Skip to content
AIRAS Cloud

How it works

A governed path from first idea to inspection-ready evidence.

Each step shows what the business owner does, what AIRAS Cloud does, which teams are involved and what evidence is retained.

  1. Step 01

    Discover and Register

    Create a reliable inventory of AI use cases, systems, models, agents, vendor features and owners.

    The owner
    The business owner records the use case, its purpose and the accountable owner.
    AIRAS Cloud
    AIRAS Cloud allocates a use-case reference, links related systems and vendors, and opens a draft record.
    Teams involved
    Business Owner, AI Governance Lead
    Evidence retained
    Registration record, ownership, submission version and timestamp.
  2. Step 02

    Define Context

    Capture intended use, excluded use, users, decisions, value, lifecycle and accountability.

    The owner
    The owner completes guided questions in plain business language, saving drafts as needed.
    AIRAS Cloud
    Configurable intake sections adapt to answers and highlight missing information before submission.
    Teams involved
    Business Owner, AI Governance Lead
    Evidence retained
    Intake responses, draft history and submitted version.
  3. Step 03

    Map Data and Integrations

    Record inputs, outputs, data classifications, providers, systems, transfers, access and write-back.

    The owner
    The owner identifies data categories, connected systems and providers.
    AIRAS Cloud
    Relationships are stored against the record so downstream reviews inherit accurate context.
    Teams involved
    Privacy / DPO, Enterprise Architecture, Cybersecurity
    Evidence retained
    Data map, integration list and transfer context.
  4. Step 04

    Assess Risk

    Apply transparent, versioned risk rules, mandatory floors and prohibited-use checks.

    The owner
    The owner reviews the calculated result and the reasons behind it.
    AIRAS Cloud
    A deterministic engine scores each dimension, applies approved floors and records an explanation trace.
    Teams involved
    AI Governance Lead, Risk
    Evidence retained
    Ruleset version, dimension scores, triggered floors and explanation trace.
  5. Step 05

    Apply Controls

    Generate relevant control and evidence requirements for the assessed context.

    The owner
    The owner assigns evidence owners and target dates.
    AIRAS Cloud
    Applicable controls are derived from the assessed context, with completeness tracking.
    Teams involved
    Quality / CSV, Cybersecurity, Privacy
    Evidence retained
    Control set, evidence requirements, owners and due dates.
  6. Step 06

    Review and Decide

    Route Quality, Privacy, Security, Legal, Risk and other reviewers with clear segregation of duties.

    The owner
    The owner responds to evidence requests and reviewer questions.
    AIRAS Cloud
    Reviewers are routed by role, decisions are versioned and conditions are recorded against the record.
    Teams involved
    Quality, Privacy, Security, Legal, Risk, Executive Sponsor
    Evidence retained
    Reviewer decisions, rationale, conditions and decision version history.
  7. Step 07

    Monitor and Reassess

    Control changes, incidents, conditions, periodic reviews, restrictions and retirement.

    The owner
    The owner reports material change and monitors agreed thresholds.
    AIRAS Cloud
    Review dates, monitoring plans, incidents and restrictions are managed against the live record.
    Teams involved
    AI Governance Lead, Quality, Cybersecurity, Internal Audit
    Evidence retained
    Monitoring results, change assessments, incident records and review outcomes.
  8. Step 08

    Export the Evidence

    Generate traceable assessment and decision packs with versions, mappings and audit history.

    The owner
    The owner or governance team produces the pack required for audit or inspection.
    AIRAS Cloud
    Exports assemble the assessment, controls, evidence and decisions with version references.
    Teams involved
    Internal Audit, Quality, Executive Sponsor
    Evidence retained
    Export pack, export log and append-only audit history.

Common questions

What governance, risk and audit teams ask us first.

What is AI governance software and why does it need to be operational?
AI governance software gives an organisation one authoritative record of every AI system, model, agent and embedded vendor feature in use, together with the risk assessment, controls, reviews, decisions and evidence attached to it. Policy documents describe intent; an operational platform is where assessing, reviewing, evidencing and monitoring actually happen, so that a decision can be reconstructed months later exactly as it was made.
How does AIRAS Cloud support EU AI Act readiness?
AIRAS Cloud structures intake, classification and risk assessment around obligations drawn from the EU AI Act, including prohibited-use checks, mandatory risk floors, intended and excluded use, data mapping, human oversight and technical documentation evidence. Framework references describe design alignment and evidence support. They do not represent certification, legal advice or a guarantee of compliance.
Is the risk assessment generated by AI?
No. AIRAS Cloud uses a deterministic risk engine that applies versioned, human-approved criteria. Every score, floor and prohibited-use trigger is explainable and reproducible against the ruleset version in force at the time. AI does not approve AI.
Which frameworks and standards does AIRAS Cloud map to?
The control libraries and evidence model support the EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR and DPIA obligations, EU GMP Annex 11, SOC 2 and ISO 27001 evidence programmes, and OWASP GenAI guidance.
Who uses AIRAS Cloud inside an organisation?
Business owners register and describe use cases. AI governance leads run assessment and routing. Quality, privacy, security, legal and risk reviewers make decisions under segregation of duties. Internal audit and executive sponsors consume the exported assessment and decision packs.
Can we see AIRAS Cloud before speaking to sales?
Yes. A synthetic demonstration environment covering the full control plane is available on request, and there is no public pricing or checkout. Register your interest and a named member of the team responds directly with access and a proposed next step.
How is evidence kept audit-ready?
Decisions are versioned, history is append-only, evidence is hashed against the record, and assessment and decision packs export with ruleset versions, control mappings, reviewer rationale and timestamps included.

Bring this workflow to your organisation

Register your interest and we will discuss how the steps map onto your existing governance forums, policies and control libraries.

No pricing commitment. No confidential information required.