Established 2021 · Built and operated in Ireland
Govern AI.Prove every decision.
One governed system for knowing what AI you use, assessing what applies, making accountable decisions and retaining the evidence behind them.
AI governance portfolio
Northfield Group · All departments · Ruleset v2.4
Total AI use cases
64
Registered across 9 departments
Awaiting review
8
3 approaching due date
High risk
6
All with active conditions
Evidence completeness
91%
Across approved records
Risk distribution
- Low21
- Medium29
- High14
Reviews due this month
12
Periodic review, condition expiry and vendor change checks.
Governance queue
- Customer Service CopilotMediumPrivacy reviewAwaiting evidence
- Predictive Maintenance ModelHighQuality and SecurityIn review
- Supplier Document AssistantLowGovernance leadApproved with conditions
- Clinical Operations SummariserHighQuality, Privacy, LegalRestricted
Lifecycle
- Registered
- Assessed
- Reviewed
- Decision
- Monitoring
Illustrative interface – synthetic data
- Ireland
- Built and operated in Ireland
- Deterministic
- Versioned rules, repeatable outcomes
- Human-decided
- Accountable people approve AI
- Evidence-led
- Hashed, append-only decision record
- 2,014
- Automated verification cases executed
The problem
Know. Decide. Prove.
Governance rarely fails at the policy layer. It fails in the operating layer, where assessing, reviewing, evidencing and monitoring actually happen. AIRAS Cloud is that layer.
01
Know
What AI are we actually using?
Systems, models, agents and embedded vendor features arrive faster than any policy cycle. Without one authoritative register, nobody can answer the first question truthfully.
02
Decide
Who said yes, and on what basis?
Decisions get made in meetings, inboxes and slide decks. AIRAS Cloud puts the decision where the assessment is, with named accountability and segregation of duties.
03
Prove
Can we show our working next year?
Regulators, auditors and boards do not ask what you intended. They ask what you assessed, what you controlled and what you retained.
How AIRAS works
One governed path. Eight stages. Nothing left to memory.
Select a stage to see what the business does, what AIRAS Cloud does and what evidence remains on the record afterwards.
Discover and Register
Create a reliable inventory of AI use cases, systems, models, agents, vendor features and owners.
- The business does
- The business owner records the use case, its purpose and the accountable owner.
- AIRAS Cloud does
- AIRAS Cloud allocates a use-case reference, links related systems and vendors, and opens a draft record.
- Evidence retained
- Registration record, ownership, submission version and timestamp.
Typically involves: Business Owner, AI Governance Lead
Platform and engine
Not a model that opines.A deterministic engine that can be re-run.
AIRAS Cloud governs the lifecycle. ARIE supplies the regulatory reasoning. People remain accountable for the decision. Three distinct responsibilities, deliberately kept apart.
Layer 01
AIRAS Cloud
The governed control plane
- Inventory
- Context
- Controls
- Review
- Human decision
- Monitoring
- Evidence
Orchestrates the lifecycle: who owns what, what has been assessed, which controls apply, who reviewed it, what was decided and what evidence is retained.
Layer 02
ARIE
The deterministic regulatory engine
- Qualify
- Role
- Prohibit
- Classify
- Obligations
- Explainable output
Applies approved, versioned regulatory logic to the recorded facts and returns a classification, the applicable obligations and a readable explanation trace that can be re-run.
Layer 03
Accountability
Authorised people, not models
- Named reviewers
- Segregation of duties
- Versioned decisions
ARIE never approves anything. Material decisions stay with authorised people, recorded against the assessment version they actually saw.
The journey
The software came later.The operating model came first.
AIRAS Cloud did not begin as a product. It began as a way of working that had to survive real scrutiny, first in spreadsheets, then in management reporting, and now as a governed platform.
Historic stages are shown as honest reconstructions of the original working views. They are not surviving screenshots.
| AI use case | Owner | Assessment | Evidence | Risk | Review |
|---|---|---|---|---|---|
| Customer contact triage | Operations | Complete | 3 of 3 | High | Approved (cond.) |
| Supplier document extraction | Procurement | Complete | 2 of 3 | Limited | In review |
| Workforce scheduling model | HR | Complete | 1 of 4 | High | Escalated |
| Marketing content assistant | Marketing | Complete | 2 of 2 | Minimal | Approved |
Before there was software, there was a working model: an inventory, a fixed set of assessment questions, evidence status, risk indicators, named human oversight and a review and action trail. Everything AIRAS Cloud enforces today started as disciplined columns.
Proof, not promises
Assessment you can defend. Decisions you can prove.
Two of the mechanisms at the heart of AIRAS Cloud: a deterministic risk engine with a readable explanation trace, and an append-only decision and audit record.
