Multi-Stage AI Compliance Assessment for Enterprise Leaders
Assess your AI exposure against global governance expectations, AI management system readiness, LLM security risks, agentic AI controls, and board-level accountability — across three SARPI tiers.
Start where it fits your role
Lite is free for everyone. Pro & Enterprise modules show a tiered upgrade once you reach gated sections.
The questions your auditors are already asking.
Enterprises are deploying AI faster than they're governing it. These gaps create regulatory exposure, legal liability, and security incidents.
“Which model produced this decision and was it approved to handle this data?”
Regulators want a signed, verifiable answer — not a best guess from a log file. Without model provenance, you have no defensible audit trail.
“Our AI agent took 30 actions last week. Who authorised them?”
Autonomous agents send emails, execute payments, and query databases without any human in the loop. Most enterprises have no governance layer controlling these actions.
“How do we know the model deployed last month hasn't been tampered with?”
Model weights can be silently modified, backdoored, or poisoned without triggering any existing security tool. Most organisations have no model fingerprinting in place.
“The EU AI Act requires proof of human oversight. What do we show the regulator?”
Compliance frameworks are arriving faster than tooling. Policies do not satisfy auditors — they want signed evidence of controls, decisions, and oversight in action.
One clear AI compliance picture.
Each stage narrows the risk profile and builds the evidence needed for governance, assurance, and advisory action.
AI System Classification
Classify your organization as provider, deployer, importer, distributor, or GPAI user.
Regulatory & Framework Fit
Map obligations across EU AI Act, ISO 42001, NIST AI RMF, OWASP LLM, and Agentic AI.
Governance Maturity
Policies, accountability, inventory, risk appetite, AI literacy, human oversight.
Technical Risk Controls
Data governance, model docs, logging, cybersecurity, prompt safety, monitoring.
Executive Roadmap
Readiness score, heatmap, gap register, prioritized remediation roadmap.
Built across three SARPI tiers.
Tier 1 · Core Frameworks
EU AI Act · ISO/IEC 42001 · NIST AI RMF — free executive snapshot.
- EU AI Act — Risk classification, transparency, GPAI, high-risk obligations.
- ISO/IEC 42001 — AI management system, governance, policies, continual improvement.
- NIST AI RMF — Govern, Map, Measure, Manage across the AI lifecycle.
Tier 2 · Security, Privacy & Enterprise
OWASP LLM · Agentic AI · SOC 2 · GDPR · ISO 27001 — full gap report & roadmap.
- OWASP LLM Top 10 — Prompt injection, sensitive disclosure, output handling, supply chain.
- Agentic AI Controls — Goal hijack, tool misuse, privilege abuse, rogue agents.
- SOC 2 — Security, availability, confidentiality, processing integrity, privacy.
- GDPR — Lawful basis, DPIAs, data-subject rights for AI processing.
- ISO/IEC 27001 — ISMS coverage for AI training data, models, and inference.
Tier 3 · Industry-Specific
HIPAA · PCI DSS · FedRAMP · NIS2 · DORA · SR 11-7 — board-ready diagnostic.
- HIPAA — PHI safeguards across AI training, inference, and audit trails.
- PCI DSS — Cardholder data scope and AI inference inside the CDE.
- FedRAMP — Federal cloud authorization with AI/ML control overlays.
- NIS2 — EU cybersecurity directive for essential & important entities.
- DORA — Digital operational resilience for financial entities.
- SR 11-7 / Model Risk — Federal Reserve model risk management for banks.
What you receive after the assessment.
Compliance Score
Overall readiness score with maturity band.
Risk Heatmap
Per-framework score across governance, security, LLM, agentic AI.
Gap Register
Clear list of gaps, impacted controls, evidence required.
30-60-90 Roadmap
Prioritized remediation plan and advisory next steps.
