What problem does AI governance software solve?
Most organizations already have an AI policy. It says which uses are allowed, which data may be sent to a model, what a customer-facing assistant must never say, and who signs off before launch. The problem is that a policy document does nothing on its own. Someone has to find the AI systems it applies to, put controls in place, check that the controls work and show the results to an auditor, a regulator or a board.
An AI governance platform is software that carries a policy through those steps and keeps a record of each one. The record is the product: it is what lets a company answer 'how do you know your AI follows your rules' with documents rather than assurances.
What are the four outputs?
We describe the chain in four steps, the same four used in the control maps on this site:
- Policy: what the rule says, in terms specific enough to test. 'Do not give individual investment advice' is a policy; 'use AI responsibly' is not.
- Control: what enforces the rule. A runtime guardrail that blocks or rewrites a response is a control. So is an approval step before a model goes live.
- Evidence: what proves the control worked. Logs of blocked responses, red teaming results, drift checks and test reports are evidence.
- Report: what an auditor receives. A report maps controls and evidence to a framework such as the EU AI Act, ISO/IEC 42001 or the NIST AI RMF.
Why do most tools cover only part of the chain?
Governance software grew from two directions. One started with risk and compliance teams: questionnaires, registers of AI systems, impact assessments and framework reports. The other started with security and trust and safety teams: adversarial testing, runtime guardrails and logs. The first is strong at policy and report. The second is strong at control and evidence.
Both are now moving toward the middle. Inventory-first platforms add monitoring and policy enforcement; enforcement-first platforms add framework mapping and audit trails. When you read a vendor page, ask which of the four steps it describes in detail and which it only names.
What should a buyer ask first?
Start with the question your auditor or regulator will ask first. If it is 'which AI systems do you run and who owns them', you need discovery and a register. If it is 'what did your customer-facing assistant say, and how did you stop it saying the wrong thing', you need runtime controls and logged evidence. Most programs need both eventually; the order decides which platform you evaluate first.
This site scores six platforms on all four steps and weights the middle two most heavily, because that is where written policy becomes provable behavior. The ranking shows the result, and the readiness score re-weights it for programs that start elsewhere.