Three ways to run it · pilots open Q3 2026

The AI governance audit, productised.

A platform, a live regulatory knowledge graph, and two ready-to-ship assessment frameworks — run it yourself, have poview.ai run it for you, or license it through your own firm.

Regulatory knowledge graph — cluster visualisation
Live regulatory knowledge graph v2.0 · 73,400 edges
50,000+
Graph nodes
73,000+
Relationships
6
Jurisdictions
5 weeks
Kick-off to board-ready
§01The market signal

Your clients' clients are already asking for it.

ISO 42001 — the AI management-system standard — was published in late 2023. Within eighteen months it had moved out of academia and into procurement.

250+

enterprise procurement processes now require evidence of AI management-system certification.

ISO 42001 · published Dec 2023 · cited globally within 18 months
§02The status quo

A bespoke project. Not a practice.

The second-line team running it, the boutique consultant brought in to help, the big firm auditing the lot — all three are building on the same stack: a spreadsheet, a senior person's regulatory memory, and six-to-eight weeks of expensive time. It does not compound, for any of them.

01

6–8 senior weeks per engagement.

Partner-grade time spent reading regulation, not interpreting findings. One, maybe two of these per partner per quarter.

02

Inconsistent between assessors.

No shared regulatory intelligence. Answers vary by who's holding the pen, and the report is impossible to standardise across the practice.

03

No remediation tail.

Static PDF delivered, findings lose momentum within a month, no annual reassessment cadence. One-off revenue with nowhere to go.

04

Single-jurisdiction scope.

Clients operate across UK, EU, US and APAC. Your spreadsheet does not. Cross-jurisdiction findings get scoped out, not scoped up.

§03How it's run

Three delivery models. One platform.

The platform is the same in every case — same knowledge graph, same frameworks, same board-ready output. What changes is who's holding the pen. Pick the model that matches the engagement you have today.

01 · Self-serve

Your second-line team runs it in-house.

For group risk, compliance, and internal-audit teams who want to own their AI governance posture rather than outsource it. Licensed to your organisation, run by your people.

  • Internal maturity baseline
  • ISO 42001 readiness, owned in-house
  • Cross-jurisdiction obligations mapped to your control library
  • Board cadence aligned to your operating-risk pack
Direct licence Self-serve pilot →
02 · Delivered by poview.ai

We run the assessment for you, on the same platform.

For organisations that want the assessment done by the team who built the platform. Poview.ai consultants conduct the engagement; you keep the platform afterwards for remediation and reassessment.

  • Senior consultant in the chair, end-to-end
  • Five-week kick-off to board-ready
  • Board-ready PDF under poview.ai branding
  • Platform handover for ongoing posture tracking
03 · White-label licence

Your consulting firm ships it under your brand.

For Risk Advisory partners and AI-practice leads who want to license the platform and deliver the engagement to their own clients. Per-client workspaces, your logo, your narrative voice.

  • White-labelled, board-ready reports
  • Per-client workspaces with hard data isolation
  • Both assessment frameworks, full knowledge graph
  • Remediation tracking — the retainer hook
Platform licence Firm pilot →
§04The platform

A purpose-built AI-governance audit platform with a live regulatory knowledge graph at its core.

AIssure is the tool, not the service. Your consultants are still in the chair. We just took the spreadsheet out from under them.

01 · Frameworks

Structured frameworks, day-one ready.

Two assessment frameworks shipped on the platform — both calibrated for regulated financial services and both extensible to your control library.

Maturity · 96QISO Deep Dive · 275Q
02 · Knowledge graph

Built from primary source materials.

50,000+ nodes ingested from FCA, EU, US and APAC primary regulation — every answer the platform gives links back to the source paragraph.

FCAEU AI ActISOAPAC
03 · Evidence assessment

AI scoring with consultant sign-off.

Per-question AI verdicts grounded in the knowledge graph, with citation guard. Consultants approve and sign every score before the report ships.

Citation-verifiedConfidence-rated
§05The defensible answer

Every answer your team gives, defensible to source.

The knowledge graph is the part that's actually hard to build, and the part competitors can't copy quickly. It's what lets your senior people defend findings in a regulator's office.

Knowledge graph constellations

Structured from the actual text of FCA handbooks, EU regulation, ISO standards, and APAC supervisory materials. Cross-referenced, versioned, citation-backed.

50,000+
Nodes
Regulations, clauses, controls, jurisdictions, evidence chunks — every concept addressable.
73,000+
Relationships
Cites, supersedes, defines, applies-to — the structure that makes search defensible.
6
Jurisdictions
UK, EU, US, Singapore, Hong Kong, Australia — versioned quarterly so findings remain reproducible.
100%
Cited to primary text
No LLM training-data hearsay. Every answer the platform gives links back to the source paragraph.
§06Frameworks

Foothold first. Premium on the rebound.

Two frameworks ship with the licence. The Maturity Assessment is your way in. The ISO Deep Dive is the engagement you sell back to the same client twelve months later.

