Regulatory compliance and transparency
The published privacy policy does not describe the AI assistant, creating a blocker for screening decisions.
AIQURIS · The AI Lifecycle Management Platform
AI is moving faster than organisations can control it.
AIQURIS works out the risks, requirements and controls of every AI deployment, tracks whether they are in place, and keeps them current. So AI deployments go live faster, with a clear basis for every decision.
From one deployment to your entire AI portfolio. For SMEs and enterprises alike.
WorkspaceILLUSTRATIVEEvery deployment, with its risk, its status and what needs attention.
| Deployment | Owner | IMPACT+ | RISK+ | Status | Next action |
|---|---|---|---|---|---|
| Visual defect inspectionComputer vision · AI-024 | Manufacturing quality | Moderate | Moderate | Review due | Review changed contextDue 6 Oct · context change recorded |
| Candidate screening assistant ↗Decision support · AI-031 | Talent acquisition | Major | Critical | In assessment | Provide control evidenceDue 29 Sept · 24 required actions open |
| Credit origination affordability assistantDecision support · AI-009 | Risk and lending | Major | Critical | Reassessment | Provide testing evidenceDue 4 Oct · 3 controls open |
| Grid load forecastingPredictive AI · AI-052 | Network operations | Moderate | Moderate | In operation | Review on material changeCondition-based · last assessed 8 Aug |
| Contract summarisation copilotGenerative AI · AI-066 | Legal and compliance | Pending | Pending | Awaiting triage | Complete IMPACT+ triageRegistered 9 Sept |
| Internal knowledge chatbotGenerative AI · AI-018 | IT and operations | Minor | Not required | In operation | Scheduled reviewDue 15 Nov |
No sample deployments match your search.
Every deployment in one AI register, with its risk, its status and what needs attention. Control, deployment by deployment. Visibility across all of them.
The challenge
Deployments still stall in pilot, or go live with unmanaged risk.
Set requirements for AI in general. They don't say what a deployment needs, or whether it is in place.
A snapshot. Only one of many controls a deployment needs.
Covers selected aspects, after the fact. Shows what happens, not what should be controlled.
Manual and person-dependent. They don't scale, and go out of date when a deployment changes.
None of them works out what each deployment needs, or keeps it current.
It works out what your specific deployment needs, maps it against what you already do, and shows what's missing, at every stage of the AI lifecycle.
Because it starts from the risks of the actual deployment, it is:
Decide with confidence. Defend with evidence.
Why it is hard
AI risk is hard to tell. It cuts across disciplines, differs by deployment and changes over time, and the controls differ with it. Below, one system in four sectors: same technology, four different risk profiles.
| Risk domain | Financial servicesAdvisers answering client product questions | HealthcareClinicians checking treatment guidelines | Defence & critical infrastructureControl-room operators querying operating procedures | ManufacturingTechnicians querying machine maintenance manuals |
|---|---|---|---|---|
| Safety | Negligible | Critical | High | Critical |
| Security | High | High | Critical | Moderate |
| Performance | Moderate | High | High | High |
| Legal compliance | Critical | High | High | Moderate |
| Ethics | Moderate | High | Moderate | Low |
| Sustainability | Low | Low | Low | Low |
| Deepest controls on | Legal compliance | Safety | Security | Safety |
Deepest controls on Legal compliance
Deepest controls on Safety
Deepest controls on Security
Deepest controls on Safety
So risks and controls have to be worked out deployment by deployment, and updated whenever something changes.
How it works
A guided intake captures everything that matters about your deployment. The engine then applies the standards, regulations and policies AIQURIS maintains, and works out the risks, requirements and controls it needs to be safe, perform and comply.

Every control is linked to its source and to the evidence it requires.
The missing link
Governance sets the rules. Teams build and run the deployments. Legal, cybersecurity, risk and the business each see one part. AIQURIS sits in between and connects them all: which rules apply to each deployment, where it stands, and who acts next.
