Your AI systems,
properly governed

EU AI Act obligations covered

ISO 42001 Annex A controls pre-seeded

ISO 42001 AIMS modules

hosted — Helsinki, no US sub-processors

No single source of truth

Your AI systems are tracked across spreadsheets, SharePoint folders, and inboxes. There is no audit trail, no owner accountability, and no way to show a regulator or auditor a coherent picture.

Enterprise platforms, enterprise prices

The recognised AI governance platforms — Credo AI, Holistic AI, OneTrust — cost £30,000–£100,000+ per year, require a sales process, and are built for governance teams that don’t look like yours.

US hosting creates its own compliance problem

Routing your AI inventory, risk assessments, and compliance evidence through a US-hosted platform raises GDPR transfer questions that compliance-conscious teams shouldn’t have to answer.

From AI inventory to audit-ready — one platform.

Endaxi AIG takes you through every stage of the AI governance lifecycle, from registering your first system to producing evidence for a regulator or certifying body.

Add every AI system, tool, and vendor-embedded AI capability to a central register. Assign owners, set data sensitivity flags, and track the full lifecycle from proposal to retirement.

A guided classification wizard screens each system through the complete EU AI Act framework — Prohibited, GPAI, High-Risk, Limited Risk, or Minimal Risk — and generates a Legal Classification Certificate with full audit rationale.

A pre-seeded risk taxonomy covers the eight core AI risks — hallucination, bias, prompt injection, model drift, and more. Assign treatment plans, record residual scores, and track risk owner accountability.

Ten pre-built AI-specific controls — mapped to ISO 42001 Annex A and EU AI Act articles — plus four structured assessment templates covering intake, security review, annual reassessment, and change-triggered review.

A board-level dashboard surfaces tier distribution, top risks, and incident trends. A dedicated auditor view gives external reviewers a clean, read-only window into your governance programme. One click produces a per-system audit pack.

Generate Annex IV technical documentation, export your Statement of Applicability, and produce complete audit packs — all in formats designed for regulatory submission and ISO 42001 certification assessments.

Lightweight registration

For low-risk, internal-use tools with no autonomous decision-making. Register the system, complete an intake assessment, confirm EU AI Act classification, and set a review date. Proportionate governance without unnecessary overhead.

Full compliance programme

For AI systems processing personal data, influencing business decisions, or classified as High-Risk under the EU AI Act. Full risk treatment, controls implementation, Fundamental Rights Impact Assessment, Annex IV documentation, and post-market monitoring.

Certification-grade assurance

For mission-critical or publicly consequential AI systems. Adversarial testing, prompt governance, complete evidence trails with expiry tracking, incident response plan testing, CAPA programme, and ISO 42001 management review cycle.

Both frameworks. One platform. No duplication.

Most AI governance tools cover one framework well. Endaxi AIG is built from the ground up to address the EU AI Act and ISO/IEC 42001 simultaneously, with cross-references throughout so you build evidence once and satisfy both.

All 17 obligations covered

  • Serious incident reporting — Art. 73
  • Prohibited practices screening — Art. 5 (7 checks incl. Omnibus)
  • High-risk classification — Art. 6, Annex III (8 categories)
  • Risk management system — Art. 9
  • Technical documentation — Art. 11, Annex IV (15 sections)
  • Human oversight — Art. 14
  • Fundamental Rights Impact Assessment — Art. 27
  • GPAI obligations — Art. 51+
  • Post-market monitoring — Art. 72

Complete AIMS lifecycle — all 10 clauses

  • Nonconformity & CAPA — Clause 10.1
  • AIMS Scope & Context — Clause 4
  • Interested Parties — Clause 4.2
  • AI Policy & Objectives — Clauses 5, 6.2
  • Risk & Impact Assessment — Clause 6.1
  • Statement of Applicability — all 32 Annex A controls
  • Controls Library — mapped to EU AI Act articles
  • Internal Audit — Clause 9.2
  • Management Review — Clause 9.3

DPOs, Heads of Compliance, General Counsel

A system of record for every AI system, with an audit trail that satisfies the ICO, a regulator, or a certifying body. Board-ready reporting without manual assembly.

CROs, Risk Managers, AI Governance Leads

Pre-seeded risk taxonomy, 5×5 scoring matrix, treatment plans, and residual risk tracking. Real-time board dashboard showing your top risks, incident trends, and overdue reviews.

CISOs, Security Reviewers, Technical Owners

Structured security review assessments, prompt governance, adversarial testing logs, vendor DPA and audit rights tracking, and least-privilege API permission logging.

Practices managing multiple client programmes

he Professional tier supports up to five separate organisations on one subscription, with full per-organisation data isolation. Manage client governance programmes without managing separate accounts.

Ready to govern your AI systems properly?