AI Governance

Which obligations apply to this AI system?

EU AI Act duties depend on what the system does, its risk tier, and whether you are the provider or the deployer. So this is a decision workflow that establishes your actual obligations — not a checklist that asks everyone the same questions.

7
Pages in this module
4
Use-case risk tiers
8
Maturity domains
42001
ISO standard aligned
Classification first

Get the classification wrong and you evidence the wrong duties.

Almost every EU AI Act mistake starts there. The wizard walks a system through classification, establishes your role, and produces the obligation set that actually applies — recording the rationale, which is the thing a regulator asks about first.

  • A portfolio view of every AI initiative, with a Fund / Fix / Freeze triage matrix and proportional model-risk distribution.
  • Use-case inventory across four risk tiers with status workflow and impact assessments — including AI you bought rather than built.
  • Model registry with training-data lineage, bias monitoring and deployment status.
  • Maturity assessment across eight domains — strategy, governance, data, technology, talent, operations, ethics and risk.
  • Article 27 FRIA support for the systems that require a fundamental-rights impact assessment.
  • ISO 42001 alignment with 65 mapped controls, 160 guided questions and 32 document templates.
See it live
+≡GR
GGRCxAI

AI Portfolio

Fund / Fix / Freeze triage across every AI initiative

PortfolioHeatmap
Use cases
34
across 4 risk tiers
Models
207
in registry
High-risk (EU AI Act)
6
obligations mapped
Maturity
3.4
of 5 · 8 domains
Fund12
Document summarisation
Support triage
Fix8
Credit scoring model
CV screening
Freeze2
Emotion inference
EU AI Act — classification outcomeDeployer
SystemRisk tierRoleObligations
Credit scoringHigh riskDeployer12 duties
CV screeningHigh riskDeployer12 duties
Support chatbotLimitedDeployer3 duties
Doc summarisationMinimalDeployerVoluntary
Inside the module

The seven pages

Portfolio through to the specific legal obligation.

AI Portfolio

Every AI initiative in one view with triage matrix, model-risk distribution and maturity gauge.

AI Use Cases

Inventory with four risk tiers, status workflow and impact assessments.

AI Models

Registry with training-data lineage, bias monitoring and deployment status.

AI Maturity

Organisational readiness across eight domains, in full, quick or domain-specific modes.

AI Risk Toolkit

AI-specific risk assessments with automated extraction and control mapping.

EU AI Act

Guided classification, then the obligations that apply to your role and risk tier.

FRIA (Article 27)

Fundamental-rights impact assessments for the systems that require them.

Works with

Every module shares one system of record, so evidence gathered in one place counts everywhere it is needed.

Risk Management

AI risks in the same register as everything else.

Learn more

Compliance & Audit

ISO 42001 controls with evidence.

Learn more

ISO & Training

An ISO 42001 course for the team.

Learn more

Classify it right, then evidence it once.

See the classification wizard run against a real system.