Skip to content
AIRAS Cloud

Operational AI governance and risk assurance

Established 2021 · Live and fully operational

Govern AI with clarity, control and evidence.

One governed path from AI intake to risk assessment, control, review, decision, monitoring and audit-ready evidence. Built for regulated organisations that must show their working.

airascloud.app / governance / portfolio

AI governance portfolio

Northfield Group · All departments · Ruleset v2.4

Filters

Total AI use cases

64

Registered across 9 departments

Awaiting review

8

3 approaching due date

High risk

6

All with active conditions

Evidence completeness

91%

Across approved records

Risk distribution

  • Low21
  • Medium29
  • High14

Reviews due this month

12

Periodic review, condition expiry and vendor change checks.

Governance queue

  • Customer Service CopilotMedium
    Privacy reviewAwaiting evidence
  • Predictive Maintenance ModelHigh
    Quality and SecurityIn review
  • Supplier Document AssistantLow
    Governance leadApproved with conditions
  • Clinical Operations SummariserHigh
    Quality, Privacy, LegalRestricted

Lifecycle

  1. Registered
  2. Assessed
  3. Reviewed
  4. Decision
  5. Monitoring

Illustrative interface – synthetic data

Enterprise delivery experience

AIRAS Cloud is founded on experience delivering complex technology, governance and transformation programmes across regulated and enterprise environments.

  • Aer LingusAviation
  • AvalonAviation leasing
  • AIBBanking
  • Bank of IrelandBanking
  • IBM / KyndrylTechnology services
  • EirGridCritical infrastructure
  • Virgin MediaTelecoms
  • Irish GovernmentPublic sector

The position

Most organisations can list their AI ambitions.Far fewer can evidence their AI decisions.

Policy documents describe intent. Governance fails at the operational layer — where assessing, reviewing, evidencing and monitoring actually happen. AIRAS Cloud is that layer.

One register

Every AI system, model, agent and embedded vendor feature in a single authoritative inventory, with named owners and lifecycle stage.

One rulebook

A deterministic risk engine applies versioned, human-approved criteria, mandatory floors and prohibited-use checks. AI does not approve AI.

One control set

Applicable controls derive from assessed context, with owners, due dates, hashed evidence and visible completeness.

One evidence trail

Versioned decisions, segregation of duties and append-only history that exports as an inspection-ready pack.

The platform

Assessment you can defend. Decisions you can prove.

Two of the mechanisms at the heart of AIRAS Cloud: a deterministic risk engine with a readable explanation trace, and an append-only decision and audit record.

airascloud.app / use-case / UC-0147 / risk assessment

Risk dimensions

Ruleset v2.4 · approved
  • Impact on people4 / 5
  • Data sensitivity4 / 5
  • Autonomy of action3 / 5
  • Regulatory exposure5 / 5
  • Operational criticality3 / 5
  • Vendor dependency2 / 5

Calculated outcome

HighRaised by mandatory floor

Base calculation returned Medium. A regulatory floor for GxP-impacting use raised the band to High.

Explanation trace

  1. Special category data declared in intake → sensitivity floor applied
  2. GxP-impacting process confirmed → Quality review mandatory
  3. Operational write-back enabled → Security review mandatory
  4. No prohibited-use pattern matched

Routed to Quality, Cybersecurity and Privacy. Segregation of duties enforced: the submitting owner cannot approve this record.

Rules are versioned and human-approved. AI does not approve AI.

Illustrative interface – synthetic data

Every dimension scored under approved, versioned rules — with floors, prohibited-use checks and the reason the outcome was reached.

airascloud.app / use-case / UC-0147 / decision record

Reviewer decisions

  • Quality12 Mar

    H. Okonkwo · Approved with conditions

  • Cybersecurity12 Mar

    L. Fereday · Approved

  • Privacy / DPO13 Mar

    A. Marchetti · Approved with conditions

  • Executive sponsor14 Mar

    S. Nairn · Final approval

Conditions: quarterly output sampling, documented human review of all customer- facing outputs, and reassessment on model or vendor change.

Audit history

  1. 14 Mar 09:41 — Decision recorded: Approved with conditions (v3)

  2. 13 Mar 16:02 — Condition added: quarterly output sampling

  3. 13 Mar 11:20 — Evidence attached: DPIA-0431 v2

  4. 12 Mar 08:55 — Risk recalculated under ruleset v2.4

Append-only. Entries cannot be edited or deleted.

Export

Assessment pack Decision pack Control evidence index

Illustrative interface – synthetic data

Reviewer decisions, conditions and rationale versioned against the record, with an exportable assessment and decision pack.

How it works

Eight governed steps, from first idea to inspection-ready evidence.

  1. 01

    Discover and Register

    Create a reliable inventory of AI use cases, systems, models, agents, vendor features and owners.

  2. 02

    Define Context

    Capture intended use, excluded use, users, decisions, value, lifecycle and accountability.

  3. 03

    Map Data and Integrations

    Record inputs, outputs, data classifications, providers, systems, transfers, access and write-back.

  4. 04

    Assess Risk

    Apply transparent, versioned risk rules, mandatory floors and prohibited-use checks.

  5. 05

    Apply Controls

    Generate relevant control and evidence requirements for the assessed context.

  6. 06

    Review and Decide

    Route Quality, Privacy, Security, Legal, Risk and other reviewers with clear segregation of duties.

  7. 07

    Monitor and Reassess

    Control changes, incidents, conditions, periodic reviews, restrictions and retirement.

  8. 08

    Export the Evidence

    Generate traceable assessment and decision packs with versions, mappings and audit history.

Alpha programme

Tested in the field, in Ireland, by the people accountable.

