Skip to content
AIRAS Cloud

Platform

One governed record for every AI use case.

AIRAS Cloud brings inventory, intake, risk, controls, evidence, review, decision, monitoring and audit into a single operational layer designed for regulated organisations.

01

AI use-case register

One authoritative inventory covering AI systems, models, agents, analytics and embedded vendor features, each with an accountable owner, lifecycle stage, linked systems and vendors.

airascloud.app / governance / portfolio

AI governance portfolio

Northfield Group · All departments · Ruleset v2.4

Filters

Total AI use cases

64

Registered across 9 departments

Awaiting review

8

3 approaching due date

High risk

6

All with active conditions

Evidence completeness

91%

Across approved records

Risk distribution

  • Low21
  • Medium29
  • High14

Reviews due this month

12

Periodic review, condition expiry and vendor change checks.

Governance queue

  • Customer Service CopilotMedium
    Privacy reviewAwaiting evidence
  • Predictive Maintenance ModelHigh
    Quality and SecurityIn review
  • Supplier Document AssistantLow
    Governance leadApproved with conditions
  • Clinical Operations SummariserHigh
    Quality, Privacy, LegalRestricted

Lifecycle

  1. Registered
  2. Assessed
  3. Reviewed
  4. Decision
  5. Monitoring

Illustrative interface – synthetic data

02

Guided intake

Adaptive question sets written in plain business language. Sections respond to earlier answers, highlight missing information and version every draft before submission.

airascloud.app / use-case / UC-0147 / intake

Data and integrations

Step 3 of 5

Which data categories are used as input?

Operational dataCustomer personal dataSpecial category dataSupplier records

Does the system write back into an operational system?

YesNoNot yet known

Write-back to an operational system triggers a mandatory security review and a human-oversight question set later in this intake.

Connected systems

  • CRM PlatformSource and write-back
  • Document RepositorySource
  • Vendor LLM ServiceProcessing
Continue Save draftDraft v4 · autosaved

Illustrative interface – synthetic data

03

Deterministic risk engine

Versioned rules score each dimension, apply mandatory floors, check prohibited-use patterns and record a readable explanation trace against the assessment.

airascloud.app / use-case / UC-0147 / risk assessment

Risk dimensions

Ruleset v2.4 · approved
  • Impact on people4 / 5
  • Data sensitivity4 / 5
  • Autonomy of action3 / 5
  • Regulatory exposure5 / 5
  • Operational criticality3 / 5
  • Vendor dependency2 / 5

Calculated outcome

HighRaised by mandatory floor

Base calculation returned Medium. A regulatory floor for GxP-impacting use raised the band to High.

Explanation trace

  1. Special category data declared in intake → sensitivity floor applied
  2. GxP-impacting process confirmed → Quality review mandatory
  3. Operational write-back enabled → Security review mandatory
  4. No prohibited-use pattern matched

Routed to Quality, Cybersecurity and Privacy. Segregation of duties enforced: the submitting owner cannot approve this record.

Rules are versioned and human-approved. AI does not approve AI.

Illustrative interface – synthetic data

04

Controls and evidence

Applicable controls are derived from the assessed context, with named evidence owners, due dates, versioned and hashed attachments, and visible completeness.

airascloud.app / use-case / UC-0147 / controls and evidence

Applicable controls

Derived from assessed context · Policy pack: Regulated Manufacturing v1.8

Completeness 78%
  • CTL-014Documented human oversight procedureEvidence attached
    Owner: QualitySOP-QA-118 v3 · hash a19f…7c2
  • CTL-027Output accuracy validation recordIn progress
    Owner: ValidationDue 14 days
  • CTL-031Vendor security assessmentEvidence attached
    Owner: CybersecurityVSA-2291 · hash 4b0d…91e
  • CTL-044Data protection impact assessmentAwaiting owner
    Owner: Privacy / DPORequested 3 days ago

Evidence integrity

Every attachment is versioned and hashed, linked to the control it satisfies and retained in the append-only audit history of the record.

Illustrative interface – synthetic data

05

Review, decision and audit

Role-based routing with segregation of duties, versioned decisions and conditions, append-only audit history and exportable assessment and decision packs.

airascloud.app / use-case / UC-0147 / decision record

Reviewer decisions

  • Quality12 Mar

    H. Okonkwo · Approved with conditions

  • Cybersecurity12 Mar

    L. Fereday · Approved

  • Privacy / DPO13 Mar

    A. Marchetti · Approved with conditions

  • Executive sponsor14 Mar

    S. Nairn · Final approval

Conditions: quarterly output sampling, documented human review of all customer- facing outputs, and reassessment on model or vendor change.

Audit history

  1. 14 Mar 09:41 — Decision recorded: Approved with conditions (v3)

  2. 13 Mar 16:02 — Condition added: quarterly output sampling

  3. 13 Mar 11:20 — Evidence attached: DPIA-0431 v2

  4. 12 Mar 08:55 — Risk recalculated under ruleset v2.4

Append-only. Entries cannot be edited or deleted.

Export

Assessment pack Decision pack Control evidence index

Illustrative interface – synthetic data

Foundations

Enterprise expectations, built into the product model.

Configuration, not rebuild

Question sets, risk dimensions, policy packs, control libraries and workflow rules evolve through governed configuration with version control.

Interoperability

REST APIs, signed webhooks and selective connectors allow AIRAS Cloud to coexist with GRC, ITSM, CMDB, document, identity, model registry and security tooling.

Tenant-scoped by design

Enterprise identity, role-based access and tenant-scoped data controls sit beneath every record, evidence file and export.

Differentiators

What makes this different from a generic GRC module.

AIRAS Cloud is purpose-built for AI governance in environments where evidence, traceability and accountability are non-negotiable.

Regulated-industry first

GxP, data integrity, privacy, security, supplier and human-oversight triggers are treated as first-class product concerns.

Deterministic risk engine

Approved versioned rules calculate scores, floors, prohibitions and review routes. AI does not approve AI.

Evidence-grade workflow

Requirements, files, hashes, versions, reviewer decisions and audit history remain linked to the record.

Configurable without rebuilding

Questions, risk dimensions, policy packs, control libraries and workflow rules can evolve through governed configuration.

Business value linked to risk

Every governed use case can retain its objective, baseline, target, guardrails and realised value.

Clean interoperability

REST APIs, webhooks and selective connectors allow AIRAS Cloud to coexist with GRC, ITSM, CMDB, model registry and security tooling.

  • EU AI Act
  • NIST AI RMF
  • ISO/IEC 42001
  • GDPR / DPIA
  • EU GMP Annex 11
  • SOC 2 / ISO 27001
  • OWASP GenAI guidance

Framework references describe design alignment and evidence support. They do not represent certification, legal advice or a guarantee of compliance.

See how AIRAS Cloud would fit your governance model

Register your interest and tell us about your current AI register, review process and evidence obligations.

No pricing commitment. No confidential information required.