AI Governance · IT Audit · Business Continuity
For organizations in Saudi Arabia, the UAE and the EU

Govern AI. Audit IT. Prove resilience.One workspace for all three.

Starkguard is a governance suite of three applications: AI Governance, IT Audit and Business Continuity. Each has its own workflow for the team that uses it. Together they share one workspace, one set of people and roles, and one audit trail.

  • Use one application or all three
  • One sign-in, members and roles
  • One audit trail across applications

The suite

Three applications, one workspace

Shared across applications: sign-in, members and roles, the audit log, and links to the AI systems in your inventory.

Application 1 of 3

AI Governance

Inventory, assess and evidence your AI systems.

Keep one register of the AI systems you build and buy, classify their risk, and assess them against the EU AI Act, NIST AI RMF, ISO/IEC 42001, OECD, KSA (SDAIA + PDPL) and UAE requirements. Incidents, human oversight decisions and policies are recorded alongside, so evidence is ready when someone asks for it.

  • AI system inventory with CSV and JSON bulk import
  • Guided assessments across seven frameworks, with gap analysis
  • Incident log, human oversight log and per-system evidence packages
  • Policy templates, action plans and board-facing reports

Inside AI Governance

Frameworks and content included

Assessment frameworks
7Assessment frameworks
Jurisdictions covered side by side: EU, KSA, UAE
3Jurisdictions covered side by side: EU, KSA, UAE
ISO/IEC 42001 Annex A controls covered
38ISO/IEC 42001 Annex A controls covered
Policy templates across 5 pillars
20Policy templates across 5 pillars
  • RAPID
  • NIST AI RMF
  • EU AI Act
  • OECD
  • ISO/IEC 42001
  • KSA AI Governance
  • UAE AI Ethics
Application 2 of 3
Early access

IT Audit

Plan, test and report IT audits in one place.

Maintain an audit universe, run engagements with a defined scope and team, and build a risk and control matrix for each one. Record design and operating-effectiveness tests, turn exceptions into findings, and track findings through agreement and remediation to closure.

  • Audit universe of auditable entities with owners and risk ratings
  • Engagements with scope, team and stages from planning to close; later stages are gated before they open
  • Risk and control matrix, with design and operating-effectiveness testing
  • Findings lifecycle and a printable engagement report

Inside IT Audit

An engagement moves through checked stages

  1. Planning

    Objective, scope from the audit universe, audit period, team and the risk & control matrix.

  2. Fieldwork

    Opens only when the objective, period and lead are set and every risk is mapped to a control. Design and operating-effectiveness tests are recorded here.

  3. Reporting

    Needs a concluded test for every key control. Exceptions become findings with a suggested severity.

  4. Closed

    No draft findings left. Scope, matrix and tests become read-only; remediation tracking stays open.

Application 3 of 3
Early access

Business Continuity

Know your critical services and show you can recover them.

Record the business services that matter, run a versioned business impact analysis to set RTO, RPO, MTPD and MBCO, and see where a dependency cannot recover fast enough. Write continuity plans against each service, exercise them, and track the actions that come out.

  • Business services with criticality tiers and owners
  • Versioned business impact analysis with RTO, RPO, MTPD and MBCO, and approval
  • Dependency mapping that flags recovery conflicts before approval
  • Versioned continuity plans and exercises with follow-up actions

Inside Business Continuity

Objectives set in the BIA, checked against dependencies

RTO
Recovery time objective
RPO
Recovery point objective
MTPD
Maximum tolerable period of disruption
MBCO
Minimum business continuity objective

Example of a flagged conflict

The service needs to be back within 4 hours, but a supporting application can only be restored in 8. The BIA cannot be approved until the conflict is resolved with an owner and a written decision.

Approved BIAs and plans are locked; changes start a new version.

One suite, shared core

Each application stands on its own. Together they share one core.

Use one application or all three. They run in the same workspace, so the people, the audit trail and the records they have in common are not duplicated across tools.

How the suite works today

  • One workspace, one team

    One sign-in, one organization and one set of members and roles across every application you use. Access is switched on per application.

  • One audit trail

    Changes in AI Governance, IT Audit and Business Continuity are written to the same organization audit log.

  • AI systems linked across applications

    Audit universe entities and business services can link to AI systems in your AI Governance inventory, so an auditor or continuity owner starts from the same record.

