Skip to main content

AI Governance & Model Risk

18 martech vendors in AI Governance & Model Risk, part of Governance, Privacy & Compliance. Each record carries the date we last verified it, so you can see how current it is before you rely on it.

Last verified:

Procurement-readiness profiles — SOC 2, ISO 27001, GDPR and DPA posture, data residency, AI-training policies — are available when you sign in.

AI governance and model-risk software lists the AI models a company runs or buys, tracks approvals, bias tests, and past incidents, and checks each model against rules like the EU AI Act. Risk, legal, and IT teams use it to answer a regulator's questions about one specific model, not the whole AI program at once.

Who it is for

  • AI governance and risk leads shortlisting a system to maintain one authoritative model inventory across every team building or buying AI.
  • IT security reviewers assessing how a platform that catalogs sensitive model documentation and testing results is itself secured.
  • Legal and compliance teams confirming the inventory maps cleanly onto the specific obligations a regulation like the EU AI Act actually imposes.

What your No-Committee will ask

IT security
Is stored model paperwork and test-result data encrypted at rest? Is editing access to the inventory limited by role, not shared across the whole team? Both encryption and role limits are logged as their own claim, each marked verified, self-attested, or not found.
Data governance
Where is uploaded model paperwork and risk-assessment data kept, and is a Data Processing Agreement on offer for it? We confirm data location and DPA availability against the vendor's own legal pages, not a sales deck.
AI governance
Does the platform itself use AI to auto-classify a model's risk tier, and if so, can a reviewer override that classification rather than accept it as final? Auto-classification and override support are tracked as a single evidenced claim, not assumed from the product description.
Legal / compliance
Does the vendor publish which specific regulatory frameworks its templates map to, rather than a general claim of 'AI compliance'? Framework-mapping detail is recorded with a source link wherever the vendor names the regulation by name.
Risk / finance
Can the whole model inventory be exported if the platform relationship ends? A model record can end up as evidence in a regulatory inquiry years later, so we check for a stated export path and call it not found where the page stays silent.

How we verify

Every claim above is pulled from the vendor's own pages — trust center, privacy policy, or public product pages — never guessed from what an AI governance tool can usually do. Our methodology page spells out the exact bar behind verified, self-attested, and not-found.

Frequently asked questions

How is AI governance and model-risk software different from data-privacy governance?

Data-privacy governance maps personal data and handles requests tied to it, like access or deletion. AI governance and model-risk software instead catalogs the models themselves — what they do, how they were tested, and which rules apply to them. The two increasingly overlap where a model processes personal data, and some platforms now cover both.

Do AI governance platform vendors typically publish SOC 2 or ISO 27001 certification?

Vendors selling into regulated enterprises with an established compliance function more often publish a SOC 2 report, since their own buyer is usually a risk or compliance team. Newer entrants in this fast-moving category more often describe controls on a general page without third-party certification, which we mark as self-attested.

Is pricing usually public for AI governance platforms?

Pricing is rarely public in this category, which is still young and moving fast. Most vendors price against the number of models tracked or the size of the organization's AI program, both of which vary too much to publish a flat rate. Expect a quote-only conversation rather than a self-serve tier.

What should I check beyond a model inventory list before shortlisting a platform?

Confirm whether risk classifications can be overridden by a human reviewer, which named regulations the templates actually map to, and where uploaded model documentation is stored. A tool meant to demonstrate AI accountability deserves the same evidentiary standard it's asking every model to meet.

AI Governance & Model Risk vendors, newest verification first. 18 shown on this page.
VendorLast verified
opaque.co
myvoice.ai
protegrity.com
lightbeam.ai
levo.ai
skyflow.com
crawlq.ai
aixplain.com
aparavi.com
modulos.ai
caliberai.net
truyo.com
onetrust.com
cloudeagle.ai
langdock.com
spectrumlabsai.com
kertos.io
bigid.com