Skip to content
AIRAS Cloud

Established 2021 · Built and operated in Ireland

Govern AI.Prove every decision.

One governed system for knowing what AI you use, assessing what applies, making accountable decisions and retaining the evidence behind them.

Trust and assurance →

airascloud.app / governance / portfolio

AI governance portfolio

Northfield Group · All departments · Ruleset v2.4

Filters

Total AI use cases

64

Registered across 9 departments

Awaiting review

8

3 approaching due date

High risk

6

All with active conditions

Evidence completeness

91%

Across approved records

Risk distribution

  • Low21
  • Medium29
  • High14

Reviews due this month

12

Periodic review, condition expiry and vendor change checks.

Governance queue

  • Customer Service CopilotMedium
    Privacy reviewAwaiting evidence
  • Predictive Maintenance ModelHigh
    Quality and SecurityIn review
  • Supplier Document AssistantLow
    Governance leadApproved with conditions
  • Clinical Operations SummariserHigh
    Quality, Privacy, LegalRestricted

Lifecycle

  1. Registered
  2. Assessed
  3. Reviewed
  4. Decision
  5. Monitoring

Illustrative interface – synthetic data

Ireland
Built and operated in Ireland
Deterministic
Versioned rules, repeatable outcomes
Human-decided
Accountable people approve AI
Evidence-led
Hashed, append-only decision record
2,014
Automated verification cases executed

The problem

Know. Decide. Prove.

Governance rarely fails at the policy layer. It fails in the operating layer, where assessing, reviewing, evidencing and monitoring actually happen. AIRAS Cloud is that layer.

01

Know

What AI are we actually using?

Systems, models, agents and embedded vendor features arrive faster than any policy cycle. Without one authoritative register, nobody can answer the first question truthfully.

02

Decide

Who said yes, and on what basis?

Decisions get made in meetings, inboxes and slide decks. AIRAS Cloud puts the decision where the assessment is, with named accountability and segregation of duties.

03

Prove

Can we show our working next year?

Regulators, auditors and boards do not ask what you intended. They ask what you assessed, what you controlled and what you retained.

How AIRAS works

One governed path. Eight stages. Nothing left to memory.

Select a stage to see what the business does, what AIRAS Cloud does and what evidence remains on the record afterwards.

Discover and Register

Create a reliable inventory of AI use cases, systems, models, agents, vendor features and owners.

The business does
The business owner records the use case, its purpose and the accountable owner.
AIRAS Cloud does
AIRAS Cloud allocates a use-case reference, links related systems and vendors, and opens a draft record.
Evidence retained
Registration record, ownership, submission version and timestamp.

Typically involves: Business Owner, AI Governance Lead

Platform and engine

Not a model that opines.A deterministic engine that can be re-run.

AIRAS Cloud governs the lifecycle. ARIE supplies the regulatory reasoning. People remain accountable for the decision. Three distinct responsibilities, deliberately kept apart.

  1. Layer 01

    AIRAS Cloud

    The governed control plane

    • Inventory
    • Context
    • Controls
    • Review
    • Human decision
    • Monitoring
    • Evidence

    Orchestrates the lifecycle: who owns what, what has been assessed, which controls apply, who reviewed it, what was decided and what evidence is retained.

  2. Layer 02

    ARIE

    The deterministic regulatory engine

    • Qualify
    • Role
    • Prohibit
    • Classify
    • Obligations
    • Explainable output

    Applies approved, versioned regulatory logic to the recorded facts and returns a classification, the applicable obligations and a readable explanation trace that can be re-run.

  3. Layer 03

    Accountability

    Authorised people, not models

    • Named reviewers
    • Segregation of duties
    • Versioned decisions

    ARIE never approves anything. Material decisions stay with authorised people, recorded against the assessment version they actually saw.

The journey

The software came later.The operating model came first.

AIRAS Cloud did not begin as a product. It began as a way of working that had to survive real scrutiny, first in spreadsheets, then in management reporting, and now as a governed platform.

Historic stages are shown as honest reconstructions of the original working views. They are not surviving screenshots.

ExcelReconstructed working view
Excel: illustrative reconstructed governance view
AI use caseOwnerAssessmentEvidenceRiskReview
Customer contact triageOperationsComplete3 of 3HighApproved (cond.)
Supplier document extractionProcurementComplete2 of 3LimitedIn review
Workforce scheduling modelHRComplete1 of 4HighEscalated
Marketing content assistantMarketingComplete2 of 2MinimalApproved

Before there was software, there was a working model: an inventory, a fixed set of assessment questions, evidence status, risk indicators, named human oversight and a review and action trail. Everything AIRAS Cloud enforces today started as disciplined columns.

Proof, not promises

Assessment you can defend. Decisions you can prove.

