THE BUYER'S FIELD GUIDE

AI Risk & Governance Management Platforms

Governance-of-record systems for an AI program: use-case inventories, risk assessments, policy and approval workflows, accountability assignment, regulatory framework mapping, and audit evidence collection.

51 related offerings · 16 primary listings · 35 overlapping listings

Product research snapshot September 6, 2026 · Editorial guide September 7, 2026 · Published by DutyGraph

When to explore this layer

Consider program-level governance when teams need a common inventory of AI use cases, accountable reviewers, risk decisions and follow-up actions. Start with the decisions you must make and the evidence needed for them. A completed questionnaire should not be mistaken for a tested control.

ILLUSTRATIVE EVALUATION · NOT A CUSTOMER RESULT

Put a real task in the demonstration.

Register a fictional customer-support use case, record its data access and human escalation, then change the agent from drafting answers to sending them. Ask the platform to show what must be reassessed, who receives the review, and how the previous decision remains available for inspection.

Questions to bring to the demonstration

  1. Are assessments attached to a specific use case, owner and version?
  2. Can a scope change reopen the relevant review without erasing the earlier decision?
  3. Does the evidence distinguish a declared control from an observed test result?
  4. Can reviewers export the decision, exceptions, evidence and unresolved follow-up together?

Evidence to request

  • A versioned use-case assessment
  • An exception with a named owner and review date
  • A change-triggered reassessment and evidence export

Record what was demonstrated, what was only described, and what remains unknown. Preserve the product version, environment and date beside each observation.

Use the editable Markdown worksheet →

Where this layer stops

A governance platform can organize a program; it does not itself provide a legal conclusion or certify compliance. Applicable obligations and assurance needs depend on the organization and use case and require the appropriate specialists.

Connect it to the work

Granular task descriptions make a use-case assessment less abstract. An advisor can distinguish drafting, deciding and executing before asking risk reviewers to assess a broad label such as 'customer-service agent'.

Read our perspective on the demand side of agents →

51 offerings to investigate

Alphabetical, not ranked. Membership includes primary and secondary research categories. These products have different scopes; inspect the evidence profile before comparing capabilities.

Primary category

AI Incident Database (AIID)

Open, community-contributed catalogue of real-world AI harms and near-harms maintained by the Responsible AI Collaborative, searchable on the web and queryable through a public read-only GraphQL endpoint, with taxonomies for classification. Records are curated press-based reports, so coverage is uneven and not an authoritative incident register.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Show me querying the GraphQL endpoint for incidents involving autonomous agents or LLM assistants and how you would use them in our AI risk taxonomy.

Read sources and limitations →

Also covers this layer

Amazon SageMaker Model Registry

AWS service for cataloguing production models as versioned model packages in model groups, with metadata, lineage, a staging construct, approval status and CI/CD deployment. Integrated SageMaker Model Cards add intended use, risk rating and evaluation records, versioned immutably on edit.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a model package moving through staging with approval status changes, and show the linked model card version history for the same model.

Read sources and limitations →

Primary category

Asenion

AI governance, risk and security platform formed when Canada's Fairly AI acquired Sweden's anch.AI in June 2025 and rebranded as Asenion. It markets automated controls that continuously assess and test AI systems and agents against frameworks including the EU AI Act, ISO/IEC 42001 and NIST AI RMF.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate one automated control test running against a production agent, and show the tamper-resistant assurance record it produces.

Read sources and limitations →

Also covers this layer

BABL AI audits and AI & Algorithm Auditor Certification

Boutique firm offering independent third-party AI audits and responsible AI consulting, plus a five-course AI and Algorithm Auditor Certification for practitioners ending in a capstone and exit exam. The firm states its audits follow assurance-engagement style practice but names no accrediting body for either the audits or the credential.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how a BABL independent third-party audit engagement is scoped and what assurance wording appears in the final report you issue to a client's stakeholders.

Read sources and limitations →

Also covers this layer

BigID AI Security & Governance

BigID's AI-oriented module inside its data security platform. It inventories AI models, agents, copilots, prompts, vector stores and pipelines, classifies the data feeding training, retrieval and inference, and maps lineage of that data. Claims come from vendor product pages; BigID's technical documentation is not publicly reachable.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how BigID builds an AI asset inventory that links a vector database to the sensitive datasets embedded in it and the identities allowed to query it.

