PricorisTechnologies

AI Governance: test the system, govern it, file the result

AISIA takes an AI use case from intake to a documented disposition. SPRICO attacks the deployed system and files what it finds against AISIA's controls. Together they produce the evidence ISO/IEC 42001, the NIST AI RMF and the EU AI Act ask for.

Governance

Intake, triage gate, system and resource registration, EU AI Act classification, impact assessment, statement of applicability with control effectiveness, risk assessment and treatment, actions, evidence, disposition. Each stage writes to the evidence register.

Assurance

2,350 adversarial prompts anchored to an 85 control enterprise checklist, run across canonical, guardrailed and adversarial variants against your endpoint, scored by twelve model types and an LLM judge, with per finding evidence artefacts.

Editions

AI Startup: a SPRICO campaign against your endpoint and AISIA for ISO 42001 readiness, for AI companies being asked for governance evidence in a customer's vendor due diligence. AI Enterprise: AISIA and SPRICO self hosted, with the third party AI vendor register. Pricing.

The bridge

SPRICO's controls cross walk to AISIA's control library on three keys: EU AI Act articles, NIST AI RMF subcategories and ISO 42001 clauses. A red team finding becomes a control effectiveness record, and a gap assessment report can cite the test that proved it.

Documents follow: gap assessment register, report and results deck against any of the three frameworks, model cards and system cards from the inventory, and the authored AIMS document set with SHA-256 integrity hashes.

Start with one AI system

Bring the use case you are least sure about. The demo ends with its disposition and the tests that support it.