Scrutineer.ai

Scrutineer · By framework

AI governance tools, platform and software for ISO 42001

Two of the AI deadlines most US companies planned their 2026 around no longer exist. The Colorado AI Act was repealed before it took effect, and the EU high risk obligations were deferred by more than a year.

Scrutineer holds your AI inventory, model documentation and human oversight evidence once, then maps it to ISO 42001, the NIST AI RMF and the rules that did land on schedule.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with AI governance

Most AI governance content is describing a rulebook that changed

The two obligations that drove nearly every 2026 AI roadmap have both moved. Colorado repealed SB 24-205 outright and replaced it with SB 26-189, a narrower notice and rights framework for automated decision making that does not start until January 1, 2027, after a federal court had already stayed enforcement of the original in April 2026. In the EU, the Digital Omnibus entered into force on July 27, 2026 and pushed the standalone high risk obligations in Annex III from August 2, 2026 out to December 2, 2027, and the obligations for AI embedded in regulated products to August 2, 2028. Building an impact assessment program this quarter because Colorado required one is building for a law that no longer exists. Scrutineer tracks what each rule requires and when it actually binds, so scope follows the statute rather than last year commentary.

The date that did not move is the one nobody prepared for

Article 50 of the EU AI Act, the transparency duty, was deliberately left out of the deferral and applied on schedule on August 2, 2026. If your product runs a chatbot, generates synthetic text, images, audio or video, or uses emotion recognition, you owe disclosure to the people interacting with it, and the duty falls on deployers as well as providers. Systems that generate synthetic content and were already on the market before August 2, 2026 have until December 2, 2026 for the machine readable marking obligation, which is the only transitional runway in it. That is a live requirement for a US SaaS company with EU users right now, while the high risk paperwork everyone was worried about sits eighteen months out.

One AI control set, mapped to every framework that asks for it

ISO 42001 and the NIST AI RMF want the same underlying artifacts: an inventory of AI systems, documented purpose and limitations, data provenance, risk assessment, human oversight, monitoring and incident handling. So do the buyers sending you AI questions in a security questionnaire. Maintaining a separate binder for each is how AI governance turns into a documentation project with no operational value. Scrutineer maps a control once and shows every framework, statute and customer question it answers, so the marginal cost of the next standard is the delta rather than a fresh program. Scrutineer is readiness and decision support; an accredited certification body still issues an ISO 42001 certificate.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Keeps a live inventory of every AI system, model and third party AI feature in your product, which is the artifact every framework and questionnaire starts from
  • Maps each AI control once to ISO 42001 Annex A, the NIST AI RMF functions and the EU AI Act articles it satisfies
  • Tracks whether each rule is in force, deferred or repealed, so you scope against the current statute rather than superseded commentary
  • Separates your provider obligations from your deployer obligations, which is what decides how much of the EU AI Act reaches you
  • Flags Article 50 transparency exposure across chatbots, synthetic media and emotion recognition, including the deployer side duties
  • Records training data provenance and documented limitations, which California AB 2013 requires and enterprise buyers now ask for directly
  • Holds human oversight evidence, review logs and escalation paths rather than a policy that claims oversight exists
  • Answers the AI sections that now appear in inbound security questionnaires from the same evidence base as your SOC 2 and ISO 27001 work
  • Shows the delta when a new AI rule takes effect, instead of restarting the program each time a legislature moves
AI GOVERNANCE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Status reference

Which AI rules are actually in force for a US company today, and which ones moved

Almost every published AI governance table compares frameworks against each other, which tells you nothing about what you owe this quarter. The axis that decides your roadmap is status: in force, deferred, or repealed. Three rows here contradict guidance that is still widely republished. The Colorado AI Act was repealed rather than delayed, the EU high risk deadline moved by more than a year, and the one EU deadline that did land on August 2, 2026 is the transparency duty almost nobody scoped.

