AI governance with the evidence behind it
Register the AI systems you build and buy, classify their risk, and assess them against the EU AI Act, NIST AI RMF, ISO/IEC 42001, OECD, and KSA and UAE requirements. Incidents, oversight decisions and policies sit alongside, so evidence is ready when regulators or auditors ask.
Inside AI Governance
Frameworks and content included
- Assessment frameworks
- 7Assessment frameworks
- Jurisdictions covered side by side: EU, KSA, UAE
- 3Jurisdictions covered side by side: EU, KSA, UAE
- ISO/IEC 42001 Annex A controls covered
- 38ISO/IEC 42001 Annex A controls covered
- Policy templates across 5 pillars
- 20Policy templates across 5 pillars
- RAPID
- NIST AI RMF
- EU AI Act
- OECD
- ISO/IEC 42001
- KSA AI Governance
- UAE AI Ethics
What AI Governance does
Guided, self-service workflows from system intake to audit-ready evidence, for DPOs, legal, risk and engineering teams.
AI system inventory
- CSV and JSON bulk import (14 fields)
- Owners, deployment context and geographic scope
- Risk classification per system
RAPID risk assessment
- Seven weighted risk dimensions
- Automated tier classification aligned with NIST AI RMF
- Risk dashboards and trends
Framework assessments
- NIST AI RMF governance (all tiers)
- EU AI Act and OECD (Professional and above)
- ISO/IEC 42001, KSA AI Governance and UAE AI Ethics (Enterprise)
- Gap analysis and scoring per framework
Compliance tracking
- Scoring and gap analysis across frameworks
- EU AI Act risk classification
- Evidence management (Enterprise)
Policies and action plans
- 4 to 20 policy templates by tier, across five governance pillars
- Version control and approval workflow
- Generated action plans with prioritized steps
Dashboard and reports
- Executive summary views and risk indicators
- PDF and DOCX reports with framework detail
- Action item tracking
EU AI Act deployer toolkit
Incident management, oversight evidence, attestation and documentation for deployer obligations.Prohibited-practice, general-purpose AI and transparency rules already apply. Annex III high-risk obligations, including Article 26 deployer duties, apply from 2 December 2027.
- All tiers
Document vault
Per-system file storage with versioning and tagging for vendor documentation, DPIAs and other evidence.
- Pro & above
Incident logging (Art. 73)
Incident records with severity, root cause and EU AI Act Article 73 notification drafts for serious incidents.
- Pro & above
Human oversight log
A per-system log of reviews with agreed or overridden outcomes, as timestamped Article 14 evidence.
- Pro & above
Compliance attestation
An attestation PDF with a posture summary and signature block, for boards and regulators.
- Pro & above
Evidence package
One download per system: assessments, documents, oversight records and the audit trail behind them.
- All tiers
Audit log
Every action recorded with user, IP address and user agent. Filter, search and export.
Insights and vendors
AI-assisted analysis, action plans and third-party assessments.
- Pro & above
AI-assisted insights
Recommendations and gap analysis generated from your assessment results.
- All tiers
Action plans
Generated action plans with prioritized recommendations and progress tracking.
- Pro & above
Third-party assessments
Standard questionnaires and scoring for vendors' AI governance: 5 vendors (Pro), 25 (Enterprise).
Seven frameworks, by plan
The AI governance frameworks and regulations your programme is most likely to be measured against.
RAPID Assessment
Seven-dimension risk scoring with automated tier classification. A fast baseline for any AI system.Available: All tiersNIST AI RMF
GOVERN, MAP, MEASURE and MANAGE functions, 68 requirements.Available: All tiersEU AI Act
Annex III risk classification, deployer obligations, Article 73 incident reporting, Article 14 oversight.Available: Professional & EnterpriseOECD AI Principles
International AI governance principles, assessed across five principles.Available: Professional & EnterpriseISO/IEC 42001
AI management system assessment against 38 Annex A controls in 9 sections.Available: EnterpriseKSA AI Governance
SDAIA risk classification, the seven AI Ethics Principles, and PDPL with data localization tracking.Available: EnterpriseUAE AI Ethics
The ten UAE AI Ethics Principles, FDPL, and sector modules for DIFC, ADGM, healthcare and government.Available: Enterprise
Works on its own, better with the other applications
AI Governance runs in the same Starkguard workspace as IT Audit and Business Continuity. You can use it alone; when you use more than one application, they share the core below.
How the shared core worksToday
- Same workspace, members and roles as IT Audit and Business Continuity
- AI systems in your inventory can be linked from IT Audit's audit universe and from Business Continuity services
- Changes are written to the same organization audit log
NextOn the roadmap
- AI systems kept in one shared inventory with applications, services and third parties
- AI remediation actions in one issues & actions list with audit findings and BCM actions
- Assessments, reviews and actions in each person's My Work queue
Built with the standards your reviewers use
Assessments are built around the frameworks below, with EU AI Act, KSA and UAE requirements covered side by side for organizations that operate across the GCC and Europe.
- EU AI Act
- NIST AI RMF
- ISO/IEC 42001
- OECD AI Principles
- KSA AI Governance (SDAIA, PDPL)
- UAE AI Ethics (FDPL)
These standards are reference points for how the application is structured. Using Starkguard does not by itself make an organization compliant or certified; that depends on your own programme and, where relevant, an independent assessment.
What comes next for AI Governance
Not available yet. Listed so you can see where the application is going; order and scope may change.
SSO/SAML
Single sign-on with your identity provider. Sign-in is email and password today.
API access
API keys for integrating the inventory and assessment results with other systems.
Inventory, assess and evidence your AI systems.
Talk to us about AI Governance for your organization in KSA, the UAE or the EU.