Founding Customer Rate: Audit Ready at $2,997/yr normally $5,997 — rate locked for life of your subscription — Use code Q3AUDIT2026 See plans →
AI Governance Program Management

AI governance your auditor can validate — and your board can defend.

A structured 26-control program framework for risk management teams and compliance officers. Generates the policies, evidence packages, and audit narratives independent reviewers require — with a five-level maturity model at every control.

EU AI Act — what applies and when
August 2, 2026
Article 50 transparency + fining power
AI disclosure obligations and the regulator's enforcement authority take effect — on schedule, not deferred.
December 2, 2027
Annex III high-risk obligations
Credit scoring, fraud detection, KYC, and hiring AI requirements deferred by the EU Digital Omnibus (May 2026). The work still has to happen — more runway, same destination.
Updated July 2026 to reflect the EU Digital Omnibus  ·  Article 50 — EC official source  ·  Omnibus analysis — Gibson Dunn
Your program, fully documented
  • Per-control governance policies
  • Standard operating procedures
  • Implementation checklists
  • Evidence collection packages
  • Completed audit narratives
  • Five-level CMMI-style maturity scores
  • 6-framework crosswalk (NIST AI RMF · ISO 42001 · EU AI Act · SOC 2 · NIST CSF · NIST 800-53)
  • Executive program assessment
  • Audit-ready ZIP package
NIST AI RMF 1.0  ·  ISO 42001:2023  ·  EU AI Act  ·  SOC 2  ·  NIST CSF  ·  NIST 800-53  ·  26 controls across Govern, Map, Measure, and Manage  ·  Designed for risk management teams and independent auditors  ·  AI compliance content stored in your browser — artifacts and control sessions never leave your device
What you get

Everything you need to demonstrate AI compliance

Stop building from blank documents. Start from production-ready, AI-personalized artifacts.

26-control artifact library

Every control generates six tailored artifacts: governance policy, SOP, implementation checklist, log template, evidence package, and audit narrative — each customized to your organization.

AI-guided compliance conversation

A structured AI-guided dialogue — not a static form — draws out the specifics of your environment, probes material gaps when they surface, and iteratively builds artifacts grounded in how your organization actually operates.

AI compliance training

Four structured courses covering the full framework. Assign to employees, track completion, and generate training records for your audit file.

Program maturity tracker

Track progress across all 26 controls with a five-level maturity model. Dashboard view shows where you stand and where to prioritize next.

Program intelligence New

One-click executive program assessment: overall maturity score, domain breakdown table, top 5 priority gaps, and a board-ready narrative summary across your entire program.

Audit package export New

Single-click download of all completed artifacts organized by control, with a program cover narrative identifying the organization, framework alignment, and artifact inventory — formatted for delivery to auditors, regulators, legal counsel, or other interested parties.

Red-flag gap probing New

When your answers reveal a material governance failure — no policy, shadow AI use, no incident process — the AI probes the depth of the gap before moving on, surfacing the real risk exposure rather than accepting a surface answer.

6-framework crosswalk New

Every control is mapped across six frameworks: NIST AI RMF 1.0, ISO 42001:2023, EU AI Act, SOC 2, NIST CSF, and NIST 800-53. Surfaced inline during each control interview and downloadable as a standalone reference workbook.

Your compliance content stays in your browser

AI-generated artifacts, control sessions, maturity scores, and your company context are stored exclusively in your browser's local database — never on Automate48 servers. Account data and training completion records are stored securely in our Cloudflare infrastructure. Full workspace export and import for backups.

AI Risk Intelligence Brief Audit tier

Daily AI security intelligence delivered to your inbox. MITRE ATLAS adversarial technique of the day with 4-layer defense mapping, NVD CVE monitoring for AI/LLM providers, LLM vendor DPA change alerts, model lifecycle tracking, and emerging AI risk news — one analyst-quality brief, five intel streams.

Included with Audit tier

AI Risk Intelligence Brief

The threat landscape for AI systems changes daily. Your compliance program needs to keep pace. The AI Risk Intelligence Brief delivers five curated intelligence streams to your inbox every morning — no research required, no subscriptions to monitor.