Two of the mechanisms at the heart of AIRAS Cloud: a deterministic risk engine with a readable explanation trace, and an append-only decision and audit record.

airascloud.app / use-case / UC-0147 / risk assessment

Risk dimensions

Ruleset v2.4 · approved
  • Impact on people4 / 5
  • Data sensitivity4 / 5
  • Autonomy of action3 / 5
  • Regulatory exposure5 / 5
  • Operational criticality3 / 5
  • Vendor dependency2 / 5

Calculated outcome

HighRaised by mandatory floor

Base calculation returned Medium. A regulatory floor for GxP-impacting use raised the band to High.

Explanation trace

  1. Special category data declared in intake → sensitivity floor applied
  2. GxP-impacting process confirmed → Quality review mandatory
  3. Operational write-back enabled → Security review mandatory
  4. No prohibited-use pattern matched

Routed to Quality, Cybersecurity and Privacy. Segregation of duties enforced: the submitting owner cannot approve this record.

Rules are versioned and human-approved. AI does not approve AI.

Illustrative interface – synthetic data

Every dimension scored under approved, versioned rules — with floors, prohibited-use checks and the reason the outcome was reached.

airascloud.app / use-case / UC-0147 / decision record

Reviewer decisions

  • Quality12 Mar

    H. Okonkwo · Approved with conditions

  • Cybersecurity12 Mar

    L. Fereday · Approved

  • Privacy / DPO13 Mar

    A. Marchetti · Approved with conditions

  • Executive sponsor14 Mar

    S. Nairn · Final approval

Conditions: quarterly output sampling, documented human review of all customer- facing outputs, and reassessment on model or vendor change.

Audit history

  1. 14 Mar 09:41 — Decision recorded: Approved with conditions (v3)

  2. 13 Mar 16:02 — Condition added: quarterly output sampling

  3. 13 Mar 11:20 — Evidence attached: DPIA-0431 v2

  4. 12 Mar 08:55 — Risk recalculated under ruleset v2.4

Append-only. Entries cannot be edited or deleted.

Export

Assessment pack Decision pack Control evidence index

Illustrative interface – synthetic data

Reviewer decisions, conditions and rationale versioned against the record, with an exportable assessment and decision pack.

Verified the way engineering teams verify.

AIRAS Cloud maintains a controlled assurance programme supported by an extensive automated verification and regression estate, executed against the source tree and a running build, with results recorded as evidence rather than described in copy.

Verification cases
2,014
Passed
2,014
Pass rate (executed)
100.0%
Suites
28

Experience developed across complex enterprise environments

AIRAS Cloud is founded on experience delivering complex technology, governance and transformation programmes across regulated and enterprise environments.

  • Aer Lingus logoAer LingusAviation
  • Avolon logoAvolonAviation leasing
  • AIB logoAIBBanking
  • Bank of Ireland logoBank of IrelandBanking
  • IBM logoIBMTechnology services
  • Kyndryl logoKyndrylTechnology services
  • EirGrid logoEirGridCritical infrastructure
  • Virgin Media logoVirgin MediaTelecoms
  • Irish Government logoIrish GovernmentPublic sector

Alpha programme

Tested in the field, in Ireland, by the people accountable.

Between 2024 and 2025 AIRAS Cloud was tested end to end by risk, compliance, quality, security and audit leaders across regulated Irish organisations. Their feedback shaped the operating model now in production.

  • HealthcareMarch 2025
    We put nine clinical decision-support tools through the guided intake. The screening picked up two that had never been recorded anywhere and correctly floored a triage model to high risk on human-oversight grounds. The DPIA linkage meant our data protection officer worked from the same record as the clinical governance committee, which had never happened before.

    Dr. Niamh Ó Braonáin

    Head of Clinical Digital Governance · Voluntary teaching hospital group, Dublin

    Tested: Clinical AI intake and DPIA linkage

  • Financial servicesApril 2025
    The point that convinced our audit committee was that the engine is deterministic and versioned. We re-ran an assessment from six weeks earlier against ruleset 1.0 and got the identical score and explanation trace. Segregation of duties is enforced rather than requested, so the approver genuinely cannot be the assessor.

    Cormac Whelan

    Director of Risk and Compliance · Irish retail bank, Dublin

    Tested: Deterministic scoring and reviewer segregation

  • Life sciencesMay 2025
    We tested it against a live Annex 11 readiness review. The evidence pack exported with hashed artefacts, control owners, due dates and the full decision history in one document. Our auditor's usual three-week evidence hunt became a single afternoon of review.

