AI governance software for ISO 42001, NIST AI RMF and the EU AI Act
Run ISO 42001, NIST AI RMF, and EU AI Act programmes from one auditable workspace — AI risk assessments, system impact assessments, technical documentation, and conformity evidence.
Free to start, no card · see pricing
What AI Governance requires
Three different instruments answer related questions about AI governance: ISO 42001 (the certifiable AI management system), NIST AI RMF (the US voluntary risk-management playbook), and the EU AI Act (binding EU law applying in phases through 2027). Mature programmes use all three — 42001 for the AIMS scaffolding, RMF for risk artefacts, the Act for conformity. They share evidence; you collect it once and present it three ways.
One workspace for all three AI programmes
SentinelPanda treats AI governance as a single problem with three different audit posters. Build your AIMS to ISO 42001, attach the same risk assessments and impact assessments to a NIST AI RMF Map and Measure profile, and present the technical documentation the EU AI Act expects of high-risk providers. Cross-framework mapping means evidence captured for one shows up in the other two without re-keying.
AI risk and impact assessments, kept defensible
AI risk assessments and AI system impact assessments are the load-bearing artefacts of an AI programme. SentinelPanda captures both as structured, reviewable records linked to the AI systems and controls they govern, and versioned across the model lifecycle. The same record satisfies the ISO 42001 Annex A.5 impact-assessment control, the NIST RMF Map function, and the EU AI Act FRIA for deployers in scope.
Tracks the EU AI Act's phased application
The AI Act lands in phases — prohibited practices and AI literacy in February 2025, GPAI and governance in August 2025, most provisions in August 2026, legacy high-risk systems by August 2027. SentinelPanda tracks each phase against your AI systems so you know which obligations apply when, which harmonised standards have been published in the Official Journal, and where you still owe conformity work.
Your ISO 42001 certification auditor joins the workspace
ISO 42001 is a certifiable standard. When you go for accredited certification, the audit team from your certification body needs visibility into your AIMS evidence, your AI system impact assessments, and your nonconformity records. SentinelPanda invites them in as auditor-layer seats inside your tenant — read access to the controls and evidence, approval rights on the workflow, and every action recorded to the HMAC-signed audit log. Nothing is exported, screen-shared, or re-keyed. The same model applies to your NIST AI RMF assessor and the EU AI Act notified body where applicable.
How SentinelPanda helps
Further reading
Practitioner-level guides on AI Governance from the SentinelPanda team.
AI Governance — frequently asked questions
Which AI standards does SentinelPanda support?
ISO 42001:2023 (full AIMS — clauses 4–10 plus the 38 Annex A controls), the NIST AI Risk Management Framework 1.0 (Govern, Map, Measure, Manage), and EU AI Act conformity records including the FRIA, technical documentation, and post-market monitoring.
Do I need all three?
Most teams do not need all three on day one. ISO 42001 is the natural backbone if you already run an ISMS to ISO 27001. NIST AI RMF helps for US enterprise and federal procurement language. The EU AI Act is mandatory if you place AI systems on the EU market or your output is used there.
Can existing ISO 27001 evidence count toward ISO 42001?
Yes — they share the Annex SL structure and many controls overlap (information security in the AI lifecycle, data governance, supplier management, incident response). Cross-framework mapping credits the shared evidence automatically.
How does this differ from a generic GRC tool that bolts on AI?
AI governance is a different discipline, not a checkbox on top of an ISMS. The artefacts (AI risk register, AI system impact assessment, training-data provenance records, post-market monitoring) need their own data model. SentinelPanda treats AI as a first-class scope, not an afterthought.
Can my external certification auditor see the workspace?
Yes. ISO 42001 certification involves audit teams from your accredited certification body; NIST AI RMF assessments often involve a third-party assessor; the EU AI Act notified-body conformity assessment for high-risk systems involves their auditors. All three audiences get auditor-layer seats inside your tenant on the Growth and Enterprise tiers — read access to the evidence, approval rights on the workflow, and an audit log of every action. No exports, no screen shares, no separate copies.
Does it help with the EU AI Act phased dates?
Yes — the AI Act applies in phases through 2 August 2027. SentinelPanda tracks each phase against your in-scope AI systems and surfaces what obligations apply when, including the prohibited-practices ban (in force since Feb 2025), GPAI obligations (Aug 2025), the main applicability date (Aug 2026), and legacy high-risk systems (Aug 2027).