Enterprise · 500+ employees

Portfolio governance, board-grade output.

One AI system is a project. Two hundred AI systems is a portfolio. Veritome gives compliance, risk and IT a single instrument for the whole estate — with the role-based access, audit trail and exports for your records and counsel that the board's audit committee asks for.

Talk to usSee pricing

No credit card · EU-hosted · 5-min

What we hear from groups

Three problems consultants don't solve.

Every business unit has its own list. We don't have one register.

Multi-org and multi-team support out of the box. One register at group level, segmented views per BU, with the same engine running underneath.

Our quarterly compliance update is a slide deck someone hand-makes.

The dashboard already has the numbers — portfolio % complete, by-tier averages, gate blockers, near-complete systems. Hand the screen to the board.

Audit asked for evidence per system per article. Nobody could produce it on the day.

Evidence attaches at obligation-item level, hash-sealed. The regulator-view dossier exports per system in a click; the public verify URL means auditors don't even need a login.
What changes at scale

Built for the 200-system estate, not the 2-system pilot.

Multi-org architecture

Group org with subsidiaries; each subsidiary keeps its own systems, classifications and obligations. Group-level rollups for the audit committee.

RBAC + SSO

Role-based access — compliance, risk, IT, business unit owner — with SAML / OIDC SSO. Permissions enforced at the API.

Phase gates across the portfolio

Six-phase compliance journey per system; the dashboard surfaces every system stuck behind a gate so the bottleneck is visible without spelunking.

Risk-tier weighted scoring

Portfolio score is risk-weighted, with a separate breakdown by tier. Prohibited systems zero the portfolio — there's no hiding behind a 92% average.

API access

REST API + webhooks for ServiceNow, Jira, GRC tools. Run Veritome alongside your existing instrument; share evidence both ways.

Audit trail you can subpoena

Every mutation logged with user, timestamp and before/after. Dossier hash chain is tamper-evident — chain breaks are surfaced, not hidden.

In practice

Three estates, three governance models.

USE CASE 01

A retail bank with 80 in-house AI models — provider for proprietary risk models, deployer for vendor systems.

  • Multi-org structure separates the in-house provider obligations from the vendor-deployer obligations.
  • The phase-gate dashboard surfaces 12 systems blocked at ASSESS — exactly where the conformity assessments are pending.
  • Each model's Annex IV doc auto-assembles from the model card + RiskPlan + governance plan.
  • Quarterly board pack is the dashboard's portfolio view, exported to PDF.
Veritome obligation workbench — engine-derived obligations across the six-phase journey, filterable by phase and system with per-item status
USE CASE 02

A multinational pharma group with 30 AI systems across R&D, clinical and commercial.

  • Annex III §5 (essential services) and §6 (law enforcement) systems trigger different obligation sets.
  • FRIA wizard runs for the public-impact systems; auto-skipped on the others.
  • Regulator-view dossier is the artefact the EMA + national authority both ask for; the public verify URL spares the audit team a dozen email threads.
  • AI literacy programme tracked org-wide for Art. 4 sign-off.
Veritome Annex IV technical-file builder — eleven sections assembled from live system data with a hash-sealed export
USE CASE 03

An insurance group consolidating risk management, GDPR and AI Act compliance into one instrument.

  • AI Act RiskPlan integrates with the existing enterprise RiskRegister via the API.
  • Art. 9 residual sign-off feeds the Solvency II ORSA narrative — same evidence, two regulations.
  • GPAI obligations on internally fine-tuned models tracked separately from third-party deployments.
  • AI literacy programme distributed across the group; per-subsidiary completion %.
Veritome AI literacy — six role-based training programmes with an organisation literacy score and per-person completion tracking for Article 4
What enterprises lean on

The capabilities that scale with the estate.