Govern every AI system from inception to retirement
The AI Registry keeps every AI system at a stage of the ISO/IEC 22989 lifecycle, with an owner who answers for it. The controls that apply follow the stage, and every move from one stage to the next is on the record with a name and a date.
1,200 AI systems across seven lifecycle stages, from inception to retirement. In one week five systems change stage. The Claims triage assistant moves from operation and monitoring to re-evaluation on Tuesday after its drift test fails, and returns to operation on Friday after retraining. Each move is recorded with the person who made it and the date.
An approved AI system keeps changing
Registration is a snapshot, but the system keeps moving. After approval, a pilot goes into production, a model is retrained, the owner changes jobs and the policy it was approved under comes up for renewal.
Governance follows the system through each of those changes: the stage it is in, the person who answers for it, the policies it has to meet and a record of every decision along the way.
Policy Center / Policies
Acceptable use of generative AI
v3 · PublishedRenewal every 12 months · next renewal 15 Jul 2027
| When | Sent to |
|---|---|
| 30 days before | Policy owner |
| 7 days before | Policy owner |
| 24 hours before | Policy owner |
| Renewal date | Policy owner |
| 24 and 48 hours after | Policy owner |
| 7 days after, then weekly | Policy Managers |
| 30 days after | Org Admins |
412 of 460 staff have acknowledged v3
The others are reminded after 7 and 30 days. Illustrative data.
Policies renew and get acknowledged on schedule
Each policy in the Policy Center has a renewal period of three, six or twelve months. A scheduled run reminds the owner before the renewal date and, when it passes, moves the reminder up to the Policy Managers and then to the Org Admins. Staff who have not acknowledged the current version get their own reminders.
Show an auditor what changed and who changed it
Policies, controls, tests and evidence each keep their own change log: what changed, when, and who or which run made the change. When the auditor asks why a control is marked as executed, the answer sits on the control itself.
Policy
Acceptable use of generative AI
- 12 JulVersion 3 approvedPolicy Manager
- 15 JulVersion 3 publishedPolicy owner
- 1 AugAcknowledged by the Claims triage assistant ownerHead of claims operations
Control
MCF-67 Production data drift monitoring
- 31 AugEvidence attached and lockedData scientist
- 22 SepStatus moved to not executedMetric test
- 25 SepStatus moved to executedControl owner
Metric test
Production data drift
- 2 SepThreshold changed from 0.30 to 0.25Data scientist
- 22 SepRun failed, owners notifiedScheduled run
- 25 SepRun passedScheduled run
See where governance is missing
The register rolls up into one view for the head of AI governance: how many systems are approved, how many wait for a review, which ones have no owner, and which business units lag behind. Decisions that have waited more than a week stand out.
Put a price on the systems in the register1,200 AI systems in the register
Monday 21 Sep, 09:00- Approved 1,053
- Pending review 71
- Draft 53
- No owner 23
23 registration decisions have waited more than a week
- Underwriting82%
- Procurement84%
- IT85%
- Marketing85%
- Customer service88%
- Legal and compliance88%
Share of each unit’s AI systems approved, lowest first. Illustrative data.
Bring one AI system you already run to the demo
We follow it through its lifecycle: the owner, the stage, the policies it answers to and the record an auditor will ask for. Then we look at how renewals and reviews would run for your teams.
Discovery, risk, compliance and agents
- Discovery Find and register every AI system, then send each one through a review.
- Risk Put a price on every AI risk and see how it changes from week to week.
- Compliance Map one control to many frameworks and test it against production.
- Agents Scout and the platform agents do the repetitive work, on demand or on a schedule.