Five phases, one coherent workflow
Each phase builds on the last. Finish in one sitting or save progress and return — by phase five you have a structured accountability package with five stakeholder-specific reports to review and share. Pricing
Define System
You start by naming the AI system and describing what it does. The tool then walks you through EU AI Act risk tier classification — Unacceptable, High, Limited, or Minimal. Each field includes a plain-language explanation of why it matters and which regulatory obligation it relates to.
Component Inventory
You answer 32 guided questions across six governance domains: Models, Data, Vendors, Infrastructure, Controls, and Monitoring. Every question shows you why it matters and which regulation it corresponds to — EU AI Act, GDPR, NIST AI RMF 1.0, G7 Hiroshima AI Process, ISO/IEC 42001, OECD AI principles, or SBOM-for-AI minimum elements (AI component transparency requirements). You don't need to know the regulations; the tool surfaces the context for you.
Gap Analysis
The gap register is generated automatically from your inventory answers — no manual analysis required. Every gap includes a severity rating (Critical, Major, or Minor), the specific regulatory article or standard it maps to, a plain-language explanation of the risk if it remains unaddressed, and a precise description of what evidence would close it.
Assess & Assign
For each gap, you assign an owner (by name or role), select a remediation approach, and set a target date. This is where a list of findings becomes an action plan. The ownership data flows directly into every report — so when the board sees a gap, they also see who is responsible for closing it and by when.
Evidence Package
With one action, you generate five stakeholder-specific HTML reports from the record you've built. Each report is written for its intended audience — the board report uses narrative and summary; the technical record includes every question and answer; the legal package focuses on GDPR and EU AI Act obligations; the CISO report covers control gaps, monitoring obligations, and remediation owners; the procurement review maps vendor accountability, contractual gaps, and AI supply chain risk. All five download as self-contained files you can share immediately.
Who runs the review
Designed for cross-functional teams — not just technical users.
Governance & Compliance
- AI governance officers and DPOs
- EU AI Act and GDPR readiness
- Audit and regulator evidence packages
Legal, Security & Procurement
- Legal counsel and privacy teams
- CISOs and risk officers
- Procurement teams evaluating AI vendors
- Each gets a report written for their role
Technical Teams
- ML engineers and system architects
- Infrastructure and DevOps leads
- Technical review record produced automatically
Ready to start?
Both products run in your browser. No account required to get started. Your SBOM files and governance answers stay on your device — they are not uploaded to our servers.
Need a walkthrough? Request a demo