AI Governance System of Record

A governance record for every AI system.

The risks each system carries, the measures in place, the evidence behind those decisions, and who reviewed them and when. All structured and linked in one place. Built on ISO/IEC 42001, the international standard for AI management systems.

14 days full access. No credit card required.

add_circle
Register AI System
Enter system name…
Select department…expand_more
Low
Medium
High
Critical
Register System

Built for the standards that matter

42001

ISO/IEC 42001

AI Management System

EU AI Act

AI Regulation Alignment

NIST

NIST AI RMF

AI Risk Management Framework

🇬🇧Data hosted in the United KingdomGDPR and UK Data Protection Act 2018 compliant

Three questions most organisations cannot answer.

01

What AI are we running?

There is no single register. The answer changes quarterly and nobody is updating it.

02

Who approved it and when?

If a regulator asks for the approval trail, most organisations would need weeks to reconstruct it.

03

What happens when it changes?

The vendor updates the model. Nobody reassessed. There is no mechanism that triggers it.

HumanWox builds the record that answers all three.

Every AI system registered, linked to risks, controls, evidence, and the full review history. When something changes, the system knows.

AI System Registry

Every AI system registered in one place. Each entry linked to its risks, controls, and evidence. When a system changes status, the platform recalculates what governance applies.

hub
AI System Registry
3 systems

Customer Support Chatbot

Customer Experience

Medium

Fraud Detection Engine

Risk & Compliance

High

Document Classifier

Legal Operations

Low

Implementation Tracker

See what has been done, what is in progress, and what has not started. Requirement by requirement. No reconstructing status from memory at review time. The implementation structure follows ISO/IEC 42001, the international standard for AI governance.

checklist
Implementation Progress
40%
check_circleClause 4: Context of the Organisation
Complete
check_circleClause 5: Leadership
Complete
pendingClause 6: Planning
In Progress
radio_button_uncheckedClause 7: Support
Not Started
radio_button_uncheckedClause 8: Operation
Not Started

Evidence Lifecycle

Every document versioned, reviewed on a set schedule, and approved by the right person. When a review date passes, the platform surfaces it before an auditor does.

folder_managed
Evidence Lifecycle
description

AI Risk Assessment v2.1

Uploaded 10 Mar 2026 by A. Patel

edit_noteDraft
calendar_todayNext review
10 Mar 2026
1
Draft
2
Under Review
3
Approved
JS

Approved by J. Smith

12 Mar 2026, 14:30

Issues Tracker

When something goes wrong, log it, assign it, track the resolution, and close it with a root cause on record.

bug_report
Issues Tracker
New

Model output drift detected

High
SC
Sarah Chen

Training data distribution shift following vendor model update on 15 Feb 2026.

scheduleResolution in progress
Due 28 Mar 2026

Readiness Reporting

A live view of where your governance stands based on actual coverage, not a status summary from last week.

monitoring
Readiness Report
ISO/IEC 42001
0%

Overall Readiness

Context of the Organisation92%
Leadership78%
Planning65%
Support45%

8

Complete

4

In Progress

3

Remaining

Audit Trail

Every action recorded. Every approval timestamped. When someone asks what happened, the answer already exists.

history
Audit Trail
calendar_todayToday
check_circle

Evidence approved

AI Risk Assessment v2.1

14:30
JS
J. Smith
rate_review

Evidence submitted for review

AI Risk Assessment v2.1

10:15
AP
A. Patel
upload_file

Evidence uploaded

Training Data Audit Report

09:45
MJ
M. Johnson
sync

AI system status changed

Fraud Detection Engine → Under Review

09:12
SY
System

Built on a compliance chain, not a document store.

Evidence cannot exist without being linked to what it governs. A control cannot be marked active without associated evidence. Gaps surface the moment they appear.

The structure follows ISO/IEC 42001: AI system to clause to control to evidence to review. Traceable in both directions.

ISO/IEC 42001EU AI ActNIST AI RMF
smart_toy
AI SystemRegistered & classified
gavel
ClauseObligation mapped
shield
ControlMeasure in place
description
EvidenceDocument linked
verified
ReviewApproved & timestamped
swap_vertTraceable in both directions

Who uses HumanWox

Compliance and Risk Leads

Your board asks whether you are governing your AI. Right now that answer takes weeks to assemble. HumanWox is the reason it takes minutes.

AI Project and Technical Leads

You built the system and assessed the risk. Six months later nobody can find the assessment. HumanWox keeps the record attached to the system, permanently.

Implementers and Consultants

Your clients need a platform that holds the record, not another spreadsheet you have to maintain for them.

Board and Senior Leadership

You need to know that your organisation can demonstrate how it governs its AI. HumanWox is that demonstration.

Straightforward Pricing for AI Governance

One plan. Full platform access. No feature gating.

Founding Member
£249/month

£2490/year (2 months free)

  • check_circleFull platform access
  • check_circleUnlimited AI systems
  • check_circleUnlimited evidence uploads
  • check_circleUnlimited team members
  • check_circleAudit package export

AI Add-on: £49/month

AI-assisted document review and evidence analysis.

Request Early Access

14 days full access. No credit card required.

Standard pricing from customer 101: £299/month or £2990/year.

Frequently Asked Questions

HumanWox is purpose-built for AI governance. Unlike generic GRC platforms designed to manage multiple compliance standards simultaneously, HumanWox is architected specifically around AI systems as the primary governance object. The data model enforces structured linkage between AI systems, risks, controls, evidence, and review activity. This is not a repurposed information security tool with an AI label applied to it.

ISO/IEC 42001 is the international standard for AI management systems, published by ISO and IEC. It provides a framework for organisations to establish, implement, maintain, and continually improve the responsible governance of AI. It follows the same management system structure as ISO 27001 (information security) and ISO 9001 (quality management). Certification is awarded by accredited certification bodies following a formal audit.

HumanWox provides the platform and implementation structure. Many organisations implement with a consultant and use HumanWox as the system of record throughout the process. Others use the built-in practitioner guidance to implement independently. The platform does not replace expert judgement where it is needed, but it significantly reduces the overhead of managing the implementation and maintaining governance post-certification.

Certification is not the finish line. Surveillance audits assess whether the management system has been maintained and improved between cycles. Evidence has a shelf life. Risk assessments go stale. New AI systems get deployed. HumanWox manages this ongoing lifecycle: evidence review schedules, obligation tracking, AI system change management, and readiness reporting for each surveillance audit.

No. HumanWox is a governance record, not a document generator. The platform stores, versions, links, and manages evidence that your organisation produces. The AI document review feature analyses uploaded evidence for quality and completeness, but it does not generate documents on your behalf. This is a deliberate design decision aligned with auditor expectations.

The EU AI Act establishes legal requirements for AI systems based on risk classification. ISO/IEC 42001 provides a management system framework that supports compliance with those requirements. Organisations using HumanWox to implement ISO 42001 are simultaneously building the governance infrastructure relevant to EU AI Act obligations. The platform is designed to extend to additional frameworks as regulatory requirements evolve.

Yes. All platform data is hosted in the United Kingdom.

The record your AI governance needs.

HumanWox is a system of record for AI systems. It maintains a structured, traceable account of each system's risks, controls, evidence, and review history.

14 days full access. No credit card. No sales call required.