Acuna AI Governance
Preview — ISO/IEC 42001 and the EU AI Act in one module
Acuna AI Governance gives you a single register of every AI system your organization builds or buys, and the management system around it that ISO/IEC 42001 and the EU AI Act demand, from first pilot to retirement. Record each system's provider, purpose, autonomy level and the people it affects, classify it under the EU AI Act, run structured impact assessments, assign human oversight, and log incidents. Nothing reaches Approved for use without an approved impact assessment behind it. The module is in preview and not yet generally available; the capabilities below describe the build now in validation.
Capabilities
What Acuna AI Governance does.
FAQ
Common questions about Acuna AI Governance.
Not yet. The module is in preview and running in staging while the register, assessment, and oversight records are validated. This page describes the build now in test. Contact us to see it and to be told when general availability lands.
Software that inventories the AI systems an organisation builds or buys, classifies them by risk, records the assessments and oversight behind each one, and keeps the evidence a regulator or auditor will ask for. It is the operational layer under standards like ISO/IEC 42001 and laws like the EU AI Act.
Yes, as separate framework trees in the same catalog. ISO/IEC 42001 ships with its full set of management clauses and Annex A controls; the EU AI Act ships at article level. A control mapped once counts against both, and against the other frameworks you already run.
Each system's provider, purpose, autonomy level, lifecycle stage, and the people it affects, plus its EU AI Act classification: role, risk class, Annex III use case where one applies, and the rationale for each. Vendor-supplied systems also carry a link to the supplier's assurance evidence.
Deployer-first. It is built for organisations that buy and run AI systems in decisions affecting people, such as hiring, credit, customer service, safety, and operations, and is designed to grow with providers who build them.
Most of the groundwork carries over: asset inventories, access control, change management, supplier oversight, and incident response all apply to AI systems too. This module adds what those do not cover, namely the AI-specific register, impact assessment, and human oversight records that ISO/IEC 42001 and the EU AI Act ask for.