
Export it as CSV or open the print view — one click each.
Evidence
The Evidence vault holds the proof: policies, test reports, meeting minutes, model cards — uploaded once, linked to every control they satisfy. Files are stored privately and served through short-lived links.
Evidence is versioned, never overwritten — a new upload creates a new version and prior versions stay retrievable, which is exactly what an auditor asking "what did this say in March?" needs. Review dates keep evidence fresh: due-soon and overdue items appear on the Dashboard.
Link evidence to an ISO 42001 or NIST control once, and the crosswalk carries it further: any EU AI Act obligation mapped to that control shows the same evidence automatically, labelled with the framework and control it came from.
Policies
The policy manager takes a policy from draft to published with an approval step in between — and keeps every version. Policies are your documents: upload the file, then take it through review and approval in Govliance.
Starting from Govliance's library of original policy templates skips the blank page: pick one and it becomes your draft's first version in the evidence vault, ready to customise by uploading revisions.
Published policies collect acknowledgements: each member records that they've read the policy, so "everyone has seen the AI use policy" is a report, not a hope. If the same person wrote and approved a policy, Govliance discloses that on the policy — a small-team reality, recorded rather than hidden.
Approvals
High-risk work should not go live on one person's say-so. The approval gate lets a system owner request approval for a system — capturing its risk tier at the time of the request — and a decision-holder approve or reject it, with the decision, the decider and the timestamp recorded permanently.
A high-risk system with no approval request is flagged by the registry's insights until one exists.
Audits
Run internal audits inside the product: plan the audit, record findings — major or minor nonconformities, observations and opportunities for improvement — and track responses to each. Open nonconformities appear on the Dashboard until they're dealt with.
Audit Mode is for external auditors: invite one with time-boxed, read-only access. They see what they need to see, can record findings, and can change nothing else. When the access window ends, so does the access.
Tasks
Tasks turn findings into work: anything that needs remediating — a gap, a risk treatment, a policy review — becomes an assigned task with an owner, a priority and a due date, optionally linked to the AI system, risk or policy it concerns.
Owners can update the status of their own tasks even without broader edit rights, overdue tasks surface on the Dashboard, and every change lands in the audit trail. Assignment also notifies the new owner — in the app, and by email when email is configured.
Vendors
Vendors are the third-party providers and data processors your AI systems depend on: model hosts, cloud infrastructure, data platforms, and anyone else handling your data in production.
Record each vendor with a category (e.g., model provider, data processor, infrastructure), your internal risk tier (Low, Medium, High or Critical), whether a data-processing agreement is in place, and its review date. Link vendors to the systems that use them so the dependency chain is clear.
Each vendor can also carry a scorecard across four factors — data sensitivity, business criticality, past issues and regulatory exposure — and Govliance suggests a tier from the worst-scoring factor, though the tier itself remains a human decision until you choose to apply the suggestion.
Overdue vendor reviews appear on the Dashboard's needs-attention list and trigger reminders, so third-party risk stays current between audits.
Vendor management is for Admins, Compliance Leads and Risk Managers.
Incidents
Incidents record when something goes wrong with an AI system in production — a biased outcome, a performance degradation, a suspected data leak — so the response is tracked in Govliance instead of living in someone's inbox.
Each incident carries a severity (Low, Medium, High or Critical) and a status that moves through Open, Investigating, Mitigated, Resolved and Closed. It can optionally link the AI system affected and the risk it realised, so the connection between what happened and what you'd already flagged as a risk is explicit. It can also record the incident's type, the categories of harm involved and the people or groups affected.
Everything done about it lives on an append-only timeline: add an entry for each step taken, and a status change adds its own entry automatically. Nothing on the timeline can be edited or deleted — a correction is always a new entry, never a rewrite of an old one. High and critical incidents also notify the leads who can act on them immediately, in the app, and by email when email is configured.
Incident management is for Admins, Compliance Leads and Risk Managers; everyone else can view incidents.
Notifications & reminders
The bell in the sidebar collects everything that needs your attention: a task assigned to you, an approval waiting on your decision (and the outcome once it is made), a policy submitted for approval, an audit finding raised, or a high- or critical-severity incident reported. It shows an unread count, and the notifications page clears it with Mark all read.
