Govern the AI you use, and the AI your suppliers use
High-risk obligations under the EU AI Act apply from 2 August 2026. Altisium keeps the inventory, the assessments, the incident queue and the control evidence in the same place as your supplier risk, because most AI exposure arrives through a third party.
EU AI Act
AI system inventory
Every AI system you build, buy or embed, classified by role and risk tier.
Article 27 FRIA
A guided fundamental rights impact assessment with the record kept against the system.
Article 73 incident queue
Serious incidents logged, triaged and tracked against the notification clock.
Training and deployer logs
Who was trained, what was logged, and the evidence behind both.
Subject information requests
Requests from affected people captured and answered on a trail.
ISO/IEC 42001
Annex A statement of applicability
All 38 reference controls with status, justification, evidence reference and owner.
AIMS clause self-assessment
Clauses 4 to 10 assessed, with the gaps visible rather than averaged away.
NIST AI RMF 1.0
Maturity register
GOVERN, MAP, MEASURE and MANAGE scored across the subcategory set on a maturity scale.
AI vendor risk
Supplier AI exposure
Which suppliers process your data with AI, under what terms, and what they will confirm in writing.
Work out what the AI Act actually asks of you.
A session on your own AI inventory and where the obligations land.
