Policy & Evidence Engine (12–20 weeks)
Move from policy documents to operational governance with evidence and control mapping.
Policy builder
- Guided AI Use Policy generator
- Prompt Safety Rules generator
- Approval routing
Evidence trail
- Store decisions and approvals
- Prompt templates and versions
- Audit logs for reviewers
Vendor registry
- Central vendor risk records
- Model/tool inventory
Controls mapping
- EU AI Act alignment
- Internal risk framework mapping
- ISO/NIST crosswalk
Milestones
- Policy builder approved by Risk/Compliance
- Evidence trail stored for pilot decisions
- Vendor registry populated
- Controls mapping validated