Rule or standard Status in August 2026 Who it reaches What it actually asks for Where teams get it wrong
EU AI Act Article 50, transparency In force. Applied August 2, 2026 and was deliberately excluded from the Digital Omnibus deferral. Providers and deployers of chatbots, synthetic content generators, emotion recognition and deepfake tools, including US companies whose systems reach EU users. Tell people when they are interacting with AI, disclose emotion recognition and biometric categorisation, and mark or disclose AI generated and manipulated content. Assuming the whole August 2026 deadline was cancelled. It was not. Only the high risk obligations moved, and the deployer side disclosure duty applied immediately.
EU AI Act Annex III, standalone high risk Deferred to December 2, 2027 by the Digital Omnibus, in force July 27, 2026. Providers and deployers of AI used in employment, credit, education, essential services and similar consequential decisions in the EU. Risk management system, data governance, technical documentation, logging, human oversight, accuracy and conformity assessment. Running a crash conformity assessment project this quarter. There is now more than a year of runway, and the standards it will be assessed against are still being finalised.
EU AI Act Annex I, product embedded high risk Deferred to August 2, 2028. AI built into products already covered by EU product safety law, such as medical devices and machinery. The high risk obligation set, folded into the existing product conformity route. Treating this as the same deadline as Annex III. It is two separate dates, twenty months apart.
Colorado AI Act, SB 24-205 Repealed. Replaced by SB 26-189, signed May 14, 2026, effective January 1, 2027. Nobody, in its original form. The replacement is a narrower notice and rights framework for automated decision making. The original demanded risk management programs, annual impact assessments and algorithmic discrimination duties. The replacement drops all three. Building an impact assessment program because a 2024 law required one. Enforcement was stayed in April 2026 and the statute was repealed in May 2026.
Texas TRAIGA, HB 149 In force since January 1, 2026. Anyone doing business in Texas, or developing, deploying or offering AI systems in Texas. Public entities carry heavier duties than private ones. Avoid specific discriminatory, harmful and manipulative uses, and keep documentation on data, limitations and performance. No mandated risk program for private business. Reading it as a Colorado style program mandate. It is intent based and narrower, and the Attorney General must give 60 days to cure before enforcing.
California AB 2013 and SB 942 Both in force. AB 2013 from January 1, 2026, SB 942 duties from August 2, 2026. AB 2013 reaches developers of generative AI made available in California. SB 942 reaches covered providers above one million monthly California users. AB 2013 requires published documentation of training data provenance. SB 942 requires AI content disclosure and a detection tool. Assuming California AI law means SB 53. SB 53 only reaches frontier developers above 10 to the 26th FLOPs and 500 million dollars of revenue, so it misses almost every SaaS company.
ISO 42001 and the NIST AI RMF Voluntary. Neither is required by any US law. Whoever your customers say. Both increasingly appear in enterprise vendor questionnaires and procurement checklists. ISO 42001 is a certifiable management system audited by an accredited body. The NIST AI RMF is a voluntary framework with no certificate. Waiting for a regulator. In this category the demand almost always arrives from a customer procurement team first.

Status verified against multiple independent legal sources in August 2026. AI legislation in this area has changed several times in twelve months, so confirm the current position before relying on any date, including these.