How the engine worksIt doesn't add to your stack. It connects it.
Example
One real deployment, traced from risk to evidence. AIQURIS assessed a candidate screening assistant before its recruitment pilot went live.
Protected attributes or proxy signals could unfairly exclude candidates from progressing.
Protected attributes must not influence results.
Human review before any rejection. Testing that protected and proxy attributes do not affect scores.
Test results against defined thresholds. Review records showing that people made the decisions.
The published privacy policy does not describe the AI assistant, creating a blocker for screening decisions.
Interface defaults, hidden filtering or cut-offs could turn decision support into automated exclusion.
Ambiguous criteria and extraction errors could produce unreliable scores and ranking errors.
Applicant data in prompts, responses and logs requires verified minimisation, retention and vendor controls.
RECOMMENDATIONProvide evidence for the critical controls before go-live.
DECISIONTalent acquisition held the pilot until the evidence is in.
Summarised from an AIQURIS assessment of a real deployment. Ratings are before mitigation (inherent risk).
Know the risks, and exactly what to do, before go-live.
Lifecycle
One connected record across the deployment's life, shared by every function involved. When the deployment or its governing sources change, requirements, controls and evidence are updated together.
EXAMPLE The approved job criteria changed after go-live. Requirements reassessed, controls reopened, evidence updated, decision on continued operation updated.
Every product includes reassessments. CONTROL+ adds defined change triggers.
The deployment changes. The controls keep up.
Products
One platform, three levels of depth. Start with IMPACT+ and go deeper only where the risk calls for it, so effort and cost match the deployment.
Who could be harmed, and how badly.
YOU RECEIVEHow the harm could occur, and which controls address it.
EVERYTHING IN IMPACT+, PLUSAI Assurance: the controls in detail, the remaining risk, the evidence.
EVERYTHING IN RISK+, PLUSNo AI governance team needed. Start with one deployment and pay per deployment.
One AI register for the whole portfolio. CONTROL+ where the risk calls for it, with expert-supported setup.
The higher the stakes, the deeper the control.

Why AIQURIS
AIQURIS was founded by Dr Andreas Hauser and Dr Martin Saerbeck. Engineering, certification, digital systems and mathematical modelling, now applied to AI. Seven years developing the AIQURIS methodology, the early years within TÜV SÜD’s global AI quality practice. AIQURIS is independent.
Selected standards contributed to. Meet the founders and explore their standards work ↗
“The solution AIQURIS presented is the first I know of in the market that closes the gap by combining AI risk management and requirements from technical standards in a tool-based way.”
Expert knowledge, applied automatically to every deployment.


IMDA Spark Company · AI Verify Foundation member
The team sits on the committees that write the AI standards.
FAQ
Straight answers to the questions we hear most in client conversations.
AIQURIS applies a structured, risk-based method grounded in established risk engineering, the same way for every deployment.
It starts with the stakeholders and potential impacts, links them to hazards and risks, identifies the regulations, standards and other governing sources that apply, and derives the requirements and the controls that meet them. It is not a black-box LLM producing an answer: the method runs on a structured knowledge graph and ontology, so every requirement can be traced back to its source, its risk and its control.
The result is only as good as the description of the deployment, which is why AIQURIS guides that step closely.
How the engine worksNo. A questionnaire starts with fixed questions. AIQURIS starts with the deployment: its use case, context, risks and applicable requirements.
The questions that go to a vendor or an internal team are generated from that analysis, so an HR screening tool and a medical AI system get very different questions. Generic procurement and governance questionnaires do not make that distinction at deployment level.
It stays current. Every AIQURIS assessment includes 12 months of platform access, during which the deployment is reassessed when something material changes.
There are three triggers: changes to the regulations or standards that apply (AIQURIS tracks them and can alert you); changes to the deployment itself, such as its use, data or context; and material changes by the AI vendor, such as a new model or new capabilities.