Read sources and limitations →

Also covers this layer

BSI ISO/IEC 42001 certification

Third-party certification of an organisation's AI management system against ISO/IEC 42001, offered by BSI alongside pre-certification gap assessment and training. BSI states it holds UKAS, RvA and ANAB accreditation for this scheme. Certification covers management-system conformity, not the performance or safety of individual AI models.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the audit stages, sampling approach and evidence you require to certify an AI management system covering generative AI agents in production.

Read sources and limitations →

Also covers this layer

Checkmarx AI Inventory and AI-BOM

Capability inside Checkmarx One that inventories AI components by scanning source code and configuration files in connected repositories, cataloguing models, agents, MCP servers, AI libraries and SDKs on every commit, then emitting an AI-BOM and enforcing policy in pull requests and CI/CD. Scope is the software pipeline, not employee tool usage.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an AI-BOM generated from one of our repositories listing every detected model, agent and MCP server with the file and commit where it was found.

Read sources and limitations →

Primary category

Collibra AI Command Center

Collibra's AI governance product, evolved from Collibra AI Governance, registering AI use cases, models, model versions and agents as governed assets with lifecycle stages, compliance assessment templates and a per-system trust score. Fits organisations already using Collibra for data governance.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an AI use case linked to its model versions, agents and datasets, plus how the trust score changes when documentation or lifecycle status degrades.

Read sources and limitations →

Primary category

Credo AI Platform

Governance workspace where an enterprise records AI use cases, models, agents and third-party AI vendors, runs questionnaire-driven reviews, and tracks control and risk libraries with task assignment. A Python/TypeScript SDK writes the same objects programmatically. Evidence reviewed covers workflow structure, not independent verification of governance outcomes.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how a new agent use case moves from intake questionnaire through control review to a governance status a regulator-facing auditor could read.

Read sources and limitations →

Also covers this layer

CSA STAR for AI

Cloud Security Alliance assurance program extending its STAR registry to AI services, with a Level 1 self-assessment against the AI Controls Matrix questionnaire, an automated validation option, and a Level 2 tier referencing third-party certification. Registry-based transparency for AI providers rather than a regulatory conformity assessment.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a completed AI-CAIQ submission for an agent platform and what the Valid-AI-ted scoring adds over a plain Level 1 self-assessment.

Read sources and limitations →

Also covers this layer

Cycode AI & ML Inventory and AIBOM

Application-security capability that discovers AI assets across the software development lifecycle - AI infrastructure, models, coding assistants, packages and associated secrets - by scanning connected repositories and pipeline systems, then producing an AI bill of materials for governance. Buyer is AppSec; it does not observe business users' AI tool usage.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate discovering which AI coding assistants and third-party models our developers introduced last quarter, and show the AIBOM entry with the repository and secret associations.

Read sources and limitations →

Also covers this layer

Cyera AI Guardian

Cyera's AI-focused extension of its data security posture platform. Its AI-SPM capability inventories AI models, applications, agents and knowledge bases including shadow AI, and links them to sensitive-data classifications produced by the underlying DSPM engine. Runtime protection is described at product level without public technical documentation.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me the live inventory of AI agents and knowledge bases Cyera discovered in my cloud accounts and which sensitive data classifications each one touches.

Read sources and limitations →

Also covers this layer

Deeploy

Dutch platform that puts governance in the deployment path: models are registered from Git, MLflow, Databricks, Hugging Face or Azure registries, standardised assessments set a use-case risk score that selects applicable controls, role-based approvals gate deployment, and a gateway handles monitoring, guardrails and logging.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a deployment blocked until the required roles approve, with the risk score, selected control framework and gateway monitoring for the approved version.

Read sources and limitations →

Also covers this layer

Deloitte Trustworthy AI

Deloitte US consulting practice organised around a Trustworthy AI framework, sold as named workstreams covering AI strategy, risk management and governance, regulatory support, model risk management, and AI audit and assurance. The public pages describe offerings and control activities but publish no methodology, deliverable list, or fee information.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the audit-ready evidence package your AI Risk Management and Governance engagement produces for a single high-impact agentic use case, from use-case tiering through monitoring KPIs.

