How it works
A governed path from first idea to inspection-ready evidence.
Each step shows what the business owner does, what AIRAS Cloud does, which teams are involved and what evidence is retained.
- Step 01
Discover and Register
Create a reliable inventory of AI use cases, systems, models, agents, vendor features and owners.
- The owner
- The business owner records the use case, its purpose and the accountable owner.
- AIRAS Cloud
- AIRAS Cloud allocates a use-case reference, links related systems and vendors, and opens a draft record.
- Teams involved
- Business Owner, AI Governance Lead
- Evidence retained
- Registration record, ownership, submission version and timestamp.
- Step 02
Define Context
Capture intended use, excluded use, users, decisions, value, lifecycle and accountability.
- The owner
- The owner completes guided questions in plain business language, saving drafts as needed.
- AIRAS Cloud
- Configurable intake sections adapt to answers and highlight missing information before submission.
- Teams involved
- Business Owner, AI Governance Lead
- Evidence retained
- Intake responses, draft history and submitted version.
- Step 03
Map Data and Integrations
Record inputs, outputs, data classifications, providers, systems, transfers, access and write-back.
- The owner
- The owner identifies data categories, connected systems and providers.
- AIRAS Cloud
- Relationships are stored against the record so downstream reviews inherit accurate context.
- Teams involved
- Privacy / DPO, Enterprise Architecture, Cybersecurity
- Evidence retained
- Data map, integration list and transfer context.
- Step 04
Assess Risk
Apply transparent, versioned risk rules, mandatory floors and prohibited-use checks.
- The owner
- The owner reviews the calculated result and the reasons behind it.
- AIRAS Cloud
- A deterministic engine scores each dimension, applies approved floors and records an explanation trace.
- Teams involved
- AI Governance Lead, Risk
- Evidence retained
- Ruleset version, dimension scores, triggered floors and explanation trace.
- Step 05
Apply Controls
Generate relevant control and evidence requirements for the assessed context.
- The owner
- The owner assigns evidence owners and target dates.
- AIRAS Cloud
- Applicable controls are derived from the assessed context, with completeness tracking.
- Teams involved
- Quality / CSV, Cybersecurity, Privacy
- Evidence retained
- Control set, evidence requirements, owners and due dates.
- Step 06
Review and Decide
Route Quality, Privacy, Security, Legal, Risk and other reviewers with clear segregation of duties.
- The owner
- The owner responds to evidence requests and reviewer questions.
- AIRAS Cloud
- Reviewers are routed by role, decisions are versioned and conditions are recorded against the record.
- Teams involved
- Quality, Privacy, Security, Legal, Risk, Executive Sponsor
- Evidence retained
- Reviewer decisions, rationale, conditions and decision version history.
- Step 07
Monitor and Reassess
Control changes, incidents, conditions, periodic reviews, restrictions and retirement.
- The owner
- The owner reports material change and monitors agreed thresholds.
- AIRAS Cloud
- Review dates, monitoring plans, incidents and restrictions are managed against the live record.
- Teams involved
- AI Governance Lead, Quality, Cybersecurity, Internal Audit
- Evidence retained
- Monitoring results, change assessments, incident records and review outcomes.
- Step 08
Export the Evidence
Generate traceable assessment and decision packs with versions, mappings and audit history.
- The owner
- The owner or governance team produces the pack required for audit or inspection.
- AIRAS Cloud
- Exports assemble the assessment, controls, evidence and decisions with version references.
- Teams involved
- Internal Audit, Quality, Executive Sponsor
- Evidence retained
- Export pack, export log and append-only audit history.
Common questions
What governance, risk and audit teams ask us first.
- What is AI governance software and why does it need to be operational?
- AI governance software gives an organisation one authoritative record of every AI system, model, agent and embedded vendor feature in use, together with the risk assessment, controls, reviews, decisions and evidence attached to it. Policy documents describe intent; an operational platform is where assessing, reviewing, evidencing and monitoring actually happen, so that a decision can be reconstructed months later exactly as it was made.
- How does AIRAS Cloud support EU AI Act readiness?
- AIRAS Cloud structures intake, classification and risk assessment around obligations drawn from the EU AI Act, including prohibited-use checks, mandatory risk floors, intended and excluded use, data mapping, human oversight and technical documentation evidence. Framework references describe design alignment and evidence support. They do not represent certification, legal advice or a guarantee of compliance.
- Is the risk assessment generated by AI?
- No. AIRAS Cloud uses a deterministic risk engine that applies versioned, human-approved criteria. Every score, floor and prohibited-use trigger is explainable and reproducible against the ruleset version in force at the time. AI does not approve AI.
- Which frameworks and standards does AIRAS Cloud map to?
- The control libraries and evidence model support the EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR and DPIA obligations, EU GMP Annex 11, SOC 2 and ISO 27001 evidence programmes, and OWASP GenAI guidance.
- Who uses AIRAS Cloud inside an organisation?
- Business owners register and describe use cases. AI governance leads run assessment and routing. Quality, privacy, security, legal and risk reviewers make decisions under segregation of duties. Internal audit and executive sponsors consume the exported assessment and decision packs.
- Can we see AIRAS Cloud before speaking to sales?
- Yes. A synthetic demonstration environment covering the full control plane is available on request, and there is no public pricing or checkout. Register your interest and a named member of the team responds directly with access and a proposed next step.
- How is evidence kept audit-ready?
- Decisions are versioned, history is append-only, evidence is hashed against the record, and assessment and decision packs export with ruleset versions, control mappings, reviewer rationale and timestamps included.
Bring this workflow to your organisation
Register your interest and we will discuss how the steps map onto your existing governance forums, policies and control libraries.
No pricing commitment. No confidential information required.