AI system register. The heart of your platform. For each AI system we record purpose, owner, supplier, datasets, model version, deployment location, business impact and risk category. Dynamic fields depend on the category: a high-risk system requires considerably more documentation than a minimal-risk chatbot. The register is searchable, exportable in audit formats and can be connected to your CMDB or MLflow instance.
Risk assessment flow. A structured wizard that guides a new AI project from idea to deployment. At each stage it asks the right questions, automatically classifies the system as unacceptable, high, limited or minimal risk, and includes a gate that prevents a system going live without completed documentation. For high-risk systems this includes a Fundamental Rights Impact Assessment (FRIA) under Article 27.
Documentation vault. Version-controlled storage for technical documentation (Article 11), data sheets, model cards, training data overviews, evaluation reports and declarations of conformity. Templates for the standard formats supervisors expect, with version history and a sign-off process for each document.
Human-in-the-loop module. Configurable review workflows for decisions made by high-risk systems. For each use case you determine which decisions may be automated, which require human sign-off and which should be escalated. Includes SLA tracking, queue management and a complete decision audit log for later reconstruction.
Monitoring layer. Drift detection on input features and output distributions, fairness metrics per protected group, accuracy tracking against benchmarks, and alerts for your data science team. We integrate with MLflow, SageMaker Model Monitor, Vertex AI Model Monitoring or a custom pipeline, depending on your stack.
Incident and post-market monitoring. Logging of serious incidents in line with the AI Act reporting obligation, root cause analysis, corrective actions and reporting flows to your national supervisory authority. For ongoing post-market monitoring per system, we build the automatable part; the legal part remains with your compliance team.
Vendor management. For third-party AI systems, such as a purchased recruitment tool with an AI component or a SaaS supplier using LLMs, we register the supplier, their declarations, their classification and the risks for your organisation. When a contract is renewed, the platform triggers a fresh assessment.