Read sources and limitations →

Also covers this layer

Dioptra

US NIST-built test platform for assessing trustworthy characteristics of AI models, providing a REST API, web interface and Python client to design, run and track reproducible experiments including adversarial red-team scenarios. Intended to support the Measure function of the AI Risk Management Framework rather than to certify systems.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate reproducing an adversarial robustness experiment in Dioptra and exporting the tracked evidence for an internal AI risk review.

Read sources and limitations →

Also covers this layer

DNV ISO/IEC 42001 certification and AI assurance

DNV offers third-party certification of AI management systems to ISO/IEC 42001 plus an AI vendor capability assessment delivered as an independent third-party audit of an organisation's ability to develop and operate trustworthy AI and data-driven solutions. Neither page names an accreditation body for the AI scheme.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the topic-by-topic findings structure of an AI vendor capability assessment and how it differs from an ISO/IEC 42001 certification audit.

Read sources and limitations →

Also covers this layer

Domino AI Governance

Governance layer of the Domino enterprise data science platform: an MLflow-based model registry with project- and deployment-scoped views, custom model cards, version management, RBAC over registered models and stage transitions, plus documented review steps for validation, ethical review, audit trails and stakeholder sign-off.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me role-based control over stage transitions in the Domino model registry and the self-documenting evidence produced for a model review.

Read sources and limitations →

Also covers this layer

DutyGraph

Directory publisher · Advisor pilot

Advisor-led workspace that maps a team's people, duties, tasks and software into a work record, then proposes agent delegation boundaries with a named accountable owner and review checkpoint. Intended for advisors and business sponsors. Currently an advisor pilot recruiting 5-10 companies; governance views are shown as a fictional sample.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show a participant-reviewed task card reaching the advisor queue, and demonstrate how an unresolved approval owner stays visible in the company graph.

Read sources and limitations →

Primary category

Enzai

UK-founded AI governance platform providing a system of record for AI systems, models, datasets and governance decisions, customisable intake by system type and risk level, assessment tracking against EU AI Act, ISO 42001 and NIST AI RMF, and dashboards summarising assessment results.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a configurable intake for a high-risk system and how completed assessments roll up into the governance dashboard and shareable reports.

Read sources and limitations →

Also covers this layer

EY Responsible AI services

EY advisory offering combining a Responsible AI framework, a GenAI governance framework, and a Responsible AI Readiness Assessment that scores an organisation's readiness to manage AI risk and coming regulation across six categories, plus stakeholder training. Public pages give category names but not the underlying scoring model.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate the Responsible AI Readiness Assessment on one business unit and show the six-category scoring and the gap remediation plan it produces.

Read sources and limitations →

Also covers this layer

Giskard Hub

French vendor pairing an open-source Python testing library with a delivered assessment service. Automated and expert-led testing probes conversational agents for prompt injection, data disclosure, sycophancy, hallucination and inappropriate refusals, returning a severity-ranked vulnerability report and a signed go/no-go deployment recommendation.

hybrid · Research snapshot 2026-09-06

Ask for a demonstration
Show me a full assessment report for my customer-facing agent, with vulnerabilities ranked by severity and the go/no-go deployment recommendation.

Read sources and limitations →

Primary category

GRACE Governance

Governance module of the Danish GRACE AI Platform: register AI projects and systems, define policies and controls, run AI assessments, report on control status and review compliance with audit trails and named role ownership. Sold as part of a wider platform, so standalone scope needs confirmation.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how GRACE Governance is used without the rest of the GRACE platform, and what the control attestation and audit trail output looks like.

Read sources and limitations →

Also covers this layer

Holistic AI AI Audits

Independent AI audit engagements from Holistic AI covering bias, privacy, efficacy, robustness and explainability, plus regulation-specific assessments and a separate independent audit service for Digital Services Act due-diligence obligations. Audits produce reports and mitigation strategies; no accreditation or certification mark is claimed on the pages reviewed.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me an anonymised AI audit report structure and the specific tests you ran for bias and robustness on a deployed decisioning model.

Read sources and limitations →

Primary category

Holistic AI Governance Platform

Enterprise platform that inventories AI systems, models, agents and pipelines, then rates each system across risk verticals such as bias, robustness, privacy and transparency on a traffic-light dashboard. Marketed for internal builds and procured AI. Risk ratings are vendor-defined scores, not audits or certifications.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how a procured third-party model gets an inherent-risk rating and what evidence sits behind the red-amber-green score.

