AssessedGovern

Know what your AI systems need. Prove they have it.

Assessed Govern is AI governance automation software. One assessment discovers your AI systems, maps them to 128 controls across 42+ frameworks, proves whether each control exists, and blocks deployments that fall short, with every conclusion traced to evidence.

Governance fingerprintExample
AGF
AutonomyLevel 3

Hover a dimension. Higher numbers mean more governance required. The CI gate watches this for changes.

Organizations deploying AI face a growing set of governance obligations. Consultants and spreadsheets take weeks per system and are outdated on delivery. That approach breaks when three AI systems become thirty.

Assessed Govern replaces the spreadsheet with an engine.

How it works

Three stages take an AI system from unknown to proven.

Each stage produces an artifact the next stage depends on. Discovery produces the manifest, assessment produces the determinations, and assurance keeps both current as the system changes. The feedback loop is the point: governance that cannot see change cannot keep up with it.

  1. 01 · Connect

    Connect the systems that hold the truth.

    Point Assessed Govern at a repository, a cloud account, or an identity provider, or describe the system in plain English. Connectors are read-only; they observe and never modify the target.

    • Code, infrastructure, and delivery pipelines are read.
    • Models, agents, tools, and data integrations are identified.
    • Each capability is staged from Suspected to Verified based on the connectors that ran.

    Output An AI System Manifest that describes what the system is, what it can do, and what data it touches.

    Discovery run · exampleScanning
    Files scanned1,284
    Model SDKs2
    Agent frameworks1
    Tool definitions7
    Data integrationsClaims database, payments
    Exposed credential1, value not stored
    S1S2S3 effective unknown
  2. 02 · Assess

    Determine what the system owes.

    Sixty deterministic rules evaluate the manifest. Every rule is version-controlled and readable, so the reasoning behind each determination can be reviewed and challenged.

    • Risks are identified across AI, security, privacy, and regulatory categories.
    • Applicable ARISE controls are selected, and the crosswalk identifies the external requirements they satisfy.
    • Gaps become findings, ranked by severity, with a remediation step for each.

    Output A governance fingerprint, the controls in scope, and a ranked list of findings.

    Rule evaluation · example60 of 60 rules
    exposureCommitted API key in config/settings.pyCritical
    securityPrompt injection can reach tool authorityHigh
    agenticFinancial action without authorization boundaryHigh
    regulatoryEU AI Act likely in scopeApplies
    organizationNo AI impact assessment completedAttest
    41controls in scope
    705requirements apply
    5findings
  3. 03 · Assure

    Prove it, then keep proving it.

    Evidence is collected from discovery, from executable control tests, and from signed attestations. Each item carries a freshness TTL; when it expires, the finding reopens without anyone having to remember.

    • Thirteen control tests check whether a control works, not whether someone says it does.
    • The CI gate compares every pull request against the baseline and blocks regressions.
    • The determination record packages the result for an auditor, regulator, or risk committee.

    Output Current evidence, a gate decision on every change, and a tamper-evident determination record.

    Evidence freshness · exampleTTL
    Model documentation
    Current
    Logging configuration
    Current
    Access review
    Stale
    Finding reopened: access review evidence expired after 90 days
    BLOCKMerge
Not a questionnaire

An engine replaces the questionnaire.

What you're used toWhat Assessed Govern does
A consultant fills out a spreadsheetAn engine reads your code and infrastructure
One framework at a time42+ frameworks from one assessment
Point-in-time auditEvidence expires and findings reopen
"We have a policy"Show the evidence, or it's a finding
Binary pass or failA six-stage capability model with provenance
Results stale on deliveryA CI gate catches regressions on every pull request
Weeks per systemMinutes per system
Automated AI system discovery

You can't govern what you can't see.

Assessed Govern reads the systems where the truth lives, including code, infrastructure, and identity, and builds an inventory of every AI system it finds: what the system is, what it can do, and what data it touches.

Models and agentsWhat the system runs and how autonomously it acts.
Tools and integrationsWhat the system can reach and act on.
Data and credentialsWhat sensitive data and secrets are present.
Infrastructure and pipelinesWhere the system runs and how it ships.

Confirmed, not assumed. Capabilities are confirmed by evidence rather than inferred from code. Where the engine cannot confirm something, it reports the gap instead of guessing.

Detected, never stored. Credentials and sensitive data are identified in place. The values themselves never reach the assessment.

AI risk management engine

Deterministic rules turn the inventory into governance requirements.

The engine evaluates each system against the ARISE Framework™ and determines which risks are present, which controls apply, and which external requirements follow. The same inputs always produce the same determinations.