Where the shared core is going

  • On the roadmap

    One inventory

    Applications, services, third parties and AI systems kept once and used by every application: audit scope and BCM dependencies picked from the inventory instead of retyped.

  • On the roadmap

    One issues & actions list

    Audit findings, BCM exercise actions and AI remediation tracked in one lifecycle, so the organization has one remediation list.

  • On the roadmap

    One queue per person

    My Work: every assignment, review and approval from all three applications in one place for each person.

AI Governance plans

AI Governance plans

Plans for the AI Governance application, from Essential to Enterprise. IT Audit and Business Continuity are in early access; ask us about access and pricing for your organization.

Essential
Essential governance for small teams
Contact Us
RAPID + NIST Essential
Contact Us
  • 3 AI Systems
  • 3 Team Members
  • 8 Assessment Credits/year
  • 300 AI Credits/month
  • 4 Policy Templates
Most Popular
Professional
Comprehensive governance with AI insights
Contact Us
EU AI Act + Third-Party
Contact Us
  • 15 AI Systems
  • 15 Team Members
  • Third-Party Assessments (5)
  • 1,500 AI Credits/month
  • 12 Policy Templates
Enterprise
All frameworks with dedicated support
Custom
ISO 42001 + KSA + UAE
Contact Us
  • 75 AI Systems
  • 50 Team Members
  • All 20 Policy Templates
  • 8,000 AI Credits/month
  • All Frameworks
FAQ

Frequently Asked Questions

The core questions we hear from teams evaluating the platform, governance scope, and rollout model.

What applications does Starkguard include?

Three: AI Governance, IT Audit and Business Continuity. AI Governance covers AI system inventory, risk classification, framework assessments and evidence. IT Audit covers the audit universe, engagements, risk and control matrices, control testing, findings and a printable engagement report. Business Continuity covers business services, a versioned business impact analysis with RTO, RPO, MTPD and MBCO, dependency conflicts, continuity plans and exercises. IT Audit and Business Continuity are currently in early access: they work today and are enabled for organizations that request access.

Do I have to use all three applications?

No. Access is switched on per application, so you can start with the one your team needs. If you add another later, it runs in the same workspace with the same members and roles.

How do the applications work together?

Today they share one workspace, one set of members and roles, and one audit log, and IT Audit entities and Business Continuity services can link to AI systems in your AI Governance inventory. On the roadmap: one shared inventory used by every application, one issues and actions list across applications, and a single My Work queue for each person.

Which regulations and standards does Starkguard work with?

AI Governance includes assessments for the EU AI Act, NIST AI RMF, ISO/IEC 42001, the OECD AI Principles, KSA AI Governance (SDAIA and PDPL) and UAE AI Ethics (FDPL). IT Audit is structured the way internal audit teams work under the IIA Global Internal Audit Standards, and Business Continuity uses the concepts in ISO 22301, NCEMA 7000 and the SAMA Business Continuity Management Framework. These are reference points: using Starkguard does not by itself make an organization compliant or certified.

Why does AI governance matter now?

The EU AI Act is being applied in phases: prohibited practices, general-purpose AI and transparency rules are in effect, and high-risk obligations follow in December 2027 (Annex III) and August 2028 (Annex I). In the GCC, SDAIA's AI ethics principles and the UAE AI Ethics principles set similar expectations. Governance is how you manage those risks and show what you have done.

What's the difference between the AI Governance plans?

Essential covers 3 AI systems with NIST AI RMF essentials. Professional adds EU AI Act, OECD, AI insights, and third-party vendor assessments (5 vendors) for 15 systems. Enterprise includes ISO/IEC 42001, KSA AI Governance (SDAIA + PDPL), UAE AI Ethics (10 principles + FDPL), and 25 vendor assessments. Professional and above include incident logging, oversight tracking, compliance attestation, and evidence packages. SSO/SAML and API access are on the roadmap. Contact us for pricing details.

How do assessment credits work in AI Governance?

Assessment credits are pooled across all assessment types (RAPID, Governance, Risk). Essential includes 8 credits/year, Professional has unlimited RAPID assessments, and Enterprise has unlimited everything. Additional credits can be arranged based on your needs.

Next step

Governance, audit and continuity in one workspace.

Start with the application your team needs and add the others when you are ready. Tell us which one and we will set up your workspace.