EU AI Act & ISO 42001 Platform
Your AI systems,
properly governed
Endaxi AIG gives compliance and legal teams a single place to register, classify, assess, and audit every AI system in their organisation — against the EU AI Act and ISO/IEC 42001, without enterprise pricing or a US data residency problem.
UPDATED JUNE 2026
Omnibus-current. Endaxi AIG already reflects the May 2026 EU AI Act Digital Omnibus amendments — including the revised Annex III deadline of 2 December 2027 and the new Art. 5(1)(ga) prohibition. No waiting for a roadmap update.
17
EU AI Act obligations covered
32
ISO 42001 Annex A controls pre-seeded
10
ISO 42001 AIMS modules
EU
hosted — Helsinki, no US sub-processors
The Challenge
AI governance is no longer optional.
The tools to do it have been out of reach.
The EU AI Act is in force. ISO 42001 certification is increasingly demanded by enterprise customers and insurers. Your board wants to know your AI risk posture. And the platforms that can genuinely help have been priced for companies ten times your size.
No single source of truth
Your AI systems are tracked across spreadsheets, SharePoint folders, and inboxes. There is no audit trail, no owner accountability, and no way to show a regulator or auditor a coherent picture.
Enterprise platforms, enterprise prices
The recognised AI governance platforms — Credo AI, Holistic AI, OneTrust — cost £30,000–£100,000+ per year, require a sales process, and are built for governance teams that don’t look like yours.
US hosting creates its own compliance problem
Routing your AI inventory, risk assessments, and compliance evidence through a US-hosted platform raises GDPR transfer questions that compliance-conscious teams shouldn’t have to answer.
How It Works
From AI inventory to audit-ready — one platform.
Endaxi AIG takes you through every stage of the AI governance lifecycle, from registering your first system to producing evidence for a regulator or certifying body.
📋
Register your AI estate
Add every AI system, tool, and vendor-embedded AI capability to a central register. Assign owners, set data sensitivity flags, and track the full lifecycle from proposal to retirement.
⚖️
Classify against the EU AI Act
A guided classification wizard screens each system through the complete EU AI Act framework — Prohibited, GPAI, High-Risk, Limited Risk, or Minimal Risk — and generates a Legal Classification Certificate with full audit rationale.
🔍
Assess and treat risk
A pre-seeded risk taxonomy covers the eight core AI risks — hallucination, bias, prompt injection, model drift, and more. Assign treatment plans, record residual scores, and track risk owner accountability.
🛡️
Implement controls and assessments
Ten pre-built AI-specific controls — mapped to ISO 42001 Annex A and EU AI Act articles — plus four structured assessment templates covering intake, security review, annual reassessment, and change-triggered review.
📊
Report to your board and auditors
A board-level dashboard surfaces tier distribution, top risks, and incident trends. A dedicated auditor view gives external reviewers a clean, read-only window into your governance programme. One click produces a per-system audit pack.
📁
Export for regulators and certifiers
Generate Annex IV technical documentation, export your Statement of Applicability, and produce complete audit packs — all in formats designed for regulatory submission and ISO 42001 certification assessments.
Governance Maturity
Start where you are. Progress at your pace.
Not every AI system carries the same risk. Endaxi AIG uses a three-tier governance maturity model that applies the right level of oversight to each system — proportional, trackable, and always audit-ready.
Tier 1 — Minimal
Lightweight registration
For low-risk, internal-use tools with no autonomous decision-making. Register the system, complete an intake assessment, confirm EU AI Act classification, and set a review date. Proportionate governance without unnecessary overhead.
Tier 2 — Regulated
Full compliance programme
For AI systems processing personal data, influencing business decisions, or classified as High-Risk under the EU AI Act. Full risk treatment, controls implementation, Fundamental Rights Impact Assessment, Annex IV documentation, and post-market monitoring.
Tier 3 — Mature
Certification-grade assurance
For mission-critical or publicly consequential AI systems. Adversarial testing, prompt governance, complete evidence trails with expiry tracking, incident response plan testing, CAPA programme, and ISO 42001 management review cycle.
