Governx, accounted for

AI governance that answers to the board and the regulator.

A trust score that explains itself, AI risk in money, frameworks assessed from live signals, audits run to a sealed archive, and evidence an auditor can check.

The Govern capabilities

Specs

Govern, in detail

Delivery and data

Delivery
SaaS, from one login.
Isolation
Each customer runs in an isolated workspace with its own database.
Certifications
None held. Frameworks are mapped to and assessed against.

Frameworks

NIST AI RMF
Mapped to: AI controls assessed from live signals.
EU AI Act
Mapped to: AI-governance controls cross-mapped, with evidence.
ISO/IEC 42001
Mapped to: The same AI controls, with clause references.
India DPDP
Mapped to: Consent and data governance controls.
SOC 2
Mapped to: Baseline controls with graded evidence.
See the frameworks

Last reviewed 6 Oct 2026

Where do we stand?

AI governance in ColossalX turns what the platform sees, controls and tests into a position you can defend to a board or regulator: a trust score that explains itself, a risk register quantified in money, frameworks assessed from live signals and an audit run to a sealed archive. Evidence collects itself, graded by how it was obtained and timestamped daily.

The board asks how exposed the AI estate is, and the answer is a slide of adjectives.

ColossalX answers with a graded score, a loss range in money and evidence an auditor can re-check.

Govern · 4 capabilities

Four capabilities answer one question, where do we stand, and each reads the same spine: one issue queue, one risk register, one trust score, one evidence store and one reports hub.

ColossalX Trust Engine

A trust score that explains itself: five pillars, security, compliance, risk, resilience and AI governance, graded A+ to F from live evidence.

Explore
More

A pillar with no evidence carries no weight, and a grade resting on too little is marked provisional. The page names what pulls the score down, how far the next grade is, and the action that supplies each missing piece of evidence.

Trust score · provisionalIllustrative

Trust score · provisional: C. Security measured; Compliance measured; Risk measured; Resilience not measured; AI governance measured. Resilience has no evidence, so provisional

Risk quantification

A risk register that fills itself from compliance gaps, audit findings, code scans, proven attacks and threat-intelligence decisions.

Explore
More

Entries are de-duplicated and closed when the source closes. Critical assets raise impact, never lower it. FAIR turns any entry into an annual loss range with a one-in-twenty-year tail. An acceptance beyond your appetite goes to the board with a reason and an end date, then lapses back to analysis.

FAIR · loss rangeIllustrative

FAIR · loss range: an illustrative loss distribution with its range shaded, the likely loss marked and the your appetite as a dashed line.

Compliance and AI governance

Frameworks mapped and assessed against, never certified.

Explore
More

They include NIST AI RMF, the EU AI Act, ISO/IEC 42001, SOC 2, GDPR, India DPDP, PCI DSS, and the SEBI and IRDAI cyber circulars. Each control carries the status a person decided beside a health label from live signals, and a control with no runtime signal is not assessable: excluded, never silently passed, while evidence is graded and timestamped.

One control, many frameworksIllustrative

One control, many frameworks: Guardrails on AI inputs and outputs maps to EU AI Act (Art. 15); NIST AI RMF (MANAGE 2.1). Mapped to and assessed against, not certified.

Audit

Run an audit of AI systems and the third parties behind them, from a risk-based plan to a sealed, timestamped archive.

Explore
More

An engagement opens only when the evidence for its trigger exists, design is tested before operation, samples replay identically and each finding gets a management response. The preparer never reviews and the signer never prepared, and findings flow into owned work and the risk register.

Audit archive · AI agentsIllustrative

Audit archive · AI agents: Engagement AI agents, second half; Workpapers Design and operation tested; Findings Answered and tracked; Sign-off Not the preparer; Timestamp From a public authority. Sealed archive.

How it works

From one proven attack to the board pack.

One attack proven on an agent, followed until the board and auditor can see it: a risk entry, a loss range in money, a decision by a named owner, a proven fix and timestamped evidence.