Once a day Govliance also sweeps for governance work that has gone quiet — overdue tasks, evidence due for review, policies past their review date and vendors due for review — and raises each as a reminder in the bell. A reminder you haven't read yet is not repeated.
On Mondays, Admins and Executive Viewers also receive a short posture digest by email, when email is configured.
Training
The training registry records the awareness and competence work an organization does around AI — which teams were trained, by whom, and on what — as competence and awareness evidence that governance frameworks expect.
Record each training with a name, provider, department, duration, the number of people covered and a description, plus a status that moves through Planned, In progress and Completed. Marking a training completed records the date it happened.
Training management is for Admins, Compliance Leads and Risk Managers; everyone else can view the registry. Records are never deleted, so the training history stays intact.
Use cases
Use cases record the business case behind an AI system — why it's being built, for which business function, and what benefit it's expected to deliver — as a proposal that outlives any one system. Each one carries its own lifecycle from Proposed through Approved, In delivery, Live and Retired, and links to the AI systems that serve it, so the reasoning and the registry entries stay connected.
EU AI Act
The EU AI Act module classifies each registered system into the Act's risk categories — from prohibited practices through high-risk, limited-risk (transparency) and minimal-risk, or records that a system is out of the Act's scope — by walking you through the questions that matter, and records the reasoning with the result.
A high-risk classification brings obligations; the module tracks each one's status so "we're working on it" has specifics behind it. Classifications are never silently edited — a re-classification supersedes the old one, which stays on record. Unclassified systems are flagged on the Dashboard, and a single print-ready EU AI Act report covers every registered system's conformity status.
Reports
Two documents cover the two audiences who will never log in:
- Board report — readiness, risk posture and open issues in a page an executive actually reads, downloadable as a branded PDF.
- Audit pack — the auditor's bundle: the AI system inventory (including each system's models), control status, the evidence index and audit findings, with a generated-at timestamp.
API
The Govliance API is a JSON interface to your governance data. An admin creates a bearer token in Settings → API keys — the token is shown once and must be saved somewhere safe — with a scope: read-only by default, or read + write, which lets an integration register systems and report incidents, subject to the key owner's current role.
Requests are authenticated with the Authorization: Bearer gva_… header. There are five endpoints:
- /api/v1/systems — your registered AI systems; a read + write key can also register a new one
- /api/v1/risks — your risk register
- /api/v1/controls — framework controls and their status
- /api/v1/evidence — your evidence vault, metadata only
- /api/v1/incidents — write-only: a read + write key can report an incident
Example request: curl -H "Authorization: Bearer gva_…" https://govliance.com/api/v1/systems
Webhooks push HMAC-signed notifications to your own endpoint for three events — system registered, incident reported, approval decided — configured under Settings → Webhooks, where each endpoint's signing secret stays visible for as long as it exists.
Roles & security
Seven roles, checked on every page and every action:
- Admin — everything, including Members, Workspaces and organization settings.
- Compliance Lead — the full governance toolkit: systems, assessments, risks, evidence, audits, EU AI Act, Policies and approval decisions — without member or workspace management.
- Risk Manager — systems, assessments, risks, evidence and EU AI Act work.
- Contributor — register and maintain systems, run assessments, record risks, attach evidence.
- Internal Auditor — read everything, run Audits, raise findings.
- External Auditor — time-boxed, read-only access plus recording findings.
- Executive Viewer — dashboards, reports and approval decisions.
Underneath: every organization's data is isolated in its own tenant; every create, update and status change lands in an append-only Audit log that nothing in the product can edit or delete; two-factor authentication is built in; and evidence files are private, versioned and served through short-lived links.
Trust center
The trust center is an optional public page you can hand to prospects and partners instead of a compliance questionnaire. It is off by default, and turning it on only ever shows aggregates: your organization name, framework coverage percentages, the number of AI systems you govern, and the titles of your published policies — never risks, evidence, control detail or member names.
Enable it, choose a public link name and an optional contact email or note, from Settings → Trust center.

