Skip to main content

The AIC platform

Your AI estate, kept on the record

One workspace for every AI system you run and the person who answers for it, the decisions those systems make, the frameworks you are held to, and the evidence your own systems already produce. AIC reads that evidence for you, every night, so the record stays current without anyone rebuilding it before an audit.

Tools on one side, the audit on the other

The platform is where you keep your record. Certification is an independent audit of it. Using the platform, or any tool in it, neither raises nor lowers your chance of being certified, and an assessor treats evidence the same way wherever it came from.

That separation is what lets AIC offer tools at all while staying impartial. It is set out in full in the impartiality statement.

AI overview

What you run, what it decided, and who answered for it.

Dashboard
Your AI exposure at a glance: systems, decisions, spend, and what needs you this week.
AI estate
Every AI system you run, what it is for, and the named person accountable for it.
Decision log
Decisions your systems record through the API, the ones a person overrode, and who made the call.
AI spend
What you spend on AI models, by provider, model and system, read from your provider accounts.
Continuity record
The standing record of your AI estate and every change to it, kept so it cannot be quietly rewritten.

Compliance tracking

The frameworks that apply to you, and the evidence against each requirement.

Frameworks
Choose which frameworks you track, from the list below, or add your own.
Controls
Each requirement, and the evidence behind it. Evidence is collected once and counts for every framework it supports.
Connected systems
AIC reads your systems every night with read-only access and records what changed.
Automated checks
What AIC found in your connected systems, why it matters, and the steps to fix it.
Evidence vault
The evidence you have filed, against the requirements for your Division.
Policies
Your policies, the version in force, and who has accepted it.
Policy against practice
Where what your policies promise and what your systems show disagree.
Incidents and findings
AI incidents and how each was resolved, and your assessor’s findings with your corrective actions.

20 frameworks to track

A mapping says this evidence usually supports this requirement. It is not an auditor's conclusion, and the platform shows plainly which requirements it does not cover.

  • POPIASouth Africa
  • EU AI ActEuropean Union
  • GDPREuropean Union
  • NIS2European Union
  • DORAEuropean Union
  • ISO/IEC 42001International
  • ISO/IEC 27001International
  • NIST AI RMFUnited States
  • NIST CSF 2.0United States
  • SOC 2United States
  • US Data PrivacyUnited States
  • HIPAAUnited States
  • HITRUST CSFUnited States
  • CRI ProfileFinancial sector
  • CMMC Level 1United States
  • FedRAMPUnited States
  • CJIS Security PolicyUnited States
  • Cyber EssentialsUnited Kingdom
  • Essential EightAustralia
  • CPS 234Australia

To see which apply where you operate, open a country on the regulatory map.

Systems AIC can read

Read-only, and you can remove AIC's access from your side at any time. A connector AIC has not yet seen working against a real client account is marked new in the platform until it has. How AIC handles access

AI providers
OpenAI, Anthropic
Code
GitHub, GitLab, Bitbucket, Snyk
Cloud
Amazon Web Services, Google Cloud, Microsoft Azure, Cloudflare, Datadog
Identity and passwords
Microsoft 365, Google Workspace, Okta, 1Password
Devices and security
Microsoft Intune, Jamf Pro, Kandji, CrowdStrike Falcon
People
BambooHR, HiBob, Personio, Deel, Rippling
Work and customers
Jira, Linear, Zendesk, Slack, Salesforce

Risk and people

What could go wrong, who holds your data, who has access, and who is trained.

Risk register
What could go wrong, how bad it would be and who owns it, with risks suggested from what your connected systems show.
Suppliers
Who holds your data or runs part of your service, their documents, and when you last checked them.
People
Joiners and leavers from your HR system, matched to the accounts they hold.
Access reviews
Confirm, person by person, who still needs each account.
Training
Security, POPIA and AI modules, and who has completed them.

AIC certification

Where you stand against the AIC standard, and what you can show others.

AIC Aware
Declare your AI awareness and hold a badge anyone can verify. Self-declared, and labelled as such.
Your certificate
Your current status, and what stands between you and the next stage.
Trust page
A public page for your customers, live from your record rather than written once and left.
Questionnaires
Answer a buyer’s security questionnaire from your record instead of from memory.
Correspondence
Messages with your assessor, kept on the record.

Agents, if you want them

Optional, and no bearing on certification.

You can run your own AI agents from the platform, with what each one may reach and spend fixed before it starts. An agent can only use the tools you give it, such as calls to the web addresses you allow, or one SharePoint site, library or folder, and every step it takes is checked against that scope and kept in a record that shows if anything was changed afterwards.

The agent is declared on your AI estate like any other system, with a named person accountable for it. Running agents through AIC is a convenience, not a route to certification, and choosing not to changes nothing.

Sharing with your insurer

On your terms, and only observations.

If your insurer asks, you can issue them a key from your workspace. With it they read an extract of your record: counts, coverage, rates and dates, each traceable to something on the record. It is built from the same source as your own overview, so what your insurer sees is never a different picture from the one you manage.

The extract carries no rating and no recommendation. Pricing and acceptance are the insurer's decisions, not AIC's. You can withdraw the key whenever you choose. What AIC offers insurers

Start with what you already run

Registration is a short form. A set-up guide then walks you through declaring your first system, connecting your first source of evidence and choosing the frameworks you track, pointing at each control as you go.

Register your organisation