FAQ

Frequently Asked Questions

Everything you need to know before we start working together.

We give regulated organisations one platform to design, govern and operate AI, regulatory compliance and fair conduct. Instead of separate tools for model risk, obligations and customer outcomes, everything runs off one governed record.

ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, POPIA and GDPR, alongside your own internal AI policies. Controls are mapped once and reused, so a single control test can satisfy obligations across several frameworks.

Know Your Agent is a live register of every AI system, model and agent in the business, with its purpose, owner, risk classification and control status. It carries each system through approval gates and into runtime monitoring.

AURA is the regulatory operating system: an automated regulatory universe, impact assessments, policy governance, an enterprise control library, regulatory reporting and a change management workstation.

Fair Conduct monitors customer outcomes continuously — that customers understand products, receive appropriate advice, are treated fairly and are protected from foreseeable harm. It includes the Consumer Trust Wallet, the consumer-facing trust layer.

Financial Services Providers, Accountable Institutions and other regulated organisations that must evidence how they govern AI, data and customer outcomes.

Yes. Deployment options are customer-hosted, Azure native, or multi-tenant SaaS. The platform is cloud agnostic and can run on Azure, AWS, Google Cloud or private cloud infrastructure.

No. AURA is built on a plug-and-play architecture that integrates with your existing RegTech ecosystem. You adopt further capabilities only as your governance needs evolve.

Trusted Regulatory Data maintains the underlying obligations and reference data as canonical, versioned datasets, so regulatory change flows through to your policies and controls rather than being tracked by hand.

Both. You can license the platform and run it yourself, or take it as GRC-as-a-Service, where our GRC Operational Centre operates the governance function alongside your team.

Cerebro builds the workforce capability to run governance. When regulation changes, it identifies capability gaps, assigns the required training and tracks organisational readiness.

With an AI and obligations inventory. From there we agree the control set, evidence model and reporting cadence: a structured path from inventory to continuous, evidenced compliance.