This is triggered reassessment across the AI lifecycle, not real-time monitoring. Where continuous monitoring is needed, for example of bias, a specialist tool can do that, and the assessment shows where it is needed.
See the lifecycleHours or days, not months.
A traditional expert assessment of a single AI deployment typically takes three to nine months. With AIQURIS, IMPACT+ and RISK+ take a few hours, and CONTROL+ a few days. The AI Deployment Assessment Sprint takes one real deployment through an assessment within three weeks, with five hours of your team's time.
About the SprintAI lifecycle management keeps each AI deployment under control, from first idea to retirement.
The risk comes from the deployment: what the AI is used for, where, by whom and with which data. The hazards behind that risk can arise at any point in the AI lifecycle, from data and training to integration, operation and change. So the controls that address them have to be established along the whole lifecycle, not just checked once at go-live.
AI lifecycle management works out the risks, requirements and controls for each deployment, tracks whether the controls are in place at every stage, and keeps them current as the deployment, the regulations or the technology change. AIQURIS is the platform for it.
Start with IMPACT+. The deployment's impact and risk decide how deep you need to go.
IMPACT+ screens the deployment: who could be harmed, and how badly. It sets an impact tier and routes you to limited follow-up or to RISK+. RISK+ builds the risk profile across all six risk domains, with the applicable requirements and high-level controls as a checklist, and recommends whether to proceed or move to CONTROL+. CONTROL+ goes clause by clause through the relevant standards, regulations and your own policies, specifies the controls in detail and determines the remaining risk against your risk appetite.
CONTROL+ is not only for high-risk deployments: use it wherever you need that depth. Not sure where to start? The AI Deployment Assessment Sprint is the guided way in.
See the productsAny AI deployment, whether you build it or buy it.
This includes, for example, predictive and machine-learning systems, computer vision, generative AI such as chatbots, copilots and assistants built on large language models, and agentic AI. It covers systems developed in-house as well as AI bought from vendors; for bought AI, the vendor is part of the assessment.
What matters is not the technology but the deployment: the same model can carry very different risks in different uses. Deployments where AI controls safety-relevant hardware are scoped individually in a first call.
ISO/IEC 42001 certifies your AI management system. AIQURIS makes it concrete for each AI deployment, and that makes certification much easier to prepare.
ISO/IEC 42001 requires organisations to assess the risks and impacts of their AI systems and to establish controls across the AI lifecycle. AIQURIS does exactly that, deployment by deployment, and produces the documented, traceable basis an auditor expects to see.
It also shows which requirements of the standard your organisation actually needs, and in what depth, given the AI deployments it really has. That puts your management system and its Statement of Applicability on a factual basis, instead of implementing everything just in case.
AIQURIS is not a certification body: its outputs support a certification audit but do not determine its outcome. The AIQURIS founders were actively involved in developing ISO/IEC 42001.
Yes. For every deployment in the EU, AIQURIS works out which EU AI Act obligations apply and whether they are met.
What the AI is used for, and in which context, sets its risk classification under the Act, and with it obligations such as human oversight, transparency, data governance and record-keeping. AIQURIS turns them into requirements, links them to the controls that meet them and records the evidence, in the same assessment as data protection law and the other sources that apply.
The AIQURIS team sits on the committees that write the standards, so it knows the harmonised standards being developed for the EU AI Act and how to interpret them. AIQURIS does not give legal advice, and the decision stays with you.
The ones that apply to your deployment, worked out for its use and its jurisdiction.
AIQURIS maintains the governing sources for you: regulations such as the EU AI Act and data protection law, international standards such as ISO/IEC 42001, ISO/IEC 25059 and ISO/IEC 5259, industry frameworks, and your own internal policies where relevant.
Singapore, the EU, the UK, Australia and the US are covered as standard. Other jurisdictions are available on request.
AIQURIS does not replace your GRC platform; it feeds it. It provides the deployment-specific AI risks, requirements and controls that a general governance, risk and compliance environment usually does not contain.
