AI Governance Platform

    Know your AI.
    Control the risk.

    Complete AI system inventory, automated EU AI Act compliance, and continuous risk monitoring, for every entity in your organisation.

    AI System Register · Whisperly
    12
    Total systems
    2
    High risk
    5
    Limited risk
    5
    Minimal risk
    CH
    ChatGPT Enterprise
    Generative AI · Language
    DeptMarketing
    ProviderOpenAI
    Risk tierLimited
    StatusCompliant
    RC
    AI Resume Screener
    ML Model · Classification
    DeptHR
    ProviderInternal
    Risk tierHigh risk
    StatusAction req.
    CO
    Microsoft Copilot
    Code assistant · Productivity
    DeptEngineering
    ProviderMicrosoft
    Risk tierMinimal
    StatusCompliant

    You can't track AI
    at the speed of
    spreadsheets.

    Spreadsheets. Legacy platforms. Email threads. Your team is buried in admin while new AI tools are deployed daily, untracked and unassessed.

    Your AI risks may already cost
    more than you know.

    Vendor AI, shadow tools, and unclassified systems compound silently. By the time a fine arrives, the damage is already done.

    Outlook
    SK
    Sarah Kovacs
    Head of Procurement · Meridian Financial Group
    to: compliance@nexaflow.io
    Today, 09:14
    ● Vendor review failed
    RE: Nexaflow AI integration, onboarding on hold

    Following our AI vendor review, we are unable to proceed with onboarding. Critical gaps in your AI governance programme prevent approval under our procurement policy.

    Findings from AI governance assessment
    CriticalNo AI system register provided. Cannot verify which AI tools process our data.
    CriticalDocument processing AI classified high-risk under EU AI Act Annex III. No conformity assessment submitted.
    HighNo AI use policy or human oversight procedure provided.

    We are happy to re-engage once a compliant AI governance programme is in place.

    Vendor risk
    3 in 5
    AI incidents traced to third-party vendors
    Shadow AI
    83%
    Of employees use AI without IT approval
    Regulatory
    €35M
    Maximum EU AI Act fine per violation

    Track your AI, manage risks and
    get compliant at the speed of AI.

    While legacy tools make you catalogue systems manually, our agents discover AI, classify risk, and generate documentation, your team reviews and approves.

    Book a Demo

    Know every AI in your
    organisation.

    From shadow AI to enterprise deployments, Whisperly surfaces every AI system automatically.

    app.whisperly.ai / ai-governance / inventory
    AI System Inventory
    SystemDepartmentRiskStatus
    ChatGPT Enterprise
    OpenAI
    MarketingLimited Approved
    Microsoft Copilot
    Microsoft
    EngineeringMinimal Approved
    Live Activity
    Waiting for activity…

    Whisperly connects to your stack and surfaces the AI nobody registered.

    Read-only connectors across identity, collaboration, cloud and spend. The discovery agent matches every signal against a catalogue of AI tools, assigns an owner and scores the risk tier.

    Your infrastructure · 12 sources connected
    GWGoogle Workspace
    M365Microsoft 365
    IdPOkta / Entra ID — SSO logs
    AWS & Azure accounts
    $SaaS spend & card statements
    </>Code repos & API keys
    Discovery Agent
    Read-only · EU-hosted · continuous
    Signals processed today3,412
    1Match signals against 1,400+ known AI tools
    2Attribute owner, business unit and data touched
    3Score the risk tier and flag missing DPAs
    AI systems discovered
    47
    AI systems
    11
    Shadow AI
    8
    High-risk
    AI recruitment scoring module
    People · registered · owner assigned
    HIGH-RISK
    ChatGPT Plus — 34 personal accounts
    SSO logs · no DPA · customer data pasted
    SHADOW AI
    Customer support chatbot
    CX · registered · limited risk
    REGISTERED
    Notion AI — workspace-wide
    118 users · training opt-out unset
    SHADOW AI
    Midjourney — personal card plan
    Card statements · Marketing · unowned
    SHADOW AI
    Every finding lands in one workflow
    Route to AI intake
    Assign an owner
    Classify & document
    Register or block
    9 days
    from connection to full AI inventory

    Comply with multiple frameworks

    One platform. Every major AI governance framework. Whisperly maps your obligations across EU AI Act, ISO 42001, and NIST AI RMF — so you comply once, everywhere.

    Available
    EU AI Act
    Europe · 2024

    Risk-based regulation for AI systems placed on the EU market. Mandatory for high-risk AI.

    Risk classificationTechnical docsHuman oversight
    Available
    ISO 42001
    Global · 2023

    International standard for AI management systems. Framework for responsible AI development and deployment.

    AI policyImpact assessmentContinual improvement
    Available
    NIST AI RMF
    United States · 2023

    Voluntary framework to improve the ability to incorporate trustworthiness into the design and use of AI systems.

    GovernMapMeasureManage

    Automate your AI intakes.

    Every new AI tool goes through a structured intake. Your team reviews and approves.

    • AI scores risk automatically
    • Compliance checklist generated
    • One-click send for review
    Book a Demo
    app.whisperly.ai / ai-governance
    AI Intake Request,
    Large Language Model
    Under review
    Submitted by
    James Kim · Engineering
    System name *
    GPT-4o Customer Support Bot
    Business unit *
    Customer Experience
    Compliance checklist
    DPIA completed
    Data retention policy linked
    Human oversight documented
    Bias assessment completed
    AI Risk Classification
    Auto-scored by AI agent
    72 / 100
    Data sensitivityHigh
    Automation levelMedium
    Human oversightLow
    Model transparencyMedium
    Evidence
    DPIA_2026.pdf
    Risk_Assessment.docx

    All you need to stay compliant with the EU AI Act.

