The platform

Everything you need to govern AI - and the evidence to prove it.

Six modules that work as one governance picture: discover what's in use, control it, score the risk, and keep it current. Each one produces something you can hand to your board.

Six modules

One picture, built from six working parts.

Not a folder of templates - a system that stays live as your tools, teams, and rules change.

AI Tool Inventory MODULE 01 · DISCOVERY

Find every AI tool in use across the business - sanctioned or not - and sort it into a single traffic-light view with owner, team, and data sensitivity.

  • Auto-sorted red-amber-green status
  • Data-sensitivity tag on every tool
  • One source of truth for the board
AI Tool Inventory47 tools
ToolTeamStatus
Otter.aiSalesUnmanaged
ChatGPT (free)MarketingReview
GitHub CopilotEngineeringReview
Claude (Team)LegalGoverned
Employee Surveys MODULE 02 · DISCOVERY

Surface the AI use that never shows up in an IT report. A short staff survey reveals shadow tools and risky habits before they become incidents.

  • Anonymous shadow-AI survey
  • Findings feed straight into the inventory
  • Evidence of what staff actually do
Shadow-AI Surveyresults
73%staff responded
Use AI weekly at work68%
On unapproved tools41%
Pasted client data in1 in 6
Risk Scoring MODULE 03 · EVIDENCE

Score each risk from a published rubric - likelihood by impact - so the numbers are repeatable and you can show your working to an auditor or board.

  • Consistent, rubric-based scoring
  • Plotted risk heatmap
  • No black-box judgement calls
Risk Heatmaplikelihood x impact
HighImpactLow
LowLikelihoodHigh
Vendor Vetting MODULE 04 · GOVERNANCE

A repeatable check for any new AI tool before it gets in - data handling, contracts, residency - ending in a clear keep, restrict, or reject.

  • Standard checklist every time
  • Clear recommendation, not a maybe
  • A record you can point to later
Vendor VettingOtter.ai
Records call audioHigh
DPA in placeNo
Data residencyUnclear
RecommendationRestrict
Incident Tracking MODULE 05 · KEEP CURRENT

Log AI-related incidents, triage them by severity, and follow a response template - so when something goes wrong, you can show you handled it properly.

  • Severity-rated incident log
  • Built-in response template
  • Evidence of a working process
Incident Logopen + closed
IncidentSevState
Client data in free chatbotHighOpen
Unreviewed AI in proposalMedReview
Hallucinated figure caughtLowClosed
Governance Maturity MODULE 06 · EVIDENCE

Assess where you sit across five maturity levels, track it over time, and generate the board briefing pack that turns all of it into a ten-minute read.

  • Five-level maturity assessment
  • Trend view over quarters
  • Board-ready PDF, generated for you
MaturityL3 of 5
L4L3L2L1
Framework mapping

Your evidence, in language auditors recognise.

Each output is cross-referenced to the standards your stakeholders already trust - so it lands without translation.

TruGovAI outputSpeaks to
AI Tool Inventory
ISO 27001 · asset managementNIST AI RMF · map
Risk Posture Scorecard + heatmap
NIST AI RMF · measureCOSO ERM · risk
AI Acceptable Use Policy
EU AI Act · AI literacyUK GDPR · data use
Vendor Vetting record
UK GDPR · processorsISO 27001 · supplier risk
Incident Log + response
NIST AI RMF · manageISO 27001 · incident mgmt
Board Briefing Pack
COSO ERM · oversightEU AI Act · transparency

Governance Ready™ is a good-practice signal against TruGovAI's published rubric. Mappings show where your evidence lines up with each framework's intent - they are not a certification, compliance guarantee, or regulator approval.

See it running on a live tenant.

Twenty minutes, real outputs, your questions answered. Then you decide.

Book a demo