Supply chain & AI governance intelligence

Browser-based · no data leaves your device
SPDX & CycloneDX · CVE mapping
EU AI Act · GDPR · NIST AI RMF
5 stakeholder reports · 32 governance questions

AI Governance Review — five phases, one package

For SBOM analysis (upload, OSV matching, compliance mapping), use the SBOM Analyzer. This section covers the AI accountability workflow.

1

Define System

Name the AI system, describe its purpose, and classify its EU AI Act risk tier. The tool guides you through each field with plain-language explanations of why each one matters to regulators and auditors.

Produces: A formal system record with unique ID, risk classification, and accountable owner.
2

Component Inventory

Answer 32 guided questions across six governance domains: Models, Data, Vendors, Infrastructure, Controls, and Monitoring. Every question includes a "why this matters" explanation and regulatory tags — EU AI Act, GDPR, NIST AI RMF, and SBOM-for-AI minimum elements.

Produces: A complete, structured evidence record across all six governance domains.
3

Gap Analysis

Generated automatically from your answers. Every gap includes its regulatory citation, the risk if left unaddressed, and exactly what evidence is needed to close it. No manual interpretation required.

Produces: A regulatory-cited gap register organized by severity — Critical, Major, Minor.
4

Assess & Assign

For each gap, assign an owner, choose a remediation approach, and set a target date. This information is embedded into every report — so the people reading the output can see who is responsible for what.

Produces: A working action plan with owners and dates embedded into every report.
5

Evidence Package

Generate five stakeholder-specific HTML reports from the single record you've built. Each report is written for its audience — from board-level narrative to technical audit detail — without any additional effort on your part.

Produces: Board report · Technical audit record · Legal/DPO package · CISO assessment · Procurement review.
Start AI Review

Browser-based · no account required · no data leaves your device

Contact for a trial or scoping call FAQ