Read sources and limitations →

Primary category

IBM watsonx.governance

IBM's AI governance offering combining a tracked model and prompt-template inventory (AI Factsheets) with monitors for fairness, drift, model health and generative-AI output risks. Suited to enterprises already on watsonx; evidence reviewed covers monitoring and inventory mechanics, not regulatory outcomes.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how a deployed model's factsheet, fairness and drift monitors, and alert thresholds appear in the shared model inventory for a risk reviewer.

Read sources and limitations →

Also covers this layer

Infosys Topaz Responsible AI Suite

Infosys implementation and advisory suite of more than ten offerings arranged as Scan, Shield and Steer, including regulatory watchtower monitoring, maturity and risk assessments, a responsible AI audit offering, and a control centre for compliance telemetry. Delivered as consulting plus proprietary assets; component depth is not documented publicly.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate the Responsible AI Control Center on a live AI portfolio: which compliance signals it ingests and what a violation alert looks like end to end.

Read sources and limitations →

Also covers this layer

JDLA C認証 (AI Governance Core Certification)

Japanese third-party certification scheme run by the Japan Deep Learning Association that reviews an organisation's AI governance structures and operations at legal-entity level, valid two years, with JDLA-accredited consulting firms supporting readiness separately from the review. It certifies governance arrangements, not individual AI tools or systems.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me the C認証 review criteria and the evidence a Japanese subsidiary must submit to demonstrate AI inventory and risk assessment practices.

Read sources and limitations →

Also covers this layer

KPMG AI Trust services

KPMG's multi-disciplinary AI governance service suite built on its Trusted AI framework, spanning AI risk assessment, AI systems inventory, governance and policy implementation, AI security and privacy, system cards, and an AI Assurance line offering model validation and independent attestation against defined frameworks such as SOC and HITRUST.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me an AI assurance and attestation engagement scope for an agentic workflow, including which framework you attest against and what the resulting report covers.

Read sources and limitations →

Primary category

Lumenova AI Platform

AI governance platform aimed at regulated industries that replaces manual risk reviews with workflow-driven assessments, evaluates models across a large metric set, and adds monitoring plus guardrails. Public evidence is largely vendor-authored, including a 2024 UK government assurance-technique listing.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me which of the 200+ model metrics are computed automatically for a deployed model and how results feed the risk assessment workflow.

Read sources and limitations →

Also covers this layer

ModelOp Center

Model and AI lifecycle governance software that maintains a searchable inventory of ML models, generative AI, agents, vendor tools and embedded SaaS AI, routes intake through policy-driven workflows, and maps controls to regulations including SR 11-7, the EU AI Act, NIST AI RMF and ISO 42001.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a policy-driven workflow blocking a non-compliant model promotion, with the control mapping and captured sign-off evidence.

Read sources and limitations →

Primary category

Modulos AI Governance Platform

Governance platform organised around projects representing one AI system each, with frameworks, requirements, controls, evidence and reviews, plus a risk module that quantifies AI risk in monetary terms and a runtime inspection module for scheduled tests. Multi-framework mapping is vendor-maintained content, not a compliance guarantee.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how one control satisfies EU AI Act and ISO 42001 requirements simultaneously and how the linked evidence and review trail is exported.

Read sources and limitations →

Primary category

Naaia

French platform marketed as an AI management system aligned to ISO/IEC 42001 that qualifies an organisation's operator status and system risk level under the EU AI Act, then generates an operational action plan with a centralised registry of projects, systems, models and components.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how operator status and EU AI Act risk level are qualified for one system and what the generated action plan and documentation pack contain.

Read sources and limitations →

Also covers this layer

Nudge Security AI Agent Discovery

Research-preview capability of Nudge Security that inventories AI agents employees create on platforms such as Copilot Studio, Agentforce, Gemini, OpenAI, n8n, ServiceNow, Databricks, Workato and Tines, surfacing creator, permissions, connected data and MCP connections. Nudge's discovery approach centres on corporate email signals and OAuth grants.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate discovering an n8n or Copilot Studio agent an employee built last week, showing the creator, its OAuth grants, and any unauthenticated MCP connection.

