Platform
One governed record for every AI use case.
AIRAS Cloud brings inventory, intake, risk, controls, evidence, review, decision, monitoring and audit into a single operational layer designed for regulated organisations.
AI use-case register
One authoritative inventory covering AI systems, models, agents, analytics and embedded vendor features, each with an accountable owner, lifecycle stage, linked systems and vendors.
AI governance portfolio
Northfield Group · All departments · Ruleset v2.4
Total AI use cases
64
Registered across 9 departments
Awaiting review
8
3 approaching due date
High risk
6
All with active conditions
Evidence completeness
91%
Across approved records
Risk distribution
- Low21
- Medium29
- High14
Reviews due this month
12
Periodic review, condition expiry and vendor change checks.
Governance queue
- Customer Service CopilotMediumPrivacy reviewAwaiting evidence
- Predictive Maintenance ModelHighQuality and SecurityIn review
- Supplier Document AssistantLowGovernance leadApproved with conditions
- Clinical Operations SummariserHighQuality, Privacy, LegalRestricted
Lifecycle
- Registered
- Assessed
- Reviewed
- Decision
- Monitoring
Illustrative interface – synthetic data
Guided intake
Adaptive question sets written in plain business language. Sections respond to earlier answers, highlight missing information and version every draft before submission.
Data and integrations
Step 3 of 5Which data categories are used as input?
Does the system write back into an operational system?
Write-back to an operational system triggers a mandatory security review and a human-oversight question set later in this intake.
Connected systems
- CRM PlatformSource and write-back
- Document RepositorySource
- Vendor LLM ServiceProcessing
Illustrative interface – synthetic data
Deterministic risk engine
Versioned rules score each dimension, apply mandatory floors, check prohibited-use patterns and record a readable explanation trace against the assessment.
Risk dimensions
Ruleset v2.4 · approved- Impact on people4 / 5
- Data sensitivity4 / 5
- Autonomy of action3 / 5
- Regulatory exposure5 / 5
- Operational criticality3 / 5
- Vendor dependency2 / 5
Calculated outcome
Base calculation returned Medium. A regulatory floor for GxP-impacting use raised the band to High.
Explanation trace
- Special category data declared in intake → sensitivity floor applied
- GxP-impacting process confirmed → Quality review mandatory
- Operational write-back enabled → Security review mandatory
- No prohibited-use pattern matched
Routed to Quality, Cybersecurity and Privacy. Segregation of duties enforced: the submitting owner cannot approve this record.
Rules are versioned and human-approved. AI does not approve AI.
Illustrative interface – synthetic data
Controls and evidence
Applicable controls are derived from the assessed context, with named evidence owners, due dates, versioned and hashed attachments, and visible completeness.
Applicable controls
Derived from assessed context · Policy pack: Regulated Manufacturing v1.8
- CTL-014Documented human oversight procedureEvidence attachedOwner: QualitySOP-QA-118 v3 · hash a19f…7c2
- CTL-027Output accuracy validation recordIn progressOwner: ValidationDue 14 days
- CTL-031Vendor security assessmentEvidence attachedOwner: CybersecurityVSA-2291 · hash 4b0d…91e
- CTL-044Data protection impact assessmentAwaiting ownerOwner: Privacy / DPORequested 3 days ago
Evidence integrity
Every attachment is versioned and hashed, linked to the control it satisfies and retained in the append-only audit history of the record.
Illustrative interface – synthetic data
Review, decision and audit
Role-based routing with segregation of duties, versioned decisions and conditions, append-only audit history and exportable assessment and decision packs.
Reviewer decisions
- Quality12 Mar
H. Okonkwo · Approved with conditions
- Cybersecurity12 Mar
L. Fereday · Approved
- Privacy / DPO13 Mar
A. Marchetti · Approved with conditions
- Executive sponsor14 Mar
S. Nairn · Final approval
Conditions: quarterly output sampling, documented human review of all customer- facing outputs, and reassessment on model or vendor change.
Audit history
14 Mar 09:41 — Decision recorded: Approved with conditions (v3)
13 Mar 16:02 — Condition added: quarterly output sampling
13 Mar 11:20 — Evidence attached: DPIA-0431 v2
12 Mar 08:55 — Risk recalculated under ruleset v2.4
Append-only. Entries cannot be edited or deleted.
Export
Illustrative interface – synthetic data
Foundations
Enterprise expectations, built into the product model.
Configuration, not rebuild
Question sets, risk dimensions, policy packs, control libraries and workflow rules evolve through governed configuration with version control.
Interoperability
REST APIs, signed webhooks and selective connectors allow AIRAS Cloud to coexist with GRC, ITSM, CMDB, document, identity, model registry and security tooling.
Tenant-scoped by design
Enterprise identity, role-based access and tenant-scoped data controls sit beneath every record, evidence file and export.
Differentiators
What makes this different from a generic GRC module.
AIRAS Cloud is purpose-built for AI governance in environments where evidence, traceability and accountability are non-negotiable.
Regulated-industry first
GxP, data integrity, privacy, security, supplier and human-oversight triggers are treated as first-class product concerns.
Deterministic risk engine
Approved versioned rules calculate scores, floors, prohibitions and review routes. AI does not approve AI.
Evidence-grade workflow
Requirements, files, hashes, versions, reviewer decisions and audit history remain linked to the record.
Configurable without rebuilding
Questions, risk dimensions, policy packs, control libraries and workflow rules can evolve through governed configuration.
Business value linked to risk
Every governed use case can retain its objective, baseline, target, guardrails and realised value.
Clean interoperability
REST APIs, webhooks and selective connectors allow AIRAS Cloud to coexist with GRC, ITSM, CMDB, model registry and security tooling.
- EU AI Act
- NIST AI RMF
- ISO/IEC 42001
- GDPR / DPIA
- EU GMP Annex 11
- SOC 2 / ISO 27001
- OWASP GenAI guidance
Framework references describe design alignment and evidence support. They do not represent certification, legal advice or a guarantee of compliance.
See how AIRAS Cloud would fit your governance model
Register your interest and tell us about your current AI register, review process and evidence obligations.
No pricing commitment. No confidential information required.