Everything you need to govern AI, and prove you did
GovernedAI covers the full lifecycle of an AI system: registration, risk classification, review and approval, ongoing change tracking, and the evidence an auditor will ask for.
Capabilities
AI inventory
One system of record for every AI system and AI-enabled vendor tool.
- Owner, business unit, data classification, deployment status
- Bulk import from CSV or Excel
- Archive without losing history
Risk classification
Use-case questionnaires score each system and assign a risk tier.
- Templates for ambient scribe, clinical decision support, prior auth / UM, RCM and billing, and patient chatbots
- Separate life-safety and technology/data risk lenses
- A supplemental assessment for agentic AI systems
Regulatory mapping
Each classification flags the regulations a system likely triggers, with a compliance checklist checked against real evidence.
- NIST AI RMF, EU AI Act, ISO/IEC 42001, NYC Local Law 144, Colorado SB21-169
- 2026 state AI health-insurance laws (AL, CO, GA, IL, IA, UT, WA)
- New regulations added as data, without waiting on a release
Workflows & approvals
A defined intake and risk-review path before any system goes live.
- Approve, conditionally approve, or reject, with required rationale
- Governance-relevant changes reopen review automatically
- Role-based access: admins, reviewers, contributors
Evidence & audit trail
Evidence attached where it belongs, and a record auditors can trust.
- Evidence tagged by type: BAA, SOC 2, model card, bias audit, policy, test results
- Tamper-evident, hash-chained audit log per system
- Incident reporting with remediation and disclosure tracking
Vendor oversight
A registry of the vendors behind your AI systems.
- BAA status, subprocessors, SOC 2 and model-card links
- Re-attestation reminders on a cadence you set
- Agent-platform controls: kill switch, permission scoping, audit-log export
Regulatory updates
A curated feed of regulatory developments, matched to your systems.
- “May affect N of your systems” with the reason shown
- Record a review outcome to each system’s audit trail
- Primary sources linked on every item
Reports & sharing
Hand over proof without a scramble.
- Per-system governance report (PDF) and audit export (CSV)
- Portfolio-level report across all systems
- Time-boxed, read-only share links for auditors
Integrations & access
Fits how your organization already works.
- SAML and OIDC single sign-on
- REST API with per-organization keys and an OpenAPI reference
- Multi-organization tenancy with strict data isolation
See it on your own systems
Start a 10-day free trial, or talk to us about an Enterprise rollout.