AI Compliance Assistant
TXAZ Accelerator Platform — cgdsn.cloud
AI Governance Copilot • Operational • Back to Platform
AI Governance Hub
Operational copilot answering the 8 core governance questions for your organization's AI usage.
0
AI Tools Tracked
0
Approved
0
Unapproved
0
Open Risks
0
Open Incidents
0
Policies
Question 1
What AI are we using?
0 tools
No AI assets registered yet.
Question 2
Who approved it?
0 approved
No approvals recorded.
Question 3
What data does it process?
0 documented
No data classifications recorded.
Question 4
What risks does it introduce?
0 risks
No risks logged.
Question 5
Which policies apply?
0 policies
No AI policies created.
Question 6
Are there unresolved remediation items?
0 open
No open remediation items.
Question 7
Aligned with compliance obligations?
--
Add assets to assess alignment.
Question 8
Evidence of responsible governance?
--
No evidence trail established yet.

🤖 AI Assistant Recommendations

No recommendations yet. Start by registering your AI tools in the Asset Registry.
AI Asset Registry
Discover and track all AI-enabled applications, services, models, and tools used in your organization.
NameTypeVendorOwnerDepartmentData ProcessedRiskApprovedActions
No AI assets registered. Click "Register AI Tool" to begin.
AI Risk Register
Track risks introduced by AI systems: data exposure, hallucination, prompt injection, model poisoning, and more.
TitleCategorySeverityLikelihoodOwnerStatusReview DateActions
No risks logged.
AI Policy Management
Create, version, approve, and track AI policies: Acceptable Use, Secure Prompting, Procurement, Data Handling, Governance Charter.
TitleTypeVersionStatusOwnerNext ReviewAcknowledgementsActions
No policies created yet.
AI Vendor Assessment
Assess each AI provider for SOC 2, ISO 27001, FedRAMP, data residency, model training policy, encryption, and assign a risk score.
VendorProductSOC 2ISO 27001FedRAMPData ResidencyRetentionRisk ScoreActions
No vendors assessed.
AI Data Classification Review
Determine whether AI tools interact with CUI, PII, PHI, PCI, IP, export-controlled data, or source code. Flag high-risk scenarios.

Data Classification by AI Tool

Register AI assets with data processing details to see classification analysis.

⚠ High-Risk Flags

No high-risk flags detected. Add AI tools with sensitive data classifications to surface risks.

AI Readiness Assessment
Questionnaire covering governance, security, privacy, legal, vendor management, human oversight, and monitoring. Generates maturity score and gap analysis.

Readiness Questionnaire

AI Compliance Mapping
Map AI governance practices to CMMC, NIST SP 800-171, NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894, and internal policies.
FrameworkControlRequirementAI Governance ActionStatus
CMMCAC.1.001Limit information system access to authorized usersMap AI tools to authorized user listsNot Assessed
CMMCAC.2.006Limit use of portable storage devicesRestrict AI tools accessing removable mediaNot Assessed
NIST 800-1713.1.1Limit access to authorized usersAI tool access controls documentedNot Assessed
NIST 800-1713.13.1Monitor and control communications at external boundariesAI API calls monitoredNot Assessed
NIST AI RMFGOVERN 1.1Policies, processes, and procedures for AI riskAI Governance Charter in placeNot Assessed
NIST AI RMFMAP 1.1Context established for AI risk identificationAI Risk Register maintainedNot Assessed
NIST AI RMFMEASURE 2.1AI risk metrics definedRisk scoring applied to AI assetsNot Assessed
NIST AI RMFMANAGE 1.1Responses to AI risks and benefitsMitigation plans documentedNot Assessed
ISO 420016.1Actions to address risks and opportunitiesAI risk assessment conductedNot Assessed
ISO 420017.5Documented information on AI managementPolicies and records maintainedNot Assessed
ISO 238944.1Understanding the organization and its context for AI riskAI inventory establishedNot Assessed
InternalAI-POL-001AI Acceptable Use PolicyPolicy created and acknowledgedNot Assessed
InternalAI-POL-002AI Data Handling StandardData classification review completedNot Assessed
Prompt Library
Approved organizational prompt repository. Track business purpose, data sensitivity, platform, owner, and approval status.
TitlePlatformOwnerData SensitivityApprovedReview DateActions
No prompts in library.
AI Incident Management
Capture AI-related incidents: data disclosure, hallucination impact, unauthorized use, prompt injection, API abuse, and model misuse.
TitleTypeSeverityReporterOwnerStatusDateActions
No incidents reported.
AI Procurement Workflow
Before adopting a new AI tool: complete risk questionnaire, vendor assessment, obtain approvals, document use, classify data, assign owner.
ToolRequestorDepartmentData ClassVendor AssessedLegalSecurityStatusActions
No procurement requests.
AI Training Tracker
Track completion of responsible AI use, prompt engineering, sensitive data protection, hallucination recognition, and organizational policy training.

Training Modules

ModuleStatusDue DateCompletionsActions
Responsible AI UseNot Started--0
Secure Prompting GuidelinesNot Started--0
Protecting CUI in AI SystemsNot Started--0
Recognizing AI HallucinationsNot Started--0
Copyright and IP ConsiderationsNot Started--0
Organizational AI PolicyNot Started--0
AI Incident ReportingNot Started--0
CMMC & AI ComplianceNot Started--0
AI Usage Analytics
Track most-used AI platforms, active users, departments, adoption trends, new tools detected, and inactive tools.
0
Total AI Tools
0
Approved
0
Shadow AI
0
Vendors

AI Tool Breakdown by Type

Register AI assets to see breakdown by type.

Top AI Tools by Risk

No data yet.