The results can be mapped into the structure you already use, from an Excel control register to an enterprise GRC system. AIQURIS is API-based, so outputs can be integrated directly, subject to your required format and your GRC provider allowing the integration. The aim is not a parallel AI risk process, but AI-specific detail inside the risk and control environment you already run.
It looks at two things: the AI solution and how the vendor develops and governs it.
For the solution, AIQURIS asks for evidence matched to the identified risks, such as accuracy, robustness or penetration test results, or data-quality evidence. For the vendor, it covers development processes, training data, data governance and organisational controls.
Vendors do not just answer yes or no. Where it matters, they must provide reports, test results or certifications. Missing evidence is never treated as a requirement met: less transparency means more uncertainty, a potentially higher assessed risk and additional controls. Material vendor statements should then be reflected in the contract, so the vendor is accountable for them.
No. AIQURIS determines which testing a deployment actually needs.
The sequence is the same as in security: first establish what can go wrong and which requirements apply, then decide on the controls. Those controls may include penetration testing, robustness testing, data-quality testing or other technical validation. Testing without that step risks being arbitrary: you test what is easy to test, not what matters. Where your risk appetite calls for independent testing in a particular area, it becomes one of the required controls.
In two steps. First, AIQURIS identifies which regulatory, cybersecurity and standards documents apply to the deployment and its jurisdiction, drawing on its regulatory knowledge, research and external sources where appropriate.
Second, those documents go through the same method as every other governing source and are translated into deployment-specific requirements and controls. Cybersecurity is therefore not a separate exercise but part of the same structured assessment, alongside the other five risk domains.
Your organisation. AIQURIS gives you a documented, traceable basis for the decision, but the decision to deploy, and to accept the remaining (residual) risk, stays with you.
Because the method is standards-based, repeatable and recorded, the assessment also shows which method and state-of-the-art practices were applied at the time. That helps you demonstrate due diligence later, to auditors, regulators or your board.
No. AIQURIS does not give legal advice. It carries out a compliance assessment: it identifies which regulatory requirements apply to a specific AI deployment and assesses whether they are met.
A lawyer interprets the law. AIQURIS translates the applicable requirements into concrete requirements and controls for that deployment, much as technical certification does for products. The advantage over a purely manual approach is consistency: two consultants may assess the same deployment differently, while AIQURIS applies the same method and the same six risk domains every time. Your legal and compliance teams stay in charge, with a structured basis to work from.
A description of the deployment. Access to the AI system itself is only needed where the assessment calls for it.
AIQURIS needs to understand the deployment: its purpose, users, data categories, jurisdiction, the system and vendor, and the controls already in place. The assessment does not need access to the AI system, your models or your production data. Access only becomes relevant once a specific requirement calls for it, for example a penetration test or a monitoring solution, and then only for that purpose. Where evidence is needed, such as test reports, you share the documents.
All information is protected and encrypted in line with current best practice. If it must not leave your own environment, AIQURIS can run inside it.
Yes. The AIQURIS platform is containerised and can run in any environment, including your own cloud or on your premises.
The language model component can run inside it too, as a containerised model, where one is available and accepted by your organisation. Deployment information, source documents and results then stay inside your perimeter.
No black box. A traceable basis for every decision.
Get started
The AI Deployment Assessment Sprint is guided by AIQURIS from start to finish. We prepare the assessment; your team gives five hours across three sessions. Within three weeks, you have one real deployment assessed at RISK+ depth, and actions with named owners.
Choose a deployment, in planning or already in production. AIQURIS then screens its impact and prepares the risk profile, requirements and controls.
The accountable stakeholders in the room. Validate the risks, challenge the controls, agree what closes the gaps.
Leave with an assessment record and an action list with named owners. Run the next deployments yourself on the platform.
Questions first? Contact info@aiquris.com
From one deployment to your entire AI portfolio.
Dashboard and lifecycle views are illustrative.