Read sources and limitations →

Primary category

OneTrust AI Governance

AI-specific module of OneTrust's privacy and governance suite: central inventory of AI systems, models, datasets, agents and vendors with use-case intake and approval workflows, risk tiering, impact assessments and policy-driven controls intended to produce audit-ready records for security and governance teams.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me the AI use-case intake and approval workflow end to end, and which evidence OneTrust captures automatically versus manually.

Read sources and limitations →

Also covers this layer

ORCAA Algorithmic Audit

ORCAA sells algorithmic audits that assess risks of a specific algorithmic use case using its Ethical Matrix framework, plus quantitative bias testing for regulatory compliance such as New York City Local Law 144 bias audits, AI governance consultation, and metric 'cockpit' design. Deliverables are reports, not certifications.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me how the Ethical Matrix is populated for one hiring algorithm and what a Local Law 144 bias audit report you issued contains.

Read sources and limitations →

Also covers this layer

Planview Agent Resource Management

Extension of Planview's portfolio resource model that treats AI agents as resources alongside people, so leaders can plan and allocate blended human and agent capacity across strategic work, track associated cost, and tie each agent action back to an accountable human decision-maker. It is planning and accountability tooling, not an agent runtime.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me a portfolio view where agent and human capacity are planned together, with the cost of agent work and the named human accountable for each agent's assignments.

Read sources and limitations →

Also covers this layer

Project Moonshot

Apache-2.0 LLM evaluation toolkit from Singapore's AI Verify Foundation that combines benchmark testing across safety and performance metrics with manual and automated red-teaming, offers guided workflows for IMDA's starter kit for LLM app testing, and produces shareable scoring reports usable in CI pipelines.

open_source · Research snapshot 2026-09-06

Ask for a demonstration
Show me running IMDA's starter-kit benchmarks plus an automated red-team attack module against our chatbot and the scoring report it produces.

Read sources and limitations →

Also covers this layer

PwC Responsible AI Toolkit

PwC advisory offering delivered as customisable frameworks, tools and processes for enterprise AI governance: role and responsibility design across three lines of defence, regulatory monitoring, policy development, bias and fairness assessment, and a free entry-level Responsible AI Diagnostic. Pages do not disclose tooling detail or pricing.

service · Research snapshot 2026-09-06

Ask for a demonstration
Show me how the Responsible AI Diagnostic output maps to a concrete governance remediation roadmap with three-lines-of-defence ownership.

Read sources and limitations →

Also covers this layer

Resaro Approved Intelligence

Independent AI assurance firm running testing, evaluation, validation and verification workflows in the client's own environment via its Approved Intelligence Platform, producing structured deployment evidence and continuous post-deployment evaluation for civil and defence uses. Marketed as evidence for deployment decisions rather than as certification against a standard.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate a TEVV run in our environment for one mission-critical model and show the evidence pack a deployment authority receives.

Read sources and limitations →

Primary category

Saidot

Finnish AI governance platform that links registered systems, models, agents and datasets to an expert-curated graph of risks, controls and policy requirements, so recommendations and risk inheritance propagate to connected assets. Curated content speeds setup but reflects the vendor's interpretation of obligations.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate risk inheritance: register a system on a new foundation model and show which risks, controls and policy requirements are auto-recommended and why.

Read sources and limitations →

Also covers this layer

SailPoint Agent Identity Security

Part of SailPoint Identity Security Cloud, this module aggregates AI agents from AWS, Azure, GCP, Salesforce and Copilot Studio, onboards each as a registered identity with business and access context, and surfaces shadow AI usage. It complements SailPoint's separate machine identity module for service accounts, bots and RPAs.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me every AI agent aggregated from Copilot Studio and Salesforce, each registered with an owner and access context, plus the shadow AI usage report.

Read sources and limitations →

Primary category

ServiceNow AI Control Tower

ServiceNow application that inventories AI agents, models and MCP servers as configuration items tied to the CMDB, with persona-based views for AI stewards, owners and risk/compliance users, and lifecycle plus risk and compliance oversight for platform customers already using ServiceNow.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how a discovered third-party AI agent becomes a CMDB configuration item with owner, lineage and a risk assessment task for the AI steward.