MITRE ATLAS — Technique of the Day

One curated adversarial AI technique from the MITRE ATLAS framework, rotated daily from a hand-selected library of 30 high-impact attack patterns. Each entry includes a plain-English description of how the attack works, followed by a structured 4-layer defense: Prevent, Detect, Contain, and Recover — with specific, actionable controls mapped to your comply program at each layer.

Emerging AI Risk — Daily Digest

Up to three items per day from authoritative AI risk sources: CISA advisories, NIST publications, Krebs on Security, The Register, and curated Google News. Each item is assessed for relevance to AI governance and compliance programs — so you see signal, not noise. Deduplication prevents the same story from appearing more than once across any rolling week.

LLM Provider DPA Monitoring

Data Processing Agreements from the major LLM providers — Anthropic, OpenAI, Google, Meta, Mistral, Cohere, and Amazon Bedrock — are monitored daily for content changes via hash comparison. When a DPA changes, the brief flags it and Claude classifies the change as material or non-material, with a plain-English summary of what shifted and what it means for your AI governance posture.

Model Lifecycle Tracking

Anthropic and OpenAI model deprecation pages are monitored for announcements of new models, version changes, and upcoming sunset dates. When a model you may be relying on — or evaluating for deployment — is scheduled for deprecation, you are notified immediately. Critical for MA-02 (Change Management for AI) and MA-05 (Vendor Oversight) control evidence.

CVE / NVD Monitoring — AI Providers

The NVD CVE feed is queried daily and filtered for vulnerabilities in AI and LLM provider infrastructure: Anthropic, OpenAI, Google AI, Amazon Bedrock, Hugging Face, LangChain, and related platforms. Up to three new CVEs per day are surfaced with severity rating, affected component, and a summary of the risk to organizations that consume these platforms via API.

Audit Tier Subscribers

The AI Risk Intelligence Brief is included at no additional cost with every Audit Ready subscription. The brief is delivered to the account holder and to every enrolled team member with the brief enabled. Invite your team from the Team section of the app — access is granted only to explicitly invited individuals, not inferred from email domain, so personal addresses cannot gain access to your organisation's subscription.

Get Audit Ready Sign in to access

Included automatically with every active Audit Ready subscription. Sign in to access.

The Framework

The AI Compliance Framework

26 controls across four NIST AI RMF domains. Each control generates six audit-ready artifacts, customized to your organization, with crosswalk references across six frameworks.

Control Govern Map Measure Manage
G-01AI Governance Policy
G-02Roles and Responsibilities
G-03Ethics and Acceptable Use
G-04Vendor Management
G-05Regulatory Compliance
G-06Training and Awareness
M-01Use Case Inventory
M-02Risk Classification
M-03Data Classification for AI
M-04Impact Assessment
ME-01Output Validation
ME-02Monitoring and Alerting
ME-03Bias and Fairness Testing
ME-04Performance Review
ME-05Human Oversight
ME-06Explainability and Transparency
ME-07Trustworthiness Assessment
MA-01Risk Treatment Planning
MA-02Change Management for AI
MA-03Access Controls for AI
MA-04Incident Response for AI
MA-05Vendor Oversight
MA-06Third-Party Assessment
MA-07Continuity and Shutdown Controls
MA-08Continuous Improvement Review
MA-09Agentic AI Controls

Every control includes 6 artifacts

Each artifact is generated through a guided AI conversation and tailored to your organization, industry, and AI use cases.

