Start free inventory

Explainable triage, never automatic compliance.

HowAISafe prioritizes governance work from facts the operator declares. It does not infer legality, certify a management system or replace qualified review.

What the score means

The four tiers—low, moderate, high and critical—represent internal governance priority. The deterministic rules consider data sensitivity, potential impact on people, customer exposure and autonomous action.

The score is designed to answer “what should we review first?”, not “is this lawful?”

What creates control work

Each system receives only applicable controls: ownership and purpose, vendor review, data handling, impact assessment, human oversight, transparency, monitoring and incident response.

A control remains Missing until a person adds evidence. Accepted means an accountable reviewer accepted the submitted evidence; it does not mean external certification.

Jurisdiction handling

Country and impact fields create review flags. They do not determine regulatory scope automatically because organizational role, sector, deployment context and current law matter.

Every system and control stores its ruleset version. Future rule changes require an explicit reassessment rather than silently rewriting historical decisions.

Evidence integrity

System, control, membership and evidence changes write tenant-scoped audit events in the same database transaction as the state change. Raw secrets should never be entered as evidence notes.

Restricted file types are hashed, versioned and served download-only. Strict review can require a different user to accept submitted evidence. Automated malware scanning, SSO and SCIM are not connected.

Authoritative reference layer

Ruleset 2026.09.1 uses high-level mappings only. Detailed legal obligations and licensed standard text are deliberately excluded.

NIST AI Risk Management Framework ISO/IEC 42001 overview European Commission AI Act overview
Open governance workspace →Back to HowAISafe