AI Sigil is a software-as-a-service governance, risk, and compliance platform built to help organizations manage the regulatory obligations attached to the AI systems they build or deploy. It is designed for legal, compliance, risk, and AI development teams to work from the same underlying system records.
Key features and functions include:
AI System Registry
Organizations register each AI system along with its components: models, datasets, interfaces, use cases, and the actions the system can take. Shared components, such as a model used across several systems, are maintained as single records so that updates and risk assessments propagate to every system relying on them.
Framework Activation and Obligation Mapping
Each registered system is classified by purpose, deployment context, autonomy, and the markets it operates in. From that profile, the platform determines applicable obligations, distinguishing provider duties from deployer duties and scaling them to the system's risk tier. Obligations are re-derived automatically when a system's profile changes.
Controls, Evaluations, and Evidence
Obligations resolve into a library of controls, each carrying a pre-built evaluation form, defined evidence requirements, and a citation to the specific legal provision it derives from. Answers and attached evidence are retained with version history to support later review.
Vendor and Third-Party Assessment
Assessments can be routed to internal system owners or to external parties, such as model vendors and suppliers, through a secure link that does not require the recipient to hold an account, bringing third-party due diligence into the same evidence trail.
Reporting
The platform can generate a report assembled from stored answers and evidence for regulator-facing use, and system data can be snapshotted to preserve a compliance position at a given point in time.
Regulatory Coverage
The EU AI Act is modeled in full, with separate provider and deployer obligation sets. Dedicated ISO/IEC 42001 and NIST AI RMF modules are listed on the vendor's site as forthcoming additions to the framework library, not yet available.
Deployment and Security
Delivered as SaaS and hosted in the European Union. The vendor states the platform is GDPR-compliant, with tenant data isolated at the row level in the database, encryption at rest, role-based access control, and single sign-on support. Programmatic access is available through a REST API.
Loading...