AI Governance, the GRC layer
AISIA AIMS GRC
AI management system governance for ISO/IEC 42001, the NIST AI RMF and the EU AI Act. An AI use case moves from intake to a documented Go, Conditional Go, Hold or No-Go, and the reasoning is always visible.
What it does
- Governance pipeline: intake, clearance gate (triage only: pass with conditions, escalate, hold, reject), system and resource registration, EU AI Act classification, impact assessment, statement of applicability with control effectiveness, risk assessment and treatment, action tracker, evidence, disposition, closed.
- The disposition is derived live from the rolled up impact assessment (maximum adjusted and residual impact, high and critical counts) and recomputed whenever impact changes, so a Go is never a checkbox.
- Executive dashboard of portfolio posture: triage mix, disposition mix, risk, controls, evidence.
- Resource register of models, data, services and components per system; AI system cards and model cards generated from the inventory.
- Gap assessment against ISO/IEC 42001, NIST AI RMF or the EU AI Act, generated on demand as a register, a report and a results deck.
- Document library with SHA-256 integrity hashes, an exportable manifest, and the authored AIMS document set and AI life cycle templates loaded per tenant; Annex IV technical documentation export.
- Third party AI vendor register, assessed on the AIMS due diligence checklist.
- Findings from SPRICO filed as control effectiveness evidence through the cross walk.
How it maps to the standards
| Obligation | Where | What the product does | Status |
|---|---|---|---|
| AI system impact assessment | ISO/IEC 42001 clause 6.1.4, A.5 | Amplifier based scoring, base to adjusted to residual, with live preview. | Built |
| Risk assessment and treatment | ISO/IEC 42001 clause 6.1.2, 6.1.3 | Inherent versus residual scoring, treatment, action tracker. | Built |
| Statement of applicability | ISO/IEC 42001 clause 6.1.3 | SoA with control effectiveness across three frameworks. | Built |
| Documented information | ISO/IEC 42001 clause 7.5 | Hashed document library with the authored set. | Built |
| Risk tier and obligations | EU AI Act Articles 6 to 15 | Classification form that advances the pipeline stage. | Built |
| Technical documentation | EU AI Act Annex IV | Export from the inventory and the evidence register. | In build, October 2026 |
| Third party AI due diligence | ISO/IEC 42001 A.10 | Vendor register on the AIMS checklist. | In build, October 2026 |
Honest limits
- Deployment is single instance per customer today; a hosted multi tenant version is in build.
- The SPRICO bridge importer is the last integration step; findings currently arrive as a confirmed workbook.
Deployment
Python, Streamlit and SQLAlchemy over SQLite or PostgreSQL, running entirely inside your estate with no external services. Documents generated in house style.
Take one use case through
Bring the AI system you are least sure about. The demo ends with its disposition and the report that supports it.