Integrated management system
01The single register that binds policy, control ownership, review cadence and internal audit across every other domain below.
- Owner
- Chief Executive
- Release
- On request under agreement
Enterprise · For procurement, security and risk reviewers
Enterprise AI governance cannot credibly be sold from an organisation that has not governed itself. AIRAS Cloud operates against a controlled internal assurance estate spanning product, security, privacy, AI governance, impact assessment, resilience, testing, release, operations, intellectual property and supplier risk.
How to read this page
Each domain below names its purpose, its current evidence status, the accountable role and the basis on which material can be released. Confidential artefacts are not published here. Where a domain is marked restricted, it is available only inside a formal process such as executed diligence or a signed agreement.
Assurance estate
The single register that binds policy, control ownership, review cadence and internal audit across every other domain below.
Threat model, control register, hardening standards, key handling, logging and vulnerability management for the platform and its build chain.
Processing records, lawful basis, controller and processor roles, retention, deletion, data-subject handling and transfer position.
Recovery objectives, encrypted backup and scripted restore, rebuild from source control, continuity scenarios and concentration risk.
Our own governance of AI used inside the business and inside the product, including where a model may and may not influence a decision.
Impact-assessment method applied to our own product features, aligned to recognised impact-assessment guidance rather than certified against it.
How scope, regulatory interpretation and ruleset change are proposed, reviewed, approved and versioned before release.
Tenant isolation model, data model, authorisation boundaries, storage separation and audit-event design.
Interface contracts, authentication, scope limits, rate control and the governed interoperability surface for external systems.
Automated unit, integration and end-to-end coverage, authorisation verification and regression evidence produced on every release.
Version control, review before deployment, separate versioning for rulesets and policy packs, and traceable release records.
Monitoring, availability handling, incident classification and the operational runbooks used when something goes wrong.
Support model, response expectations, escalation route and how support access to tenant data is limited and recorded.
Onboarding method, configuration decisions, role design, evidence migration and the definition of a completed implementation.
Ownership and provenance of source, asset register, trade-secret register and the controls protecting engine logic.
Contributor onboarding, confidentiality obligations, access provisioning and removal, and separation of duties.
Sub-processor register, dependency assurance, licence and advisory scanning, and review of platform providers we rely on.
Contracting position, order-form control, pricing governance and the diligence pack maintained for corporate processes.
Independent penetration testing, certification readiness and third-party review: scoped and prepared, not yet completed.
Where to go next
Tell us which domain you need to satisfy and the form your organisation expects it in. We will reply with the available material, or with the terms under which it can be released.
Do not submit credentials, customer data or sensitive evidence in a web form.