RisksWhat could go wrong, and how severe it would be.
ControlsWhat the system owes, mapped across every applicable framework.
FindingsWhere the gaps are, with a remediation step for each.
Observations are never rewritten.

What a connector saw is recorded once and cited by every finding that depends on it.

Absence is reported as absence.

"Not found" and "does not exist" are different claims. The engine only makes the first.

Every mapping shows its method.

Reviewed, imported, and inferred mappings stay distinguishable. Nothing is silently upgraded.

Continuous AI assurance

Evidence has an age.

A control someone attested to last year is not proof that the control exists today. For every required control, Assessed Govern sets an evidence expectation and then collects evidence from three sources.

From discoveryObservations

Matched to evidence requirements. Did the scan find logging configuration, identity permissions, an evaluation suite?

From control tests13

Executable evaluations that check whether a control actually works, not whether someone says it does.

From attestation29

Organizational questions for controls no scanner can observe. Only asked when the control is in scope. Only counted when someone signs their name to the answer.

ExpectedRequirement set
CollectedScanner
ValidatedTest passes
StaleTTL expires, finding reopens

TTLs range from 1 to 365 days depending on the control. Continuous assurance means re-proving, not trusting last year's answer.

Coverage is reported honestly.

Both numbers are correct for the connectors that ran. The engine reports what it can prove, not what it hopes is true.

3%
Evidence coverage
AI security assessment, privacy, and ethics

The engine automates what evidence can prove.

Judgment stays with the people accountable for it.

AutomatedAI

Capabilities, autonomy, and impact are assessed from the system itself.

AutomatedCybersecurity

Exposure and AI attack paths are identified and tested.

AutomatedPrivacy

Personal data flows and their obligations are mapped.

AttestedEthics

Fairness and human impact are settled by a named, accountable person.

A fairness determination is a judgment about people and context, so Govern does not automate it. It records who made the call, when, and on what evidence, so the answer can be reviewed and challenged.

AI CI/CD governance gate

Governance runs in the pipeline, not in a meeting.

The gate checks every pull request against the system's baseline and returns one of three results.

PASS

The change raises no governance concerns.

WARN

The change is flagged for review and can still merge.

BLOCK

The change cannot merge until the issue is resolved.

Engineers see the finding and the fix in their pull request, and the gate policy lives alongside their code.

AI determination record

The output an auditor is handed.

When a regulator, auditor, or risk committee asks to see your AI governance, the answer is the determination record: a self-contained, tamper-evident document. Same inputs produce the same record.

Determination recordclaims-triage-agent
    Merkle rootcomputing

    Try to tamper with it.

    Each section is hashed with SHA-256, and a Merkle root covers them all. Change any section and the chain breaks.

    $ assessed record verify
    OK · all sections match root

    The record sits in an append-only ledger that can be anchored externally. Only the root hash leaves your tenant, and no governance data is published.

    System manifestWhat the AI system is
    Governance fingerprintThe 10-dimension risk profile
    Control determinationsWhich ARISE controls apply and their evidence state
    Risk assessmentRisks with severity and mitigation mapping
    Evidence artifactsWhat was collected, when, by which collector, and its freshness
    Test resultsPassed, failed, or requires manual review
    FindingsGaps ranked by severity, with remediation
    TraceabilityFinding to rule to fact to observation to file and line
    ProvenanceEngine, rule, and knowledge graph versions
    EU AI Act, NIST AI RMF, ISO 42001, and more

    One assessment maps to more than 42 frameworks.

    Every AI system maps to the ARISE governance ontology: 128 controls with 953 prioritized requirements. The crosswalk then fans out to more than 42 external frameworks. Every row carries its mapping method and confidence score. We don't hide how the mapping was made.

    That makes one engine your EU AI Act compliance tool, your NIST AI RMF compliance platform, and your ISO 42001 compliance automation, without running three separate programs.

    Law and regulation

    EU AI Act

    GDPR

    CCPA / CPRA

    UK Data Protection Act

    Standards

    ISO 42001

    ISO 27001

    NIST AI RMF

    NIST CSF

    Audit criteria

    SOC 2

    SSAE 18

    Industry frameworks

    OWASP Top 10 for LLM Applications

    MITRE ATLAS

    CIS Controls

    Research and guidanceMore

    AI safety and governance frameworks, for 42+ in total

    Your AI system
    DiscoveredWhat it is
    60 rulesARISE controls that apply
    CrosswalkTo 42+ external frameworks
    Applicable clausesWith the evidence state for each

    No framework-to-framework mapping. ARISE is the common language, and the crosswalk fans out from there.

    What you get

    Each leader reads the same record for a different decision.

    The CISO sees AI risk across the portfolio.

