Your AI models need compliance proof, not more checklists

SecureGRC verifies your AI models against ISO 42001, generates a complete inventory, and signs every artifact with quantum-safe cryptography.

ISO 42001 · 36 Annex A controls FIPS 204 · CRYSTALS-Dilithium FIPS 202 · SHA-3 verification MITRE ATLAS · 13 threat vectors UK patent filed
app.securegrc.io
Dashboard
Models
Threats
Compliance
Remediation
Evidence
Questionnaire
Audit Trail

google-bert/bert-base-uncased

83.3% Compliance · Compliant

Controls (25/30)

A.6.2.2 Risk ID ✓
A.6.2.3 Inventory ✓
A.7.3 Provenance ✓
A.8.4 Audit trail ✓
A.8.2 User info ✗
A.6.2.5 Objectives ✗

Active threats

T01 Prompt injection T02 Data poisoning T06 Supply chain T07 Bias T12 Regulatory T13 Quantum
The problem

Compliance tools manage paperwork. They don't verify your models.

Vanta, Drata, and OneTrust handle IT compliance well. But ISO 42001 has 36 AI-specific controls that require model-level data no existing platform collects.

Every model treated the same

A text-generation model faces prompt injection. An image classifier doesn't. If your compliance tool can't tell the difference, your risk assessment is wrong.

No model inventory

ISO 42001 requires a documented inventory of every AI system. Most companies can't list what models they run, let alone their training data, dependencies, and lineage.

Evidence won't last

Every compliance artifact signed with RSA or ECDSA today becomes unverifiable when quantum computers arrive. Your audit trail has an expiry date.

6-18mo
To certify ISO 42001 manually
£650K
Enterprise assessment cost
Aug '26
EU AI Act deadline
~50
Companies ISO 42001 certified
AI trust infrastructure

Three pillars. One trust layer.

SecureGRC doesn't manage paperwork. It verifies your actual AI models and creates a cryptographic chain of trust.

T

Transparency — ML-BOM

Automated 67-field inventory of every AI model. Identity, architecture, training data lineage, framework dependencies, and known vulnerabilities. The ingredients label for AI.

V

Verification — TCCE Engine

13 threat vectors mapped to exact ISO 42001 Annex A controls with task-aware filtering. Different model types get different assessments. Every weight has documented rationale.

C

Continuity — Quantum-safe

Every artifact signed with FIPS 204 (CRYSTALS-Dilithium) and anchored in a FIPS 202 (SHA-3) Merkle tree. Evidence remains independently verifiable for decades.

How it works

From model to signed compliance proof.

No access to model weights or production environment. Metadata only. Approved in one security review.

01

Connect your AI models

Point at HuggingFace, SageMaker, or provide model details directly. We extract metadata only — your weights, training data, and IP never enter our system.

02

Automated threat and compliance assessment

The TCCE engine identifies AI-specific risks with task-aware filtering, maps to 36 ISO 42001 Annex A controls, and produces a four-dimension risk score.

03

Quantum-safe cryptographic signing

Every artifact — ML-BOM, compliance report, evidence record — is signed with CRYSTALS-Dilithium and anchored in a Merkle provenance tree.

04

Enforce, report, remediate

CI/CD enforcement gate blocks non-compliant models. Auditor-ready PDFs generated automatically. Prioritised remediation plans with ISO 42001 templates.

Why SecureGRC

Built for AI models. Not bolted onto IT compliance.

CapabilitySecureGRCVantaDrataCredo AI
ISO 42001 Annex A model-level assessment36 controlsProgramme onlyGovernance only
Post-quantum cryptographic signaturesFIPS 204
Automated AI model inventory (ML-BOM)67-fieldManual
No access to model weights or IPMetadata-onlyAgent-basedAgent-basedVaries
Task-aware threat intelligenceMITRE ATLASGeneric
CI/CD deployment enforcement7 policies
Recognition

In the press.

Get started

Find out what's actually in your AI models.

Free compliance assessment. We'll analyse your AI models and show you the gaps. No model access required.