Everything you need to govern AI - and the evidence to prove it.
Six modules that work as one governance picture: discover what's in use, control it, score the risk, and keep it current. Each one produces something you can hand to your board.
One picture, built from six working parts.
Not a folder of templates - a system that stays live as your tools, teams, and rules change.
Find every AI tool in use across the business - sanctioned or not - and sort it into a single traffic-light view with owner, team, and data sensitivity.
- Auto-sorted red-amber-green status
- Data-sensitivity tag on every tool
- One source of truth for the board
| Tool | Team | Status |
|---|---|---|
| Otter.ai | Sales | Unmanaged |
| ChatGPT (free) | Marketing | Review |
| GitHub Copilot | Engineering | Review |
| Claude (Team) | Legal | Governed |
Surface the AI use that never shows up in an IT report. A short staff survey reveals shadow tools and risky habits before they become incidents.
- Anonymous shadow-AI survey
- Findings feed straight into the inventory
- Evidence of what staff actually do
Score each risk from a published rubric - likelihood by impact - so the numbers are repeatable and you can show your working to an auditor or board.
- Consistent, rubric-based scoring
- Plotted risk heatmap
- No black-box judgement calls
A repeatable check for any new AI tool before it gets in - data handling, contracts, residency - ending in a clear keep, restrict, or reject.
- Standard checklist every time
- Clear recommendation, not a maybe
- A record you can point to later
Log AI-related incidents, triage them by severity, and follow a response template - so when something goes wrong, you can show you handled it properly.
- Severity-rated incident log
- Built-in response template
- Evidence of a working process
| Incident | Sev | State |
|---|---|---|
| Client data in free chatbot | High | Open |
| Unreviewed AI in proposal | Med | Review |
| Hallucinated figure caught | Low | Closed |
Assess where you sit across five maturity levels, track it over time, and generate the board briefing pack that turns all of it into a ten-minute read.
- Five-level maturity assessment
- Trend view over quarters
- Board-ready PDF, generated for you
Your evidence, in language auditors recognise.
Each output is cross-referenced to the standards your stakeholders already trust - so it lands without translation.
| TruGovAI output | Speaks to |
|---|---|
| AI Tool Inventory | ISO 27001 · asset managementNIST AI RMF · map |
| Risk Posture Scorecard + heatmap | NIST AI RMF · measureCOSO ERM · risk |
| AI Acceptable Use Policy | EU AI Act · AI literacyUK GDPR · data use |
| Vendor Vetting record | UK GDPR · processorsISO 27001 · supplier risk |
| Incident Log + response | NIST AI RMF · manageISO 27001 · incident mgmt |
| Board Briefing Pack | COSO ERM · oversightEU AI Act · transparency |
Governance Ready™ is a good-practice signal against TruGovAI's published rubric. Mappings show where your evidence lines up with each framework's intent - they are not a certification, compliance guarantee, or regulator approval.
See it running on a live tenant.
Twenty minutes, real outputs, your questions answered. Then you decide.
Book a demo