Getting started

From exposure scan to audit-ready

A clear path from your first AI exposure scan to continuous, evidenced governance — four steps, with an owner and a target on every system.

The path

How it works

Four steps take you from discovering your AI estate to assuring and reporting on it continuously.

1

Run the Exposure Scan

Find the AI across your estate and score where your exposure sits before anything else.

Exposure Scan →
2

Assess readiness

Measure each system against ISO 42001 and the EU AI Act to see where the gaps are.

Readiness →
3

Govern in the platform

Build your inventory, apply controls and capture the evidence behind every decision.

Governance Platform →
4

Assure & report

Keep controls under continuous assurance and turn the results into board packs.

Runtime Assurance →
Before you start

What you'll need

A short list keeps the first scan moving and makes the results easy to act on.

🧠

Your AI systems

A rough picture of the AI in use across your teams — even a partial list is enough to start.

  • Models and assistants in use
  • Vendor and in-house systems
  • Where each one runs
🎯

Framework targets

The frameworks you need to meet, so readiness is measured against the right bar from day one.

  • EU AI Act obligations
  • ISO 42001 alignment
  • NIST AI RMF where relevant
👤

An owner per system

A named owner for each system, so every decision and piece of evidence has someone accountable.

  • One accountable owner
  • Clear escalation path
  • Decisions you can trace

Start with the scan

Run an exposure scan, see where you stand, and take the path from there to audit-ready.