Workflow · one proven attack, accounted forIllustrative

01 Exposure proven

A red-team run proves an attack, and the register gets a risk.

02 Quantified in money

FAIR gives the risk an annual loss range and a one-in-twenty-year tail.

03 Owner decides

A named owner treats it; accepting it would need a board minute.

04 Proven and recorded

The fix is proven, the trust score moves, and evidence is timestamped.

How it connectsx, accounted for

Where a governed x goes next.

Governance does not end on a dashboard. The same records reach the people, tools and reports that act on them.

  1. Findings from testing, scanning, intelligence, audit and compliance land in one owned queue.

  2. Evidence collects itself, graded A to D, second-person verified, withdrawn but never deleted.

  3. An AI policy generated or uploaded, published by version and accepted by named people.

  4. Reports hub

    11 report types as branded PDFs, scheduled and signed off by a second person.

  5. The risk register syncs out to GRC, ticketing and SIEM tools, signed and outbound only.

Honest by design

What it does, and what it does not.

Sign-off · separation of dutiesIllustrative

Sign-off · separation of duties: audit preparer to management sign-off, "Approve the audit report for the AI agents engagement". Checks: Signer did no work failed, Reason shown passed. Verdict: refused, Signer never preparer.

What it does not do

x, not measured

ColossalX holds no certification, and mapping a framework to its controls does not confer conformity with that framework.

All 4 limits
  • Framework control sets are baselines, not clause-by-clause mappings, and several controls have no runtime signal yet.
  • Jurisdiction packs and audit checklists are starting content for your counsel to review, not legal advice.
  • FAIR is only as good as the ranges your analysts enter; no workspace is seeded with loss estimates.

How we know

  • A pillar with no evidence carries no weight, and a thin grade is marked provisional.
  • Evidence is graded A to D from facts the server recorded, never from what a client said.
  • Not assessable is a first-class answer: excluded from the score, never counted as a pass.
  • Risk acceptances must expire, and those beyond appetite need a board minute.

Questions

Questions buyers ask

What is an AI governance platform?

An AI governance platform keeps an organisation's use of AI accountable: what is in use, who owns it, which risks it carries, which rules and frameworks apply, and the evidence that controls work. ColossalX does this from its own runtime and testing data, so the position it reports is measured rather than filled in by questionnaire.

What is the difference between AI governance and AI security?

AI security finds, stops and tests: it finds AI in use, refuses unsafe requests and attacks your own defences. AI governance accounts for it: risk in money, frameworks assessed, policies accepted, audits run and evidence kept. In ColossalX both run on one spine, so a proven attack moves the governance record without anyone retyping it.

Which frameworks does ColossalX map to?

NIST AI RMF, the EU AI Act, ISO/IEC 42001, SOC 2, GDPR, India DPDP, PCI DSS and the SEBI and IRDAI cyber circulars, with AI-governance controls cross-mapped to NIS2. Each is mapped to and assessed against, never certified: ColossalX holds no certification, and its framework control sets are baselines rather than clause-by-clause mappings.

How does ColossalX produce evidence an auditor can check?

Evidence collects itself from runtime signals and is graded A to D by how it was obtained. It can be verified by a second person, originals are kept byte-exact, a daily manifest of the whole store is timestamped by a public authority, and withdrawn evidence is flagged with a reason rather than deleted.

Who in an organisation owns AI governance?

Usually several people: a head of AI governance or a DPO for policy and data, risk for the register, compliance for frameworks, internal audit for assurance and the CISO for security. ColossalX gives each a role and enforces separation of duties on the server, so a preparer cannot sign off their own work.

What does the board see?

A grade it can read, with its reasons: the trust score across five pillars, the top risks as loss ranges with a one-in-twenty-year tail, acceptances above appetite awaiting a board minute, and reports signed off by a second person. Where evidence is thin, the grade says provisional instead of flattering the position.

The other verbs

Next step

Account for your x.

See your own AI estate the way your board and your auditor will: graded, in money, and backed by evidence anyone can re-check.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start