1
Governance Policy
Formal requirements document defining scope, accountability, and enforcement — suitable for board approval or regulatory submission.
2
Standard Operating Procedure
Step-by-step operational guidance written for practitioners implementing the control in your specific environment.
3
Implementation Checklist
Itemized task list for executing the control, with completion tracking for project management or internal review.
4
Log Template
Pre-structured record-keeping template for capturing ongoing compliance evidence required by this control.
5
Evidence Checklist
Structured inventory of the specific evidence an auditor or regulator expects to see — aligned to the control's requirements.
6
Audit Narrative
Written current-state assessment of your organization's posture against this control, formatted for internal audit, external auditors, or regulators.
Dave Cooper — Founder, Automate48
Dave Cooper
Founder & CEO, Automate48
Built by practitioners, not theorists

20 years of enterprise compliance at the Fortune 100 level — now applied to AI governance

Dave Cooper spent 20 years as a Vice President at one of the largest US banks, where the security and compliance programs he led protected $100T+ in annual transaction throughput across retail banking, commercial payments, and institutional wire systems — spanning a workforce of 200,000+ and approximately one million technology assets. He established multiple governance and compliance functions from the ground up and earned 5 patents for innovation in security automation. His work produced multiple industry firsts — including the first digital identity provider natively trusted by the US Federal Government and the DoD. A contributing member to multiple national information security standards, he represented the firm on global standards bodies worldwide.

Dave was responsible for assessing and implementing AI/ML information security technologies enterprise-wide — prioritizing evaluations, managing implementations, and setting the security posture for AI adoption at scale. He owned the policy stack across IS Risk Management, Data Protection, Cryptography, and Identity and Access Management — including exactly the type of governance artifacts this tool generates: policies, SOPs, implementation checklists, evidence packages, and audit narratives.

He delivered 100% closure on an OCC Consent Order across 550+ deliverables and terabytes of audit evidence, served as NIST/FedRAMP domain delegate, and spent 12 years leading reverse audits of third-party service providers.

The governance discipline built into every control in this framework comes from two decades of building, auditing, and defending programs under federal regulatory scrutiny — not from theory.

CISSP Six Sigma Black Belt ITIL NIST AI RMF ISO 42001 AI Governance Compliance Programs IS Risk Management DevSecOps Internal/External Audits Federal Regulators Reverse Audits AWS AI/ML 5 Patents
Free resource — no account required

Enterprise AI governance questionnaire — with model answers

Enterprise customers are adding AI governance sections to vendor security questionnaires. This pack gives you the 25 questions they're asking — and what a compliant answer looks like, mapped to ISO 42001, NIST AI RMF, and EU AI Act controls.

  • AI system inventory and risk classification
  • Governance policy, roles, and accountability
  • Risk management, monitoring, and incident response
  • EU AI Act Article 50, Annex III, and ISO 42001 compliance
  • Data privacy, training data provenance, and PII handling

Comply generates a customized version of these answers based on your actual AI systems during the guided intake. The pack above is illustrative — sign up, set your company context, and the AI walks you through each control.

Get the answer pack

25 model answers, framework-mapped. Sent to your inbox immediately.

Check your inbox — the guide is on its way.

Questions? [email protected]

Pricing

Straightforward annual pricing

One license per company. Cancel anytime.

Starter
Train your team and demonstrate AI compliance awareness to customers and auditors.
$497
per year
  • 4 AI compliance training courses — one per NIST AI RMF domain
  • Awareness track (all staff) and Practitioner track (compliance owners) per course
  • Certificate of completion per track
  • Training completion records and printable certificates
  • Unlimited employee seats for training
  • 26-control compliance library — read-only (no AI generation)
Get started
Growth
Build your AI governance program. Generate all 26 control artifacts through guided AI sessions and export an audit-ready package.
$2,997
per year
  • Everything in Starter
  • AI-generated artifacts for all 26 controls — 6 per control (policy, SOP, checklist, log, evidence checklist, audit narrative)
  • 50 AI sessions/month — Claude Sonnet 4.6
  • Five-level maturity tracker with program-wide progress dashboard
  • Program assessment — AI executive summary, domain breakdown, and gap report (.docx)
  • Audit package ZIP — all completed artifacts + master audit narrative + framework crosswalk XLSX
  • Framework crosswalk — 6 frameworks mapped per control, inline and as XLSX download
  • Workspace backup and restore
Get started

Choose Audit Ready over Growth if any of these apply

  • A formal audit, regulatory review, or board presentation requires a single comprehensive AI compliance program narrative — not a collection of 26 separate control documents.
  • Multiple departments need to contribute to the intake before the AI generates anything. Legal, IT, HR, Finance, and Security each own different controls — Program Mode's Excel workbook can be circulated across teams offline before upload.
  • Your output will be reviewed by external auditors, regulators, or enterprise procurement teams where the depth and sophistication of governance documentation is evaluated.
  • You operate in financial services, healthcare, or another regulated industry with a complex AI environment — Claude Opus 4.8 produces materially more sophisticated artifacts than Sonnet for high-stakes documentation.

What each feature includes

Training
4 AI compliance courses All tiers
Structured courses aligned to the four NIST AI RMF domains: Govern, Map, Measure, and Manage. Each course has an Awareness track (~30 min, all staff) covering obligations, shadow AI risk, and incident reporting, and a Practitioner track (longer, for compliance owners) covering implementation methodology and control evidence requirements. Eight tracks total across the four courses.
Certificates and completion records All tiers
A certificate of completion is issued after passing the end-of-course assessment for each track, showing course name, track, completion date, assessment score, and a unique certificate ID. Certificates are printable as PDF via the browser print dialog. Completion dates and scores for all tracks are tracked within the platform and visible in the training catalog. For Audit Ready accounts, completion records are also synced to server-side storage to power the Team Training Report.
Team management & employee enrolment All tiers
Account holders on any plan can invite an unlimited number of employees to the platform by email from the Team section of the app. Each invitation generates a unique enrolment link — access is granted only to explicitly invited individuals, not inferred from email domain. This means personal addresses (gmail.com, icloud.com) cannot be inadvertently included in your organisation's training programme. Invited employees enrol on their own accounts and complete training independently; their progress is visible to the account administrator.
Team Training Report Audit Ready
Compliance administrators on the Audit Ready plan can view a consolidated completion report showing training status for every enrolled employee — by course, by track, with assessment scores and completion dates. Provides the audit evidence required to demonstrate organisation-wide AI governance training under NIST AI RMF GOVERN 6.2 and ISO 42001 §9.
AI Risk Intelligence Brief
Daily AI security intelligence Audit Ready
The brief is delivered every morning to the account holder and to all enrolled team members who have brief delivery enabled. Each recipient receives an individually addressed copy with a one-click unsubscribe link in the email footer — one person opting out does not affect other team members' delivery. Recipients can also toggle brief delivery on or off from within the app at any time. Brief delivery is only active while the Audit Ready subscription is current; if the subscription lapses, delivery stops automatically.
Compliance Library
26-control library — read-only Starter
Starter users can view all 26 controls in the compliance dashboard — descriptions, domain assignments, implementation effort ratings, and control ownership guidance — without generating AI artifacts. AI-assisted artifact generation requires Growth or above.
Framework crosswalk — 6 frameworks Growth +
Each of the 26 controls is mapped to its corresponding reference across six frameworks: NIST AI RMF 1.0, ISO 42001:2023, EU AI Act, SOC 2 (Trust Services Criteria), NIST CSF 2.0, and NIST 800-53 Rev 5. The crosswalk appears inline during any control interview (toggled via the Crosswalk button in the artifact panel) and is also available as an XLSX spreadsheet download for use in mapping exercises or audit packages.
AI Artifact Generation — Guided Mode
26 control artifact bundles Growth +
The AI generates six artifacts per control through a guided conversation (Guided Mode): (1) Governance Policy — the formal policy document governing this control area; (2) Standard Operating Procedure — step-by-step implementation guidance for staff; (3) Implementation Checklist — actionable tasks to achieve and maintain compliance; (4) Log Template — pre-structured record-keeping for ongoing evidence; (5) Evidence Checklist — exactly what an auditor expects to find for this control; (6) Audit Narrative — a written current-state assessment of your organization's posture, formatted for internal audit, external auditors, or regulators. All six artifacts are tailored to your company, industry, AI use cases, and existing controls.
50 AI sessions/month Growth
A session is counted once per control per new conversation start — when you send the first message to the AI for a given control. Subsequent exchanges within that same conversation do not consume additional sessions. 50 sessions is sufficient to open all 26 controls in a single month with sessions to spare for re-starts. Sessions reset at the start of each calendar month. Uses Claude Sonnet 4.6.