Good questions

Questions about AI governance

AI governance software holds your inventory of AI systems, model documentation, risk assessments, human oversight records and monitoring evidence in one place, then maps each control to the frameworks and laws it satisfies. The useful ones do scope work as well as control work: they tell you which AI rules actually bind your business before you spend a quarter building for all of them.
It depends on which job you have. Model evaluation and bias testing tools sit close to the data science workflow. Policy and inventory platforms sit close to the compliance team. Broad GRC suites add an AI module to an existing program. If your real driver is that customers are asking for ISO 42001 alignment and AI answers in security questionnaires, a platform that runs AI governance from the same evidence base as your other frameworks is the better fit than a standalone AI tool.
No US federal law and no US state law currently requires a private company to hold an AI governance certification or run a formal AI risk management program. Texas TRAIGA regulates specific harmful and discriminatory uses rather than mandating a program, and Colorado repealed the one state law that came closest before it took effect. What drives most adoption is customer procurement, not statute.
Yes, if you place an AI system on the EU market or the output of your system is used in the EU, regardless of where you are established. A US SaaS company with EU customers is generally in scope. What varies is how much reaches you: the transparency duties in Article 50 apply now, while the heavier high risk obligations were deferred to December 2027 and August 2028.
It applies in stages. Prohibited practices and AI literacy duties started February 2, 2025, general purpose AI model obligations on August 2, 2025, and the Article 50 transparency duties on August 2, 2026. The Digital Omnibus, in force July 27, 2026, moved standalone high risk obligations to December 2, 2027 and product embedded high risk AI to August 2, 2028.
Partly. The Digital Omnibus entered into force on July 27, 2026 and deferred the high risk obligations: Annex III standalone systems to December 2, 2027 and Annex I product embedded systems to August 2, 2028. The Article 50 transparency obligations were deliberately excluded from that deferral and took effect as originally scheduled on August 2, 2026.
It was repealed before it ever applied. Colorado first postponed SB 24-205 from February 1, 2026 to June 30, 2026, a federal magistrate stayed enforcement on April 27, 2026, and on May 14, 2026 the governor signed SB 26-189, which repeals the original and replaces it with a narrower disclosure and rights framework for automated decision making technology effective January 1, 2027.
It applies broadly to anyone doing business in Texas or developing, deploying or offering AI systems in Texas, and it took effect January 1, 2026. In practice its private sector duties are narrow: it targets specific discriminatory, harmful and manipulative uses rather than requiring a documented risk management program. The Texas Attorney General has exclusive enforcement authority and must give notice and a 60 day cure period first.
You can easily be both, and this is where scoping goes wrong most often. Teams that embed a third party model assume they are only a deployer, but putting your own name on the system, changing its intended purpose or substantially modifying it can make you a provider under the EU AI Act, which carries a much heavier obligation set. Texas TRAIGA sidesteps the distinction entirely by reaching anyone who develops, deploys or offers AI in the state.
ISO/IEC 42001 is the international management system standard for artificial intelligence. It specifies how to run the organizational system around AI, covering policy, roles, risk and impact assessment, lifecycle controls, supplier management and continual improvement. It is certifiable by an accredited body, which is why it is the AI credential most often named in enterprise procurement.
ISO 42001 is a certifiable management system standard with auditable requirements, so it produces a certificate a customer can ask for. The NIST AI Risk Management Framework is a voluntary US framework organized around four functions, govern, map, measure and manage, with no certification and no accredited audit. They overlap heavily on substance, so most of the evidence you gather for one carries over to the other.
No law requires it. It is becoming a commercial requirement rather than a legal one, appearing in enterprise vendor questionnaires and procurement checklists the same way SOC 2 did a decade ago. If your buyers are large enterprises in regulated industries, expect the question before you expect a regulator.
AI governance is the internal system that decides how AI gets built, bought and used in your organization: who approves it, what gets documented, how risk is assessed and who reviews the output. AI compliance is the narrower question of which of those practices a law, standard or contract actually obliges you to have. Governance is the program, compliance is the subset someone can hold you to.
Data governance covers how data is classified, stored, accessed and retained. AI governance covers what happens when that data is used to train or operate a model: intended purpose, documented limitations, evaluation, human oversight and monitoring for drift once it is live. They share the inventory and lineage work, and the AI questions in a security questionnaire assume you have both.
Vendors in this category quote per deal rather than publishing rate cards, and the published figures you will find are usually estimates rather than confirmed contracts, so we will not invent a number. The variables that actually move it are how many AI systems you inventory, whether you need ISO 42001 alignment or general risk documentation, and whether AI governance sits alongside your other frameworks or in a separate tool with its own contract.
Often not. The artifacts AI frameworks ask for, inventory, ownership, risk assessment, supplier records, monitoring and incident handling, are the same artifacts your existing compliance program maintains for SOC 2 and ISO 27001. A separate platform makes sense when you build or fine tune models at scale and need evaluation and bias testing close to the pipeline. If you mainly buy and embed AI, adding AI to the program you already run is usually the cheaper and more defensible answer.

Keep reading

Related reading

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification