A structured 26-control program framework for risk management teams and compliance officers. Generates the policies, evidence packages, and audit narratives independent reviewers require — with a five-level maturity model at every control.
Stop building from blank documents. Start from production-ready, AI-personalized artifacts.
Every control generates six tailored artifacts: governance policy, SOP, implementation checklist, log template, evidence package, and audit narrative — each customized to your organization.
A structured AI-guided dialogue — not a static form — draws out the specifics of your environment, probes material gaps when they surface, and iteratively builds artifacts grounded in how your organization actually operates.
Four structured courses covering the full framework. Assign to employees, track completion, and generate training records for your audit file.
Track progress across all 26 controls with a five-level maturity model. Dashboard view shows where you stand and where to prioritize next.
One-click executive program assessment: overall maturity score, domain breakdown table, top 5 priority gaps, and a board-ready narrative summary across your entire program.
Single-click download of all completed artifacts organized by control, with a program cover narrative identifying the organization, framework alignment, and artifact inventory — formatted for delivery to auditors, regulators, legal counsel, or other interested parties.
When your answers reveal a material governance failure — no policy, shadow AI use, no incident process — the AI probes the depth of the gap before moving on, surfacing the real risk exposure rather than accepting a surface answer.
Every control is mapped across six frameworks: NIST AI RMF 1.0, ISO 42001:2023, EU AI Act, SOC 2, NIST CSF, and NIST 800-53. Surfaced inline during each control interview and downloadable as a standalone reference workbook.
AI-generated artifacts, control sessions, maturity scores, and your company context are stored exclusively in your browser's local database — never on Automate48 servers. Account data and training completion records are stored securely in our Cloudflare infrastructure. Full workspace export and import for backups.
Daily AI security intelligence delivered to your inbox. MITRE ATLAS adversarial technique of the day with 4-layer defense mapping, NVD CVE monitoring for AI/LLM providers, LLM vendor DPA change alerts, model lifecycle tracking, and emerging AI risk news — one analyst-quality brief, five intel streams.
The threat landscape for AI systems changes daily. Your compliance program needs to keep pace. The AI Risk Intelligence Brief delivers five curated intelligence streams to your inbox every morning — no research required, no subscriptions to monitor.
One curated adversarial AI technique from the MITRE ATLAS framework, rotated daily from a hand-selected library of 30 high-impact attack patterns. Each entry includes a plain-English description of how the attack works, followed by a structured 4-layer defense: Prevent, Detect, Contain, and Recover — with specific, actionable controls mapped to your comply program at each layer.
Up to three items per day from authoritative AI risk sources: CISA advisories, NIST publications, Krebs on Security, The Register, and curated Google News. Each item is assessed for relevance to AI governance and compliance programs — so you see signal, not noise. Deduplication prevents the same story from appearing more than once across any rolling week.
Data Processing Agreements from the major LLM providers — Anthropic, OpenAI, Google, Meta, Mistral, Cohere, and Amazon Bedrock — are monitored daily for content changes via hash comparison. When a DPA changes, the brief flags it and Claude classifies the change as material or non-material, with a plain-English summary of what shifted and what it means for your AI governance posture.
Anthropic and OpenAI model deprecation pages are monitored for announcements of new models, version changes, and upcoming sunset dates. When a model you may be relying on — or evaluating for deployment — is scheduled for deprecation, you are notified immediately. Critical for MA-02 (Change Management for AI) and MA-05 (Vendor Oversight) control evidence.
The NVD CVE feed is queried daily and filtered for vulnerabilities in AI and LLM provider infrastructure: Anthropic, OpenAI, Google AI, Amazon Bedrock, Hugging Face, LangChain, and related platforms. Up to three new CVEs per day are surfaced with severity rating, affected component, and a summary of the risk to organizations that consume these platforms via API.
The AI Risk Intelligence Brief is included at no additional cost with every Audit Ready subscription. The brief is delivered to the account holder and to every enrolled team member with the brief enabled. Invite your team from the Team section of the app — access is granted only to explicitly invited individuals, not inferred from email domain, so personal addresses cannot gain access to your organisation's subscription.
Included automatically with every active Audit Ready subscription. Sign in to access.
26 controls across four NIST AI RMF domains. Each control generates six audit-ready artifacts, customized to your organization, with crosswalk references across six frameworks.
| Control | Govern | Map | Measure | Manage |
|---|---|---|---|---|
| G-01AI Governance Policy | ✓ | |||
| G-02Roles and Responsibilities | ✓ | |||
| G-03Ethics and Acceptable Use | ✓ | |||
| G-04Vendor Management | ✓ | |||
| G-05Regulatory Compliance | ✓ | |||
| G-06Training and Awareness | ✓ | |||
| M-01Use Case Inventory | ✓ | |||
| M-02Risk Classification | ✓ | |||
| M-03Data Classification for AI | ✓ | |||
| M-04Impact Assessment | ✓ | |||
| ME-01Output Validation | ✓ | |||
| ME-02Monitoring and Alerting | ✓ | |||
| ME-03Bias and Fairness Testing | ✓ | |||
| ME-04Performance Review | ✓ | |||
| ME-05Human Oversight | ✓ | |||
| ME-06Explainability and Transparency | ✓ | |||
| ME-07Trustworthiness Assessment | ✓ | |||
| MA-01Risk Treatment Planning | ✓ | |||
| MA-02Change Management for AI | ✓ | |||
| MA-03Access Controls for AI | ✓ | |||
| MA-04Incident Response for AI | ✓ | |||
| MA-05Vendor Oversight | ✓ | |||
| MA-06Third-Party Assessment | ✓ | |||
| MA-07Continuity and Shutdown Controls | ✓ | |||
| MA-08Continuous Improvement Review | ✓ | |||
| MA-09Agentic AI Controls | ✓ |
Each artifact is generated through a guided AI conversation and tailored to your organization, industry, and AI use cases.
Enterprise customers are adding AI governance sections to vendor security questionnaires. This pack gives you the 25 questions they're asking — and what a compliant answer looks like, mapped to ISO 42001, NIST AI RMF, and EU AI Act controls.
Comply generates a customized version of these answers based on your actual AI systems during the guided intake. The pack above is illustrative — sign up, set your company context, and the AI walks you through each control.
25 model answers, framework-mapped. Sent to your inbox immediately.
Check your inbox — the guide is on its way.
Questions? [email protected]
One license per company. Cancel anytime.
Need a custom arrangement for a larger organization or reseller program? Contact us.