    Classify your system and start complying with EU AI Act obligations through Whisperly guidance.

    Explore the EU AI Act solution
    AI System Register

    Build and maintain a complete, always-current inventory of every AI system.

    AI Register
    12 systems
    ChatGPT Enterprise
    OpenAI · Marketing
    Limited
    Resume Screener
    Internal ML · HR
    High risk
    Microsoft Copilot
    Microsoft · Engineering
    Compliant
    Risk Assessment

    Conduct AI impact assessments in a fraction of the time.

    Risk Register
    Updated 2 min ago
    2
    High
    3
    Limited
    7
    Minimal
    Resume Screener, DPIA missing
    High
    Credit model, disclosure lacking
    Limited
    Incident Management

    Centralise AI incident reports and serious malfunction notifications.

    Incident Inbox
    2 open
    Bias complaint · Resume Screener
    Urgent
    Received 1 Jul · Due 15 Jul · Day 2
    Malfunction · Credit model
    In progress
    Received 28 Jun · Day 5
    Post-Market Monitoring
    Continuously track deployed AI systems for performance issues, drift, and emerging risks.
    Technical Documentation
    Generate and maintain all Article 11 technical documentation. Audit-ready at all times.
    Transparency Obligations
    Track and fulfil Article 52 disclosure requirements for limited-risk AI systems automatically.
    AI Policy Library
    Pre-built templates for AI use policies, acceptable use agreements, and human oversight procedures.
    EU AI Act Registration
    Manage your EU database registrations for high-risk AI systems with deadline tracking.
    Governance Risk Register
    AI-assisted risk register with continuous monitoring across your AI portfolio.

    Agents do the work.
    You monitor and approve.

    Three specialised agents cover every dimension of your AI governance programme, continuously, without waiting to be asked.

    AI Inventory Agent

    AI discovery and cataloguing, automated.

    Continuously scans your organisation for AI systems, from enterprise SaaS to internal models. Builds and updates your AI register without manual effort.

    AI Inventory Agent · Scanning
    AI System Discovery, Live ScanDiscovering
    ChatGPT Enterprise
    OpenAI · Generative AI · Marketing
    Limited risk
    AI Resume Screener
    Internal ML · Classification · HR
    High risk
    Microsoft Copilot
    Microsoft · Code assistant · Engineering
    Minimal risk
    Credit Scoring Model v2
    Internal ML · Finance · Banking
    Classifying…
    ◎ Agent finding: 4 of 12 systems require compliance action
    Risk Assessor Agent

    Risk classified. Actions prioritised. Gaps closed.

    Assesses each AI system against the EU AI Act's risk tiers automatically. Flags required conformity assessments, registrations, and human oversight obligations.

    EU AI Act Assessment, AI Resume Screener
    Unacceptable
    High risk ✓
    Limited
    Minimal
    Classification reasoning
    !Employment decisions covered by Annex III, point 4
    !Automated screening affects access to employment
    !No fundamental rights impact assessment completed
    Documentation Agent

    Docs written. Evidence stitched. Ready to review.

    Drafts Article 11 technical documentation, keeps records versioned, and links evidence to each obligation. Your team accepts or edits, one click at a time.

    Draft: Article 11 Technical DocumentationReady for review
    System description generated
    Data governance section drafted
    Human oversight procedure attached
    Post-market monitoring plan linked

    Multiple entities and languages.

    Manage your entire group's AI governance programme. Each legal entity maintains its AI register and compliance posture in its own language.

    Multiple legal entities
    Each subsidiary has its own isolated AI register and governance programme.
    Multiple frameworks, unified controls
    EU AI Act, ISO 42001, NIST AI RMF, UK AI, each mapped automatically, no duplicated work.
    Multiple languages
    Policies generated in the local language of each entity, German, English, French, and more.
    Organisational Units
    Build and manage your company structure with legal entities and departments.
    Veridax Group
    Parent Organisation
    Germany
    EU AI Act · German
    HR
    Marketing
    Procurement
    Berlin
    Munich
    United Kingdom
    ISO 42001 · English
    HR
    Legal
    Sales
    London
    Manchester
    California
    NIST · English
    Product
    Sales
    Marketing
    San Francisco
    France
    EU AI Act · French
    HR
    Compliance
    Zurich
    Geneva
    EU AI ActISO 42001NIST AI RMFISO 42001
    4 entities · 4 frameworks · 2 languages

    Three solutions. One platform.
    No gaps between them.

    AI governance doesn't exist in isolation. Neither should your tools.

    AI Governance

    AI governance across frameworks

    Connected to your data privacy programme and AI vendor risk assessments, so no AI obligation falls through the cracks.

    Data Privacy

    AI within your data privacy compliance

    AI systems process personal data. Without linking AI governance to your privacy programme, your DPIAs are incomplete and your EU AI Act and GDPR obligations go untracked.

    Vendor Risk

    Vendor assessment

    Under both AI governance and data privacy programmes, you need live vendor risk assessments to keep Article 28 and AI Act obligations current.

    Whisperly connects all three, because they are inseparable.
    When a vendor uses an AI tool that processes EU personal data, Whisperly flags it across your RoPA, your DPIA, and your AI Act inventory simultaneously.
    Book a Demo
    Customer Success
    "Whisperly has been our data privacy compliance partner for years. As we expand into AI governance, it was an easy decision to extend that cooperation - having everything in one place."
    Read the full story
    Featured customer
    Bloomberg Adria
    Media & Publishing

    Common questions about
    AI governance.

    No per-seat costs.
    No implementation fees.

    Join the organizations that have turned AI governance from a burden into a business accelerator.

    Stay ahead of compliance changes

    Practical compliance tips, delivered to your inbox every two weeks.