Regulatory Coverage
Both frameworks. One platform. No duplication.
Most AI governance tools cover one framework well. Endaxi AIG is built from the ground up to address the EU AI Act and ISO/IEC 42001 simultaneously, with cross-references throughout so you build evidence once and satisfy both.
EU AI Act (Regulation 2024/1689)
All 17 obligations covered
- Serious incident reporting — Art. 73
- Prohibited practices screening — Art. 5 (7 checks incl. Omnibus)
- High-risk classification — Art. 6, Annex III (8 categories)
- Risk management system — Art. 9
- Technical documentation — Art. 11, Annex IV (15 sections)
- Human oversight — Art. 14
- Fundamental Rights Impact Assessment — Art. 27
- GPAI obligations — Art. 51+
- Post-market monitoring — Art. 72
ISO/IEC 42001:2023
Complete AIMS lifecycle — all 10 clauses
- Nonconformity & CAPA — Clause 10.1
- AIMS Scope & Context — Clause 4
- Interested Parties — Clause 4.2
- AI Policy & Objectives — Clauses 5, 6.2
- Risk & Impact Assessment — Clause 6.1
- Statement of Applicability — all 32 Annex A controls
- Controls Library — mapped to EU AI Act articles
- Internal Audit — Clause 9.2
- Management Review — Clause 9.3
Who It’s For
Built for the people responsible for getting AI governance right.
Compliance & Legal
DPOs, Heads of Compliance, General Counsel
A system of record for every AI system, with an audit trail that satisfies the ICO, a regulator, or a certifying body. Board-ready reporting without manual assembly.
Risk & Governance
CROs, Risk Managers, AI Governance Leads
Pre-seeded risk taxonomy, 5×5 scoring matrix, treatment plans, and residual risk tracking. Real-time board dashboard showing your top risks, incident trends, and overdue reviews.
Security & IT
CISOs, Security Reviewers, Technical Owners
Structured security review assessments, prompt governance, adversarial testing logs, vendor DPA and audit rights tracking, and least-privilege API permission logging.
AI Governance Consultancies
Practices managing multiple client programmes
he Professional tier supports up to five separate organisations on one subscription, with full per-organisation data isolation. Manage client governance programmes without managing separate accounts.
Why Endaxi AIG
What makes Endaxi AIG different from everything else on the market?
🇬🇧
UK & EU hosted
Bare-metal servers in Helsinki. EU jurisdiction. No US cloud providers. No third-country transfer questions.
📐
Governance-ready from day one
Pre-seeded risk taxonomy, controls library, 5×5 risk matrix, and all 32 ISO 42001 Annex A controls. Not a blank canvas.
⚡
Omnibus-current
Already updated for the May 2026 Digital Omnibus amendments. Most platforms are still on their roadmap.
💷
Transparent pricing
From £149/month. Published. No sales call required to see what you’re paying. No feature restrictions by tier.
🔒
Enterprise-grade security
Argon2id passwords, email 2FA on every login, CSRF protection, HSTS, strict CSP, and append-only audit logging.
📦
Your data is always yours
Export everything — SoA, audit packs, Annex IV documentation — at any time, in standard formats. No lock-in.
Who It’s For
Built for the people responsible for getting AI governance right.
Capability
Endaxi AIG
Credo AI
Holistic AI
OneTrust AI
EU AI Act — all 17 obligations
✓
✓
Partial
Partial
ISO/IEC 42001 — full AIMS lifecycle
✓
Partial
✗
✗
Omnibus 2026 alignment
✓
Roadmap
Partial
Roadmap
FRIA (Art. 27) module
✓
Partial
✗
✗
UK / EU data hosting
✓
✗ US
✗ US
✗ US
Self-serve — no sales call needed
✓
✗
✗
✗
Published pricing
✓
✗
✗
✗
Three-tier maturity model
✓
✗
✗
✗
Starting price (annual)
£1,788
£30,000+
£25,000+
£25,000+
Ready to govern your AI systems properly?
Start with a plan that fits your current AI estate. Every feature, every framework, on every tier. Upgrade as you grow.