Between 2024 and 2025 AIRAS Cloud was tested end to end by risk, compliance, quality, security and audit leaders across regulated Irish organisations. Their feedback shaped the operating model now in production.

  • HealthcareMarch 2025
    We put nine clinical decision-support tools through the guided intake. The screening picked up two that had never been recorded anywhere and correctly floored a triage model to high risk on human-oversight grounds. The DPIA linkage meant our data protection officer worked from the same record as the clinical governance committee, which had never happened before.

    Dr. Niamh Ó Braonáin

    Head of Clinical Digital Governance · Voluntary teaching hospital group, Dublin

    Tested: Clinical AI intake and DPIA linkage

  • Financial servicesApril 2025
    The point that convinced our audit committee was that the engine is deterministic and versioned. We re-ran an assessment from six weeks earlier against ruleset 1.0 and got the identical score and explanation trace. Segregation of duties is enforced rather than requested, so the approver genuinely cannot be the assessor.

    Cormac Whelan

    Director of Risk and Compliance · Irish retail bank, Dublin

    Tested: Deterministic scoring and reviewer segregation

  • Life sciencesMay 2025
    We tested it against a live Annex 11 readiness review. The evidence pack exported with hashed artefacts, control owners, due dates and the full decision history in one document. Our auditor's usual three-week evidence hunt became a single afternoon of review.

    Aoife Ní Chatháin

    Quality Systems Lead · Contract pharmaceutical manufacturer, Cork

    Tested: GxP evidence packs and Annex 11 alignment

  • InsuranceMay 2025
    Embedded vendor AI was our blind spot. Registering third-party features as first-class entries surfaced eleven capabilities switched on inside tools we already owned. Three needed contractual action. Without the register we would not have known they existed.

    Seán Mac Giolla Phádraig

    Chief Information Security Officer · Insurance group, Dublin

    Tested: Vendor and embedded AI discovery

  • Public sectorJune 2025
    The prohibited-use checks stopped a proposed profiling use case at intake, with a written rationale we could hand straight to elected members. Being able to show the decision, the version of the rules applied and who approved it is what makes this defensible in a public setting.

    Máire Donnelly

    Data Protection Officer · Local authority, Galway

    Tested: Prohibited-use screening and public accountability

  • MedTechJune 2025
    We ran two autonomous agents through oversight for six weeks. Scoped permissions, escalation thresholds and the moderation log gave our engineering leads something they had never had: a factual record of what the agent was allowed to do and what it actually did.

    Declan Fitzgerald

    Head of Data and AI · Medical technology manufacturer, Limerick

    Tested: Agent oversight and runtime moderation

  • ManufacturingJuly 2025
    As an auditor my first instinct is to try to break the trail. The history is append-only, decisions are versioned and nothing can be quietly edited after approval. I tested it deliberately and could not manufacture a gap. That is a rare thing to be able to write in a report.

    Sinéad Kavanagh

    Group Internal Audit Manager · Food and agribusiness group, Kilkenny

    Tested: Audit trail integrity

  • TelecomsJuly 2025
    Configuration governance was the surprise. Ruleset changes go through controlled versioning, so our risk function can evolve criteria without invalidating historic assessments. Integration into our existing identity and ticketing estate took days, not a quarter.

    Ruairí Ó Donnchadha

    Enterprise Architect · Telecommunications operator, Dublin

    Tested: Multi-tenant configuration and integration

  • Life sciencesAugust 2025
    We used it to build our EU AI Act inventory position. Classification, obligations and control coverage sit against each system rather than in a spreadsheet a single person maintains. It turned a mapping exercise into an operating routine.

    Orla Brennan

    Head of Regulatory Affairs · Clinical research organisation, Dublin

    Tested: EU AI Act readiness mapping

  • Financial servicesSeptember 2025
    Our reviewers are not data scientists. The adaptive intake asks only what the context needs and the explanation trace is written in plain language, so a board committee can read the rationale without a translator. Adoption was the fastest I have seen for a governance tool.

    Pádraig Lynch

    Director of Technology · Credit union services body, Cork

    Tested: Adoption by non-technical reviewers

  • Professional servicesOctober 2025
    Most tools stop at approval. Periodic reassessment triggers and the incident register meant a model that drifted after a data change was picked up, reassessed and re-approved with the change captured against the original decision. That closed loop is the whole point.

    Caoimhe Ní Mhurchú

    Head of Responsible AI · Professional services firm, Dublin

    Tested: Periodic reassessment and incident handling

  • LogisticsNovember 2025
    The executive view gave me one honest number: how many AI use cases we run, how many are governed and where the gaps sit. Assessment turnaround dropped from roughly five weeks to eight days across the alpha, and the board stopped asking for a status deck because they could see it.

    Fergal Byrne

    Chief Operating Officer · Logistics and supply chain group, Waterford

    Tested: Value realisation and executive reporting

Alpha participants are named with permission. Organisation names are withheld under the confidentiality terms of the alpha programme.

Where it is used

Regulated environments, treated as first-class.

Screening logic, review routes and evidence expectations reflect the obligations of the sector, not a generic risk template.

  • EU AI Act
  • NIST AI RMF
  • ISO/IEC 42001
  • GDPR / DPIA
  • EU GMP Annex 11
  • SOC 2 / ISO 27001
  • OWASP GenAI guidance

Framework references describe design alignment and evidence support. They do not represent certification, legal advice or a guarantee of compliance.

Register your interest in AIRAS Cloud

Tell us about your organisation, your governance obligations and the next step that would be most useful. A named member of the team will respond directly.

No pricing commitment. No confidential information required.