AI Governance Maturity AssessmentSELL FIRST

Foothold first. Premium on the rebound.

96
Questions
8
Domains
0–5
Maturity scale

Two frameworks ship on the platform. The Maturity Assessment is your way in. The ISO Deep Dive is the engagement you sell back to the same client twelve months later.

FCA SYSCConsumer DutyEU AI ActDORAMASHKMA
ISO Standards Deep DiveCERTIFICATION-READY

Certification-grade under the same roof.

275
Questions
3
ISO standards
Critical weight

Six months later: the same client, the ISO Deep Dive. CRITICAL questions weighted 4×; the report ships externally validatable.

ISO/IEC 42001ISO/IEC 23894ISO/IEC 38507
§07Engagement shape

Five weeks. Kick-off to board-ready.

Senior time clusters at the start and the end. The middle is operated by a junior consultant supervised through the platform. That is the leverage shift.

01
Wk 1
Setup

Firm profile, scope auto-tailored to jurisdictions and product lines.

02
Wk 2
Assessment

Guided sessions with client stakeholders; evidence capture in-platform.

03
Wk 3–4
AI analysis

Automated scoring; consultant review; every citation verified.

04
Wk 5
Reporting

Board-ready PDF with your branding, narrative voice and remediation matrix.

05
Ongoing
Remediation

Owner-assigned actions tracked to closure. Annual reassessment optional.

Up to 80% faster than the spreadsheet-and-Word version. From 6–8 senior weeks → 5 mixed-seniority weeks
§08What you license

A tool, not a service. The audit, productised.

The platform is the same in every delivery model — whether your second-line team is running it, poview.ai consultants are running it for you, or a licensed consulting firm is running it for their clients. The list below is what ships in the box.

01
Platform access, scoped to your firm

Per-client workspaces with hard data isolation. Your consultants, your clients, no cross-tenant access.

05
Consultant regulatory chat

Multi-turn AI chat for ad-hoc questions during engagements. Citation-backed answers, not RAG-over-PDF guesses.

02
Both assessment frameworks

Maturity (96Q) and ISO Deep Dive (275Q). All eight domains. All weighting. Both jurisdictions.

06
White-labelled, board-ready reports

Your logo, your narrative voice, your delivery. Auto-generated structure, manually finalised by your team.

03
Full regulatory knowledge graph

UK, EU, US, Singapore, Hong Kong, Australia. Updated quarterly. Versioned so old findings remain reproducible.

07
Remediation tracking

Owner assignment, due dates, evidence attachment. The retainer hook that turns one-off audits into recurring revenue.

04
AI evidence assessment

Scored verdicts against every requirement, with confidence ratings and citation trails. Your consultant signs off.

08
Named engagement-success contact

Through pilot and the first three live engagements. Real onboarding, not a Notion handover.

§09Outcomes

What changes when the audit is productised.

Three outcomes that fall out of the engagement shape changing from contractor-grade to product-grade. Each one matters to both audiences — a Risk Advisory P&L and a second-line CRO are measuring different things, but the underlying shift is the same.

SPEED & CONSISTENCY

Six-to-eight senior weeks become five mixed-seniority weeks. Same regulatory intelligence regardless of who's holding the pen.

For consulting firms Engagement margin captured by your P&L, not passed to the client.
CONTINUOUS POSTURE

Findings stay live, not buried in a PDF. Remediation tracked. Quarterly reassessment runs against the same baseline.

For consulting firms The retainer hook. Engagement margin captured by your P&L, not passed to the client.
+1
ISO 42001 READINESS

The platform's ISO Deep Dive frames the audit against ISO/IEC 42001, 23894 and 38507 — the certification path your clients are now being asked for.

For consulting firms A new productised service line. The firms that build it in 2026 will own the category through 2030.
§10The pilot

One real assessment. Eight weeks. Fixed price.

Three pilot shapes, same shape on the platform. Pick the one that matches the engagement you have today — we'll handle the rest.

If the three success criteria land — time-to-report, stakeholder NPS, repeat intent — we move to a standard licence on terms agreed at pilot kick-off. No surprises, either side.

Book the working session
Three paths Self-serve — your team, your organisation. poview.ai — we run it for you. White-label — your consultants, your client.
Scope One Maturity Assessment or one ISO Deep Dive — your call.
Duration Eight weeks end-to-end, including reporting.
Investment Fixed pilot fee, materially below list licence.
Success criteria Time-to-report · stakeholder NPS · repeat intent.
Next step Standard licence or follow-on engagement on terms agreed during pilot kick-off.
Next step

Thirty minutes. One of your engagements. A direct answer.

Walk us through one in-flight or recently-completed engagement. We'll tell you honestly whether AIssure would have changed the shape of it. If the answer is yes, we scope the pilot from there.

ContactTerry Yodaiken · Founder & CEO Emailterry.yodaiken@poview.ai Platformaissure.app