    Aoife Ní Chatháin

    Quality Systems Lead · Contract pharmaceutical manufacturer, Cork

    Tested: GxP evidence packs and Annex 11 alignment

  • InsuranceMay 2025
    Embedded vendor AI was our blind spot. Registering third-party features as first-class entries surfaced eleven capabilities switched on inside tools we already owned. Three needed contractual action. Without the register we would not have known they existed.

    Seán Mac Giolla Phádraig

    Chief Information Security Officer · Insurance group, Dublin

    Tested: Vendor and embedded AI discovery

  • Public sectorJune 2025
    The prohibited-use checks stopped a proposed profiling use case at intake, with a written rationale we could hand straight to elected members. Being able to show the decision, the version of the rules applied and who approved it is what makes this defensible in a public setting.

    Máire Donnelly

    Data Protection Officer · Local authority, Galway

    Tested: Prohibited-use screening and public accountability

  • MedTechJune 2025
    We ran two autonomous agents through oversight for six weeks. Scoped permissions, escalation thresholds and the moderation log gave our engineering leads something they had never had: a factual record of what the agent was allowed to do and what it actually did.

    Declan Fitzgerald

    Head of Data and AI · Medical technology manufacturer, Limerick

    Tested: Agent oversight and runtime moderation

  • ManufacturingJuly 2025
    As an auditor my first instinct is to try to break the trail. The history is append-only, decisions are versioned and nothing can be quietly edited after approval. I tested it deliberately and could not manufacture a gap. That is a rare thing to be able to write in a report.

    Sinéad Kavanagh

    Group Internal Audit Manager · Food and agribusiness group, Kilkenny

    Tested: Audit trail integrity

  • TelecomsJuly 2025
    Configuration governance was the surprise. Ruleset changes go through controlled versioning, so our risk function can evolve criteria without invalidating historic assessments. Integration into our existing identity and ticketing estate took days, not a quarter.

    Ruairí Ó Donnchadha

    Enterprise Architect · Telecommunications operator, Dublin

    Tested: Multi-tenant configuration and integration

  • Life sciencesAugust 2025
    We used it to build our EU AI Act inventory position. Classification, obligations and control coverage sit against each system rather than in a spreadsheet a single person maintains. It turned a mapping exercise into an operating routine.

    Orla Brennan

    Head of Regulatory Affairs · Clinical research organisation, Dublin

    Tested: EU AI Act readiness mapping

  • Financial servicesSeptember 2025
    Our reviewers are not data scientists. The adaptive intake asks only what the context needs and the explanation trace is written in plain language, so a board committee can read the rationale without a translator. Adoption was the fastest I have seen for a governance tool.

    Pádraig Lynch

    Director of Technology · Credit union services body, Cork

    Tested: Adoption by non-technical reviewers

  • Professional servicesOctober 2025
    Most tools stop at approval. Periodic reassessment triggers and the incident register meant a model that drifted after a data change was picked up, reassessed and re-approved with the change captured against the original decision. That closed loop is the whole point.

    Caoimhe Ní Mhurchú

    Head of Responsible AI · Professional services firm, Dublin

    Tested: Periodic reassessment and incident handling

  • LogisticsNovember 2025
    The executive view gave me one honest number: how many AI use cases we run, how many are governed and where the gaps sit. Assessment turnaround dropped from roughly five weeks to eight days across the alpha, and the board stopped asking for a status deck because they could see it.

    Fergal Byrne

    Chief Operating Officer · Logistics and supply chain group, Waterford

    Tested: Value realisation and executive reporting

Controlled document

Alpha participants are named with their permission and organisation names are withheld under the confidentiality terms of the programme. Feedback is recorded in a controlled internal record, summarised here, and made available to assurance reviewers under agreement rather than published as a public reference.

Guided demo · synthetic data only

Hold AI governance in your hand.

A seven-step guided walkthrough of how AIRAS Cloud discovers, qualifies, classifies, decides, evidences and monitors an AI system — with prefilled examples and help notes at every field. Built entirely on synthetic data, and installable to your phone home screen as its own app.

No sign-in, no data collection and no connection to any customer environment.

AIRAS Tour

Govern one AI system, end to end.

  • 01Discover
  • 02Qualify
  • 03Classify
  • 04Decide
  • 05Evidence
  • 06Monitor
  • 07Outcome

Synthetic demonstration

Cover of The Irish Guide to AI Governance by Richie Higgins, Founder and CEO of AIRAS Cloud

Free eBook · 28 pages

The Irish Guide to AI Governance

What the EU AI Act means after 2 August 2026 — and the practical steps Irish organisations should take next. Written by our founder, Richie Higgins. No form, no paywall.

Put one AI decision through AIRAS Cloud

Tell us about your organisation, your governance obligations and the next step that would be most useful. A named member of the team will respond directly.

No commercial commitment. No confidential information required.