150 AI sessions/month — Claude Opus 4.8 Audit Ready
Three times Growth's session capacity. Uses Claude Opus 4.8 — Anthropic's most capable model — for every AI exchange and artifact generation. Opus produces longer, more nuanced artifacts and handles complex governance environments (multiple AI systems, regulated industries, existing ISO 27001 or SOC 2 programs) with greater depth than Sonnet. The additional session capacity supports using Guided Mode alongside Program Mode in the same month.
AI Artifact Generation — Program Mode (Audit Ready only)
Program Mode intake workbook Audit Ready
Program Mode is a parallel path to Guided Mode for organizations that prefer bulk intake over control-by-control sessions. Download the 214-question Excel workbook (four tabs: Govern, Map, Measure, Manage), complete it offline with your team, then upload the completed file. The workbook includes guidance notes for every question. This workflow is suited to teams that want to gather answers across multiple departments before engaging the AI.
AI review and gap analysis Audit Ready
After uploading the completed workbook, Claude Opus reviews every answer across all 26 controls and flags each as GOOD, NEEDS_CLARIFICATION, or NEEDS_INPUT. You review the feedback, revise the workbook if needed, and re-upload before proceeding to narrative generation. This review step catches thin or missing answers before they become gaps in your audit narrative.
Master AI Compliance Program Narrative Audit Ready
After the workbook review, Claude Opus generates an 8-section Master AI Compliance Program Narrative covering: Executive Summary, Program Scope and Governance Structure, GOVERN domain controls, MAP domain controls, MEASURE domain controls, MANAGE domain controls, Program Maturity Assessment, and Key Gaps and Improvement Priorities. Because all 26 controls' intake answers are processed simultaneously in a single AI call, the narrative references cross-control relationships and dependencies — the AI understands how your vendor management posture (G-04) relates to your incident response capability (MA-04), for example. Downloads as a Word document (.docx).
Maturity, Reporting & Export
Five-level maturity tracker Growth +
Self-assess each control at one of five levels: L1 Initial (ad hoc, undocumented), L2 Developing (documented but inconsistently applied), L3 Defined (standardized and consistently applied), L4 Managed (measured and monitored), L5 Optimized (continuous improvement process in place). The dashboard shows controls started vs. not started, average maturity across the program, and how many controls have reached L3 or above. Maturity ratings are your own subjective assessments — they do not affect AI-generated artifact content.
Program assessment Growth +
One-click AI-generated executive summary across all controls where you have set a maturity level: overall program maturity score, domain-by-domain breakdown table (Govern, Map, Measure, Manage), top five priority gaps with recommended next steps, and a board-ready narrative summary. Downloads as a Word document (.docx) for presentation or inclusion in an audit file. Requires at least one control to have a maturity level set.
Audit package ZIP export Growth +
Single-click download of a ZIP file containing: all completed control artifacts (Policy.docx, SOP.docx, Implementation-Checklist.docx, Log-Template.docx, Evidence-Checklist.docx, Audit-Narrative.docx) organized in a subfolder per control; a Master Audit Narrative (.docx) consolidating the audit narrative artifact from every completed control into a single document; the framework crosswalk spreadsheet (.xlsx); and a cover page identifying the organization, date, framework alignment, and artifact inventory. Only controls with at least one generated artifact are included. The ZIP is formatted for direct delivery to auditors, regulators, legal counsel, or enterprise procurement teams.
Workspace backup and restore Growth +
All compliance content — AI sessions, generated artifacts, maturity ratings, and company context — is stored in your browser's IndexedDB, not on Automate48's servers. The workspace backup exports this data as a JSON file. Import the file at any time to restore your workspace in a different browser, recover from a browser data reset, or transfer work between devices. Training progress is managed separately and is not included in the workspace backup.

Need a custom arrangement for a larger organization or reseller program? Contact us.