AI Governance application

AI governance with the evidence behind it

Register the AI systems you build and buy, classify their risk, and assess them against the EU AI Act, NIST AI RMF, ISO/IEC 42001, OECD, and KSA and UAE requirements. Incidents, oversight decisions and policies sit alongside, so evidence is ready when regulators or auditors ask.

Inside AI Governance

Frameworks and content included

Assessment frameworks
7Assessment frameworks
Jurisdictions covered side by side: EU, KSA, UAE
3Jurisdictions covered side by side: EU, KSA, UAE
ISO/IEC 42001 Annex A controls covered
38ISO/IEC 42001 Annex A controls covered
Policy templates across 5 pillars
20Policy templates across 5 pillars
  • RAPID
  • NIST AI RMF
  • EU AI Act
  • OECD
  • ISO/IEC 42001
  • KSA AI Governance
  • UAE AI Ethics
Available in the application today

What AI Governance does

Guided, self-service workflows from system intake to audit-ready evidence, for DPOs, legal, risk and engineering teams.

AI system inventory

One register of the AI systems you build and buy, populated by bulk import rather than retyping.
  • CSV and JSON bulk import (14 fields)
  • Owners, deployment context and geographic scope
  • Risk classification per system

RAPID risk assessment

A fast, self-service baseline for any AI system, scored across seven risk dimensions.
  • Seven weighted risk dimensions
  • Automated tier classification aligned with NIST AI RMF
  • Risk dashboards and trends

Framework assessments

Guided assessments that unlock as your programme matures.
  • NIST AI RMF governance (all tiers)
  • EU AI Act and OECD (Professional and above)
  • ISO/IEC 42001, KSA AI Governance and UAE AI Ethics (Enterprise)
  • Gap analysis and scoring per framework

Compliance tracking

Posture by framework and by system, with the gaps that remain.
  • Scoring and gap analysis across frameworks
  • EU AI Act risk classification
  • Evidence management (Enterprise)

Policies and action plans

Policy templates and remediation plans that track who does what.
  • 4 to 20 policy templates by tier, across five governance pillars
  • Version control and approval workflow
  • Generated action plans with prioritized steps

Dashboard and reports

Posture for boards and regulators, without technical detail they do not need.
  • Executive summary views and risk indicators
  • PDF and DOCX reports with framework detail
  • Action item tracking
Governance & evidence

EU AI Act deployer toolkit

Incident management, oversight evidence, attestation and documentation for deployer obligations.Prohibited-practice, general-purpose AI and transparency rules already apply. Annex III high-risk obligations, including Article 26 deployer duties, apply from 2 December 2027.

  • All tiers

    Document vault

    Per-system file storage with versioning and tagging for vendor documentation, DPIAs and other evidence.

  • Pro & above

    Incident logging (Art. 73)

    Incident records with severity, root cause and EU AI Act Article 73 notification drafts for serious incidents.

  • Pro & above

    Human oversight log

    A per-system log of reviews with agreed or overridden outcomes, as timestamped Article 14 evidence.

  • Pro & above

    Compliance attestation

    An attestation PDF with a posture summary and signature block, for boards and regulators.

  • Pro & above

    Evidence package

    One download per system: assessments, documents, oversight records and the audit trail behind them.

  • All tiers

    Audit log

    Every action recorded with user, IP address and user agent. Filter, search and export.

More capabilities

Insights and vendors

AI-assisted analysis, action plans and third-party assessments.

  • Pro & above

    AI-assisted insights

    Recommendations and gap analysis generated from your assessment results.

  • All tiers

    Action plans

    Generated action plans with prioritized recommendations and progress tracking.

  • Pro & above

    Third-party assessments

    Standard questionnaires and scoring for vendors' AI governance: 5 vendors (Pro), 25 (Enterprise).

Frameworks

Seven frameworks, by plan

The AI governance frameworks and regulations your programme is most likely to be measured against.

  • RAPID Assessment

    Seven-dimension risk scoring with automated tier classification. A fast baseline for any AI system.
    Available: All tiers
  • NIST AI RMF

    GOVERN, MAP, MEASURE and MANAGE functions, 68 requirements.
    Available: All tiers
  • EU AI Act

    Annex III risk classification, deployer obligations, Article 73 incident reporting, Article 14 oversight.
    Available: Professional & Enterprise
  • OECD AI Principles

    International AI governance principles, assessed across five principles.
    Available: Professional & Enterprise
  • ISO/IEC 42001

    AI management system assessment against 38 Annex A controls in 9 sections.
    Available: Enterprise
  • KSA AI Governance

    SDAIA risk classification, the seven AI Ethics Principles, and PDPL with data localization tracking.
    Available: Enterprise
  • UAE AI Ethics

    The ten UAE AI Ethics Principles, FDPL, and sector modules for DIFC, ADGM, healthcare and government.
    Available: Enterprise
Part of the suite

Works on its own, better with the other applications

AI Governance runs in the same Starkguard workspace as IT Audit and Business Continuity. You can use it alone; when you use more than one application, they share the core below.

How the shared core works

Today

  • Same workspace, members and roles as IT Audit and Business Continuity
  • AI systems in your inventory can be linked from IT Audit's audit universe and from Business Continuity services
  • Changes are written to the same organization audit log

Next
On the roadmap

  • AI systems kept in one shared inventory with applications, services and third parties
  • AI remediation actions in one issues & actions list with audit findings and BCM actions
  • Assessments, reviews and actions in each person's My Work queue
Standards context

Built with the standards your reviewers use

Assessments are built around the frameworks below, with EU AI Act, KSA and UAE requirements covered side by side for organizations that operate across the GCC and Europe.

  • EU AI Act
  • NIST AI RMF
  • ISO/IEC 42001
  • OECD AI Principles
  • KSA AI Governance (SDAIA, PDPL)
  • UAE AI Ethics (FDPL)

These standards are reference points for how the application is structured. Using Starkguard does not by itself make an organization compliant or certified; that depends on your own programme and, where relevant, an independent assessment.

On the roadmap

What comes next for AI Governance

Not available yet. Listed so you can see where the application is going; order and scope may change.

  • SSO/SAML

    Single sign-on with your identity provider. Sign-in is email and password today.

  • API access

    API keys for integrating the inventory and assessment results with other systems.

Inventory, assess and evidence your AI systems.

Talk to us about AI Governance for your organization in KSA, the UAE or the EU.