Read sources and limitations →

Also covers this layer

SPLX AI Asset Management

AI-BOM and inventory module of the SPLX platform, now part of Zscaler. It connects to cloud platforms, code repositories and ML/AI platforms to detect LLMs in use, scan repositories to map agents, tools and MCP servers in AI workflows, and run risk assessments on discovered agents. Detection is scan-based, not user-traffic based.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me the agentic workflow map produced from scanning one of our repositories, including each agent, its tools, and the MCP servers it connects to.

Read sources and limitations →

Primary category

trail

German AI governance tool centred on a live AI registry of use cases, systems, agents, models and third-party vendors, with guided EU AI Act risk and role classification, curated framework templates, control implementation tracking and reusable assessments and evidence across linked assets.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me how EU AI Act role and risk classification is derived for one system and how a completed assessment is reused on a dependent asset.

Read sources and limitations →

Primary category

Trustible AI Governance Platform

Purpose-built system of record for AI intake: teams capture use cases, models, agents and vendors, get risk-based triage, run risk and impact assessments, track mitigations and incidents, and map to regulatory frameworks with curated risk taxonomies. Framework mappings are vendor-curated interpretations, not regulator-endorsed.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me the intake-to-approval path for a high-risk use case, including which curated framework mappings and audit evidence it produces.

Read sources and limitations →

Also covers this layer

TÜV SÜD ISO/IEC 42001 certification

TÜV SÜD audits and certifies AI management systems against ISO/IEC 42001, including risk-focused assessments of bias, privacy and security controls and optional integrated audits combining several management-system standards. The pages reviewed name no accreditation body for the AI scheme, so accreditation status could not be confirmed.

service · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate how an integrated ISO/IEC 42001 and ISO/IEC 27001 audit is planned for one AI platform, and what nonconformities you have typically raised on AI risk assessment.

Read sources and limitations →

Also covers this layer

ValidMind

Model risk management and AI governance platform pairing a Python library that runs tests and generates model documentation with a review platform for validators, covering statistical, ML, LLM and agentic records with inventory, versioning and approval workflows aimed at regulated financial institutions.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate the developer-to-validator handoff: library-generated documentation and test results entering a validation workflow with approvals and version control.

Read sources and limitations →

Also covers this layer

Velatir

European platform that inserts human approval into AI agent workflows: agents submit an operation via API, SDK or an MCP server integration, policies assess it, and low-risk requests auto-approve while higher-risk ones route to named human reviewers who approve, reject or request changes, with an audit trail. Reviewer coverage depends on integration work.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an agent tool call blocked at the MCP approval gate, the policy that routed it to a human, and the audit record of the reviewer's decision and reason.

Read sources and limitations →

Also covers this layer

Veza AI Agent Security

Veza's access graph labels non-human accounts across its integrations, shows their effective permissions, supports right-sizing and periodic review, and its agent-focused release maps unmanaged AI agents and service accounts to human owners and enumerates the tools an agent may invoke. Agent capabilities were described as early access.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me every tool and action an AI agent is authorized to invoke in a connected app, with the suggested human owner and a review campaign to revoke unused entitlements.

Read sources and limitations →

Also covers this layer

Workday Agent System of Record

Workday functional area for cataloguing and administering an organisation's AI agents - Workday's own and third-party - with dedicated security domains for agent management, agent compliance and agent reporting. It is a registry and administration layer configured per tenant; evidence reviewed does not show detection of agents outside what is registered.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Demonstrate registering a third-party agent in ASOR and show the agent reporting and agent compliance views an auditor would rely on.

Read sources and limitations →

Also covers this layer

Yields Model Risk Management

Belgian model risk management software providing a configurable inventory of models, AI systems, agents, use cases, vendors and data sources with risk tiers, a workflow engine for validation and change control, automated validation reporting and monitoring, targeted at financial institutions with formal MRM functions.

commercial · Research snapshot 2026-09-06

Ask for a demonstration
Show me an automated validation report generated from the inventory record, including versioning history and the audit trail for a model change.

Read sources and limitations →

About this guide

The evaluation questions and fictional scenario are DutyGraph's editorial guidance. Product listings use the supplied source-linked research snapshot. We have not independently tested these offerings. Listing is not an endorsement, certification or working integration.

Read the directory methodology · Suggest a correction