Risk dimensions
Ruleset v2.4 · approved- Impact on people4 / 5
- Data sensitivity4 / 5
- Autonomy of action3 / 5
- Regulatory exposure5 / 5
- Operational criticality3 / 5
- Vendor dependency2 / 5
Calculated outcome
Base calculation returned Medium. A regulatory floor for GxP-impacting use raised the band to High.
Explanation trace
- Special category data declared in intake → sensitivity floor applied
- GxP-impacting process confirmed → Quality review mandatory
- Operational write-back enabled → Security review mandatory
- No prohibited-use pattern matched
Routed to Quality, Cybersecurity and Privacy. Segregation of duties enforced: the submitting owner cannot approve this record.
Rules are versioned and human-approved. AI does not approve AI.
Illustrative interface – synthetic data
Every dimension scored under approved, versioned rules — with floors, prohibited-use checks and the reason the outcome was reached.
Reviewer decisions
- Quality12 Mar
H. Okonkwo · Approved with conditions
- Cybersecurity12 Mar
L. Fereday · Approved
- Privacy / DPO13 Mar
A. Marchetti · Approved with conditions
- Executive sponsor14 Mar
S. Nairn · Final approval
Conditions: quarterly output sampling, documented human review of all customer- facing outputs, and reassessment on model or vendor change.
Audit history
14 Mar 09:41 — Decision recorded: Approved with conditions (v3)
13 Mar 16:02 — Condition added: quarterly output sampling
13 Mar 11:20 — Evidence attached: DPIA-0431 v2
12 Mar 08:55 — Risk recalculated under ruleset v2.4
Append-only. Entries cannot be edited or deleted.
Export
Illustrative interface – synthetic data
Reviewer decisions, conditions and rationale versioned against the record, with an exportable assessment and decision pack.
Verified the way engineering teams verify.
AIRAS Cloud maintains a controlled assurance programme supported by an extensive automated verification and regression estate, executed against the source tree and a running build, with results recorded as evidence rather than described in copy.
- Verification cases
- 2,014
- Passed
- 2,014
- Pass rate (executed)
- 100.0%
- Suites
- 28
Experience developed across complex enterprise environments
AIRAS Cloud is founded on experience delivering complex technology, governance and transformation programmes across regulated and enterprise environments.
Aer LingusAviation
AvolonAviation leasingAIBBanking
Bank of IrelandBanking
IBMTechnology services
KyndrylTechnology services
EirGridCritical infrastructure
Virgin MediaTelecomsIrish GovernmentPublic sector
Alpha programme
Tested in the field, in Ireland, by the people accountable.
Between 2024 and 2025 AIRAS Cloud was tested end to end by risk, compliance, quality, security and audit leaders across regulated Irish organisations. Their feedback shaped the operating model now in production.
- HealthcareMarch 2025
We put nine clinical decision-support tools through the guided intake. The screening picked up two that had never been recorded anywhere and correctly floored a triage model to high risk on human-oversight grounds. The DPIA linkage meant our data protection officer worked from the same record as the clinical governance committee, which had never happened before.
Dr. Niamh Ó Braonáin
Head of Clinical Digital Governance · Voluntary teaching hospital group, Dublin
Tested: Clinical AI intake and DPIA linkage
- Financial servicesApril 2025
The point that convinced our audit committee was that the engine is deterministic and versioned. We re-ran an assessment from six weeks earlier against ruleset 1.0 and got the identical score and explanation trace. Segregation of duties is enforced rather than requested, so the approver genuinely cannot be the assessor.
Cormac Whelan
Director of Risk and Compliance · Irish retail bank, Dublin
Tested: Deterministic scoring and reviewer segregation
- Life sciencesMay 2025
We tested it against a live Annex 11 readiness review. The evidence pack exported with hashed artefacts, control owners, due dates and the full decision history in one document. Our auditor's usual three-week evidence hunt became a single afternoon of review.
Aoife Ní Chatháin
Quality Systems Lead · Contract pharmaceutical manufacturer, Cork
Tested: GxP evidence packs and Annex 11 alignment
- InsuranceMay 2025
Embedded vendor AI was our blind spot. Registering third-party features as first-class entries surfaced eleven capabilities switched on inside tools we already owned. Three needed contractual action. Without the register we would not have known they existed.
Seán Mac Giolla Phádraig
Chief Information Security Officer · Insurance group, Dublin
Tested: Vendor and embedded AI discovery
- Public sectorJune 2025
The prohibited-use checks stopped a proposed profiling use case at intake, with a written rationale we could hand straight to elected members. Being able to show the decision, the version of the rules applied and who approved it is what makes this defensible in a public setting.
