New: AI Agent Governance Pack
Your AI agents need governance too.
If any AI tool in your company can read email, edit files or call another system, you are already running agents. The pack gives you what an auditor will ask for, in days rather than months.
Inventory
Every agent, model, tool and data source, with an owner.
Permissions
What each one may read, write, send or spend.
Oversight
Who can stop it, how fast, and whether the stop is logged.
Audit trail
One record per run, tied to the exact instruction version.
We run these controls on our own agents and publish the attestation, including what was not verified. Read it on the trust page.
The situation you are probably in
Your team adopted AI tools the way everyone did — quickly, and in several places at once. Marketing has a copy assistant, engineering has a coding assistant, someone piloted a chatbot. Now a customer questionnaire asks which AI systems process their data, whether you test for bias, and who is accountable. Or a renewal lands with an AI clause in it.
The honest answer is usually that nobody has written it down. Not because the risk is unmanaged, but because nobody had a spare month to produce an inventory, a policy set, a risk register and an evidence trail in the shape a reviewer expects.
What you actually receive
An assessment with arithmetic you can check
Every score discloses how it was reached: the factors, the weight of each, and why the number is not higher or lower. If the assessment says 62, you can follow the 62. A number without its reasoning is an incomplete answer, and we treat it as one.
Policies written for your organisation
An AI governance and accountability policy, acceptable use, and the supporting standards — shaped by what your intake actually said, not a generic pack with your name substituted at the top.
A risk register and evidence requirements
What to hold, why, and what a reviewer will ask for. The register is the thing that turns a one-off document into something you can maintain.
Framework mapping that cites real identifiers
ISO/IEC 42001, ISO 27001, SOC 2, NIST AI RMF and more, cited to identifiers in a maintained library. Requirements are described in our own words; licensed standard text is never reproduced.
Why the output is worth trusting
The uncomfortable question about any AI-generated compliance document is whether it invented something. Ours is built so that it cannot do so quietly.
- An independent review stage. Every output is checked by a separate reviewer that never sees the instructions given to the system that wrote it. Its job is to decide whether the output can be released — not to defend it. If a citation is not supported by the material supplied, the output is withheld rather than published.
- Citations are checked against the library, not asserted. A clause identifier that does not exist in the control library does not survive review.
- Withholding is a normal outcome. Sometimes you will be told an output was held back for human review. That is the control working, and we would rather show you that than publish something fluent and wrong.
- Gaps stay gaps. Missing information is reported as missing. It is never quietly treated as compliant to make a score look better.
How this works in detail, and what we deliberately do not claim →
How it goes
- Free scan. 12 questions, roughly 10 minutes. Scored in your browser, and the score appears without an email. You keep it either way.
- Full assessment ($299). A structured intake covering your systems, data, oversight and vendors, producing the scored assessment, the domain analysis and the gap report.
- Documents. Policies, register and evidence requirements generated from that assessment — either as the standalone Policy Pack ($499) or inside the Readiness Bundle ($899).
Priced to be decided, not negotiated
Every comparable platform is an annual subscription that starts around $5,000 and is gated behind a sales call. That is a reasonable way to buy when you have a compliance function. It is a poor fit when you have a customer questionnaire due in a fortnight.
| What | Price | Commitment |
|---|---|---|
| Free AI risk scan | $0 | None. No email needed to see the score. |
| AI Risk Assessment | $299 | One-time |
| Policy Pack | $499 | One-time |
| Readiness Bundle | $899 | One-time |
Full pricing, including professional review and partner terms →
Reasonable objections
Could I not just ask a general-purpose AI to write these?
You can, and for a first draft it will look convincing. The difference is what happens to the citations: a general model will produce clause identifiers that sound right, and some of them will not exist. RiskWoven cites against a maintained control library and puts every output through a review stage whose job is to catch exactly that. It also keeps your organisation's context, so the second document is consistent with the first.
Is this a certification?
No. Nothing here certifies, accredits or approves anything, and no output will tell you that you are compliant. It produces the assessment, documents and evidence position that a certification body or a customer's reviewer will want to see. Certification is awarded by an accredited body after their own audit.
What happens if the AI gets something wrong?
The review stage withholds outputs it cannot support, and those go to a human review queue rather than to you. Everything you receive is advisory and is written for you to check — which is why the reasoning is attached to every score rather than kept behind the number.
We are eleven people. Is this proportionate?
It should be. An eleven-person business with two AI tools and human review before anything is published is not the same risk as an autonomous system making decisions about people, and the assessment is built to say so rather than to rate everything as critical. If the output ever recommends a governance committee to a bakery, that is a defect and we want to hear about it.
Who can see our data?
Your workspace is yours. See Trust & method for how information is handled, what leaves the platform, and what does not.
Start with the scan
It costs nothing, it takes ten minutes, and the score is yours whether or not you ever buy anything. If it tells you that you are in reasonable shape, that is a useful thing to know too.