Three problems consultants don't solve.
“Every business unit has its own list. We don't have one register.”
“Our quarterly compliance update is a slide deck someone hand-makes.”
“Audit asked for evidence per system per article. Nobody could produce it on the day.”
Built for the 200-system estate, not the 2-system pilot.
Multi-org architecture
Group org with subsidiaries; each subsidiary keeps its own systems, classifications and obligations. Group-level rollups for the audit committee.
RBAC + SSO
Role-based access — compliance, risk, IT, business unit owner — with SAML / OIDC SSO. Permissions enforced at the API.
Phase gates across the portfolio
Six-phase compliance journey per system; the dashboard surfaces every system stuck behind a gate so the bottleneck is visible without spelunking.
Risk-tier weighted scoring
Portfolio score is risk-weighted, with a separate breakdown by tier. Prohibited systems zero the portfolio — there's no hiding behind a 92% average.
API access
REST API + webhooks for ServiceNow, Jira, GRC tools. Run Veritome alongside your existing instrument; share evidence both ways.
Audit trail you can subpoena
Every mutation logged with user, timestamp and before/after. Dossier hash chain is tamper-evident — chain breaks are surfaced, not hidden.
Three estates, three governance models.
A retail bank with 80 in-house AI models — provider for proprietary risk models, deployer for vendor systems.
- Multi-org structure separates the in-house provider obligations from the vendor-deployer obligations.
- The phase-gate dashboard surfaces 12 systems blocked at ASSESS — exactly where the conformity assessments are pending.
- Each model's Annex IV doc auto-assembles from the model card + RiskPlan + governance plan.
- Quarterly board pack is the dashboard's portfolio view, exported to PDF.
A multinational pharma group with 30 AI systems across R&D, clinical and commercial.
- Annex III §5 (essential services) and §6 (law enforcement) systems trigger different obligation sets.
- FRIA wizard runs for the public-impact systems; auto-skipped on the others.
- Regulator-view dossier is the artefact the EMA + national authority both ask for; the public verify URL spares the audit team a dozen email threads.
- AI literacy programme tracked org-wide for Art. 4 sign-off.
An insurance group consolidating risk management, GDPR and AI Act compliance into one instrument.
- AI Act RiskPlan integrates with the existing enterprise RiskRegister via the API.
- Art. 9 residual sign-off feeds the Solvency II ORSA narrative — same evidence, two regulations.
- GPAI obligations on internally fine-tuned models tracked separately from third-party deployments.
- AI literacy programme distributed across the group; per-subsidiary completion %.


