Alexis Hirschhorn · ISO 42001 Lead Auditor
Know every AI system you run. And prove you govern it.
Acuna AI Governance is one register of every AI system your organisation builds or buys, with the management system ISO/IEC 42001 and the EU AI Act expect around it. Classification, impact assessment, named human oversight, and incidents, all on the same records as the rest of your compliance program.
Built by CISOs, auditors and DPOs · Made in Switzerland · Data hosted in Swiss infrastructure
Part of the Acuna platform · AI Governance (AIM)
WHAT IT DOES
Know your AI. Assess its impact. Show your evidence.
Know your AI
One inventory of every AI system, in-house or vendor-supplied, with its provider, purpose, autonomy level, lifecycle stage and the people it affects. Including the tools another team switched on without telling you.
Assess its impact
A structured assessment of the harm a system can do to the people it affects, with its EU AI Act classification recorded alongside it: role, risk class, Annex III use case, and the rationale for each.
Show your evidence
Approved assessments freeze. Oversight is named. Incidents attach to the system that caused them. When a regulator or an auditor asks on what basis, the record answers.
THE SHAPE OF THE WORK
The question is never "do you have an AI policy?"
It is which systems you run, what harm they could do, who is accountable for each one, and what happened when something went wrong. Most organisations cannot answer the first part, which makes the rest unanswerable.
You do not have the list
AI arrived through procurement, through a feature toggle in software you already owned, and through a vendor who never mentioned it. There is no inventory, so the first honest answer to "which AI systems do you run?" is a spreadsheet somebody starts on the day the question is asked.
The assessments live somewhere else
Where impact assessments exist, they are documents. They are not attached to a system, they are not versioned against a decision, and nothing stops a system going live without one. The gate is a meeting, and meetings are not evidence.
It is a second program you do not want
Most of what an AI management system needs (asset inventories, access control, change management, supplier oversight, incident response) is already running in your security and privacy programs. Buying a separate AI tool means proving the same controls twice, in two places, to two auditors.
TRY IT
Is your AI system high-risk under the EU AI Act?
The classification question decides how much of the Act applies to you. Work through it here, on a system you actually run. Nothing is stored and nothing is sent. The check runs entirely in your browser.
Is your AI system high-risk?
Four questions at most, in the order a regulator asks them. Nothing is saved and nothing leaves your browser. This runs entirely on this page.
An orientation tool, not legal advice. Classification turns on your system’s actual intended purpose and the documentation behind it. Confirm the result against the Act and the Commission guidelines.
This is the same classification logic the module records against each system, with the rationale kept beside the answer.
THE REGISTER
One row per AI system. Classification on the record, not in a memo.
Every system carries its role under the EU AI Act, its risk class, the Annex III use case where one applies, and the reasoning behind each. The audit question is always "on what basis?", so the rationale is a field rather than a footnote.
RATIONALE ON AI-2026-014
Annex III point 4(a): AI intended to be used for recruitment or selection, in particular to screen or filter applications. Recorded at classification, dated, and carried into the impact assessment.
THE LIFECYCLE
Nothing reaches Approved for use without an approved assessment behind it.
Every system moves through five states, and the transition into Approved for use is gated. Not by a reminder or a checklist item. The state will not change until an approved impact assessment exists on the system.
Dated history, and an assessment that freezes on approval
Every transition carries its date and who made it, so the lifecycle is its own audit trail. And an approved assessment keeps the wording, the scope and the evidence it was approved against. Reassessments supersede it rather than overwrite it, so an assessment approved in March still reads as March in December. That is what makes it evidence: it states what was true on the day, and goes on stating it.
HUMAN OVERSIGHT
Name the person who can actually stop it.
Oversight is only real if someone holds the authority to act on it. Each system records who supervises it and what they are actually empowered to do: override a decision, suspend the system, or neither.
What the module flagsA system in production with nobody empowered to stop it is flagged, not silently accepted. That flag is the one an auditor will find first, so you should find it first.
INSIDE THE PLATFORM
Built into the GRC program, not beside it.
An AI system is not an island. It runs on assets you already track, supports processes you already map, touches processing activities in the Privacy module, and carries risks, issues and controls in the registers you already keep. A control mapped once counts everywhere it applies.
Both framework trees ship in the catalog
The organisations that struggle with AI governance are usually the ones treating it as a brand new discipline. In practice most of the controls already exist in their security and privacy programs. The work is pointing them at AI and keeping a human on the decisions that matter, not buying a second system to run in parallel.
QUESTIONS
Common questions about Acuna AI Governance.
EARLY ACCESS
See the working module, and shape what ships.
AI Governance is available soon. Early-access participants get a walkthrough of the working build, commercial terms confirmed for their scope, and direct input into what lands before general availability.
- A 30-minute walkthrough on your own AI systems, not a canned demo
- Commercial terms for your scope, confirmed before you commit to anything
- Direct line to the team building it, and influence on what ships first
AI Governance is priced as a module on top of Acuna Core, like Supplier Shield and the Data Privacy Module. See platform pricing.
Govern your AI where you already govern everything else.
A 30-minute walkthrough on the AI systems you actually run, inside the platform that already holds your frameworks, risks and controls.