    The view shows which systems have credentials in source, which have write authority without identity boundaries, and where governance is not yet established. All of it comes from automated discovery rather than a survey.

    The engineering lead finds issues in the pull request.

    The CI gate catches governance issues before merge. Engineers see a failing check and a remediation step rather than a framework they have never read, and governance runs in the pipeline instead of in a meeting.

    The compliance lead gets every framework from one assessment.

    A single assessment maps to the EU AI Act, NIST AI RMF, ISO 42001, GDPR, SOC 2, and more than 42 frameworks in total, with evidence instead of attestation wherever a scanner can observe it. Produce the determination record the regulator asks for.

    The head of AI ships without a six-week review.

    The engine runs in minutes rather than months. When the model changes, the assessment updates. When evidence expires, you know.

    Use cases

    Organizations apply the engine across the AI lifecycle.

    01

    Pre-deployment assessment

    Run the engine, complete the organizational intake, generate the determination record, and present it to the risk committee. Minutes of engine time instead of weeks of consultant time.

    02

    Continuous monitoring

    Evidence expires, models change, and permissions drift. The CI gate catches regressions on every pull request, and the fingerprint diff shows exactly what changed.

    03

    Regulatory response

    Asked for EU AI Act compliance on a system? Hand over the record: the system description, applicable articles, evidence state, and findings. Every claim traces to an observation.

    04

    Shadow AI detection

    Scan repositories across the organization and find the SDKs, agent frameworks, and model calls nobody registered. Discovery is the first step to governance.

    05

    M&A due diligence

    Scan the target's repositories before close. How many AI systems, what they can do, what data they touch, and where the gaps are. The profile takes hours rather than months.

    06

    Portfolio risk view

    Compare fingerprints across every system. See where autonomy, sensitive data, and weak oversight concentrate, and prioritize by evidence, not intuition.

    By the numbers

    These figures sit behind every assessment.

    128ARISE governance controls
    953prioritized requirements
    42+regulatory frameworks mapped
    1assessment to cover all of it
    Security

    A governance product must hold its own security to a higher standard.

    Read-only by designConnectors observe and never modify your systems.
    Secrets never storedSensitive values are detected, never retained.
    Immutable recordsObservations and audit events cannot be altered.
    Isolated tenantsAccess is scoped by role and by tenant.

    Found a security issue? Email security@assessedsolutions.ai. We respond within 48 hours.

    Questions

    Organizations ask these questions first.

    What is an AI governance platform?

    An AI governance platform determines what governance each AI system requires, proves whether the controls exist, and keeps that record current. Assessed Govern does this by reading your code, cloud, and identity configuration instead of relying on questionnaires.

    How does Assessed Govern help with EU AI Act compliance?

    It determines whether the EU AI Act is likely in scope for a system, maps the applicable requirements through the ARISE crosswalk, and shows the evidence state for each. The determination record is what you hand a regulator.

    Does it support NIST AI RMF and ISO 42001?

    Yes. One assessment maps to NIST AI RMF, ISO 42001, the EU AI Act, SOC 2, GDPR, and more than 42 frameworks in total.

    Can it run an OWASP LLM Top 10 assessment?

    Yes. The security rule domain covers AI attack vectors such as prompt injection reaching tool authority, with risk categories sourced from the OWASP LLM Top 10, NIST AI RMF, MITRE ATLAS, and ARISE.

    What is an AI determination record?

    A self-contained, tamper-evident document containing the system manifest, governance fingerprint, control determinations, evidence, test results, and findings. Every finding traces to a source file and line, and every section is hashed with SHA-256 under a Merkle root.

    How does the AI CI/CD governance gate work?

    It runs in your CI pipeline on every pull request, compares the system against its baseline, and returns PASS, WARN, or BLOCK. The gate policy lives alongside your code.

    What is continuous AI assurance?

    Evidence has a freshness TTL of 1 to 365 days depending on the control. When it expires, the finding reopens automatically, so assurance means re-proving controls rather than trusting last year's answer.

    How is ethics handled?

    Ethics controls are part of every applicable assessment, and the questions reach the people accountable for them. Answers count only when a named person attests. Fairness determinations require human judgment, so Govern records them rather than automating them.

    See your first assessment.

    Join the beta, point Assessed Govern at a repository, and receive your governance fingerprint, applicable controls, and findings in minutes.

    Sign up for beta today

    Join the beta

    Tell us about your organization and which platform you want to run. We use these details only to contact you about the beta, as described in our Privacy Policy.

    Interested in

    By signing up, you agree that Assessed Solutions may contact you about the beta. You can ask us to delete your details at any time. See our Privacy Policy.

    You're on the list.

    Thank you for your interest. We will contact you at the email you provided with next steps for the beta.