Máire Donnelly
Data Protection Officer · Local authority, Galway
Tested: Prohibited-use screening and public accountability
- MedTechJune 2025
We ran two autonomous agents through oversight for six weeks. Scoped permissions, escalation thresholds and the moderation log gave our engineering leads something they had never had: a factual record of what the agent was allowed to do and what it actually did.
Declan Fitzgerald
Head of Data and AI · Medical technology manufacturer, Limerick
Tested: Agent oversight and runtime moderation
- ManufacturingJuly 2025
As an auditor my first instinct is to try to break the trail. The history is append-only, decisions are versioned and nothing can be quietly edited after approval. I tested it deliberately and could not manufacture a gap. That is a rare thing to be able to write in a report.
Sinéad Kavanagh
Group Internal Audit Manager · Food and agribusiness group, Kilkenny
Tested: Audit trail integrity
- TelecomsJuly 2025
Configuration governance was the surprise. Ruleset changes go through controlled versioning, so our risk function can evolve criteria without invalidating historic assessments. Integration into our existing identity and ticketing estate took days, not a quarter.
Ruairí Ó Donnchadha
Enterprise Architect · Telecommunications operator, Dublin
Tested: Multi-tenant configuration and integration
- Life sciencesAugust 2025
We used it to build our EU AI Act inventory position. Classification, obligations and control coverage sit against each system rather than in a spreadsheet a single person maintains. It turned a mapping exercise into an operating routine.
Orla Brennan
Head of Regulatory Affairs · Clinical research organisation, Dublin
Tested: EU AI Act readiness mapping
- Financial servicesSeptember 2025
Our reviewers are not data scientists. The adaptive intake asks only what the context needs and the explanation trace is written in plain language, so a board committee can read the rationale without a translator. Adoption was the fastest I have seen for a governance tool.
Pádraig Lynch
Director of Technology · Credit union services body, Cork
Tested: Adoption by non-technical reviewers
- Professional servicesOctober 2025
Most tools stop at approval. Periodic reassessment triggers and the incident register meant a model that drifted after a data change was picked up, reassessed and re-approved with the change captured against the original decision. That closed loop is the whole point.
Caoimhe Ní Mhurchú
Head of Responsible AI · Professional services firm, Dublin
Tested: Periodic reassessment and incident handling
- LogisticsNovember 2025
The executive view gave me one honest number: how many AI use cases we run, how many are governed and where the gaps sit. Assessment turnaround dropped from roughly five weeks to eight days across the alpha, and the board stopped asking for a status deck because they could see it.
Fergal Byrne
Chief Operating Officer · Logistics and supply chain group, Waterford
Tested: Value realisation and executive reporting
Alpha participants are named with their permission and organisation names are withheld under the confidentiality terms of the programme. Feedback is recorded in a controlled internal record, summarised here, and made available to assurance reviewers under agreement rather than published as a public reference.
Choose your view
What are you here to evaluate?
The depth is all still here. Pick the route that matches your responsibility and we will take you straight to the relevant detail.
- Governance and risk leadSee how assessment, controls, review routing and reassessment work in practice.Continue
- Security and technologyIsolation, encryption, access control, audit history and integration surfaces.Continue
- Privacy and data protectionProcessing basis, data mapping, retention and data subject considerations.Continue
- Quality, audit and assuranceVerification evidence, regression coverage and delivery governance records.Continue
- Procurement and legalLicensing models, controlled documents and how to request evidence.Continue
- Executive sponsorWhat changes for the board: portfolio visibility, accountability and defensibility.Continue
Guided demo · synthetic data only
Hold AI governance in your hand.
A seven-step guided walkthrough of how AIRAS Cloud discovers, qualifies, classifies, decides, evidences and monitors an AI system — with prefilled examples and help notes at every field. Built entirely on synthetic data, and installable to your phone home screen as its own app.
No sign-in, no data collection and no connection to any customer environment.
AIRAS Tour
Govern one AI system, end to end.
- 01Discover
- 02Qualify
- 03Classify
- 04Decide
- 05Evidence
- 06Monitor
- 07Outcome
Synthetic demonstration
Put one AI decision through AIRAS Cloud
Tell us about your organisation, your governance obligations and the next step that would be most useful. A named member of the team will respond directly.
No commercial commitment. No confidential information required.
Explore AIRAS Cloud
- AI governance in Ireland
- EU AI Act Ireland guide
- EU AI Act: what changes on 2 August 2026
- Enterprise AI governance platform
- AI risk assessment
- AI agent governance
- AI governance for financial services
- AI governance for life sciences
- AI governance for healthcare
- AI governance for technology
- What is AI governance?
- EU AI Act governance requirements
- Enterprise governance checklist
- Trust centre
- Press and media
- Contact AIRAS Cloud
