Skip to content
New · AI governance: inventory your AI systems, check the controls, certify ISO 42001.See it
AI governance

Govern the AI you build and buy, with evidence

An inventory of every model, AI feature and vendor AI tool you operate, impact assessments against your Statement of Applicability, ISO 42001 and NIST AI RMF controls mapped to automated checks, and the certification audit run where the evidence lives.

Inventory

Every AI system, with a name on it

The models you train, the third-party models embedded in your product and the AI tools your teams buy, recorded with an accountable owner, the intended use, the data it touches and its status, as dated evidence with a full audit trail.

  • Built, embedded and bought AI systems in one inventory
  • An accountable owner, intended use and data classes for each
  • Vendor AI tools assessed in the vendor module, on the same record
Impact assessments

Assessed before it ships, reviewed before it drifts

AI system impact assessments recorded against your Statement of Applicability, with the reasons for every inclusion and exclusion, review dates, and the approvals that closed them.

  • Impact assessments linked to the systems and controls they cover
  • Inclusion and exclusion reasons recorded for the auditor
  • Review dates and approvals, so nothing goes stale unnoticed
Controls checked automatically

Checked where the evidence lives, not filed as documents

Every ISO 42001 clause and Annex A control, and the NIST AI Risk Management Framework, mapped to a control in the library. Where the evidence lives in your cloud, identity and code systems it is checked automatically; where it does not, a structured evidence request carries it, with the same audit trail.

  • Access to models, keys and training data, checked in your cloud and identity systems
  • Change management for AI components, checked in your code systems
  • Data governance for AI: classification, retention and location, checked where it is stored
  • Policy, process and oversight controls as structured evidence requests with owners and dates
Certification

ISO 42001, on the evidence you already have

The AI management system shares its structure and most of its clauses with ISO 27001, so in Viglyn the shared work is done once. Stage 1 and Stage 2 run inside the platform with scoped auditor access, and workpapers export with integrity hashes.

  • ISO 42001 and NIST AI RMF on one evidence base with ISO 27001 and SOC 2
  • Scoped auditor access at a depth you control
  • Workpapers that export with SHA-256 integrity hashes

See Viglyn on your stack

A 30-minute walkthrough on your stack. Walk away knowing exactly how fast you could be audit-ready. No commitment.