You can't attest to what you can't see.
Shadow AI and model sprawl mean the use-cases carrying the most risk are often the ones no one has inventoried. AIssure inventories, scores and maps every material AI use-case to the controls that bind it — so your attestation rests on evidence, not optimism.
The pressure you carry
Every business unit now reaches for AI, and most reach for it faster than governance can follow. Copilots, embedded vendor models, a script a desk quietly stood up — the result is model sprawl, and the use-cases with the sharpest risk are frequently the ones absent from any register. The CISO is asked to attest to the estate as a whole while parts of it remain, functionally, invisible.
The regimes assume you can see all of it. DORA holds you to identifying and managing ICT and operational-resilience risk across your systems — including the AI woven through them — and expects the mapping and register to actually exist. ISO/IEC 42001, the AI management-system standard, is built on the same premise: a governed system starts with a known inventory of AI, its purposes and its controls. Neither regime rewards a partial view, and a model inventory that omits the awkward cases is worse than none — it attests to coverage you do not have.
Why visibility is the control
You cannot govern, remediate or attest to a use-case you have never inventoried. Granular, estate-wide visibility is not a reporting nicety here — it is the first control, and everything downstream (risk scoring, remediation, the resilience mapping DORA expects) is only as complete as the inventory beneath it.
What AIssure gives the CISO
The audit turns an unknown estate into a defensible, cited register — one board-ready document in which every artefact is traceable:
- An inventory of material AI use-cases — surfaced across the estate, including the ones that never went through formal approval.
- A score per use-case — each assessed against the same engine, so exposure is comparable rather than anecdotal.
- A control mapping — every use-case tied to the specific DORA and ISO/IEC 42001 obligations that bind it, and a domain × jurisdiction heatmap across all eight jurisdictions in scope.
- The citation trail — every finding addressable back to the source clause on a regulatory knowledge graph of 14,000+ provisions: the difference between "the AI says" and "the regulation says."
Independence is the whole point
AIssure is an external opinion, not self-marking. It attests to your AI governance; it never operates, monitors or remediates the models it inventories. A control the security function runs cannot be objectively attested by that same function — which is why the assessor sits outside the estate being assessed. For a CISO signing an attestation, that separation is what makes it hold.
The deliverable, in your language
Most firms start with the AI Governance Maturity Assessment — 96 questions across eight domains, marked 0–5 — to establish a defensible baseline and a first honest inventory. Firms heading for accreditation run the ISO Standards Deep Dive — 275 questions across ISO/IEC 42001, 23894 and 38507. Both produce the same board pack: reproducible at re-performance, comparable engagement to engagement, and certification-ready for the accredited body that will certify — a word we never use for AIssure itself.
Related
The AI governance audit
The productised, point-in-time assessment, explained end to end.
→ The moatThe regulatory knowledge graph
How the citation trail is built, versioned and verified.
→ CoverageDORA
The ICT and operational-resilience obligations your AI use-cases map to.
→ By roleFor the CDO
Governance that lets data and AI ship faster, not slower.
→For the CISO — the questions we get.
What a CISO asks before attesting to an AI estate they need to see in full.
How does AIssure handle shadow AI and models we haven't documented?
Inventory comes first. The assessment surfaces material AI use-cases across the estate — including the ones that never went through a formal approval — then scores each and maps it to the controls that bind it. You cannot govern, or attest to, what you have not inventoried, so the audit treats discovery as the foundation rather than an afterthought. What you get back is a defensible register, not a hopeful one.
Is AIssure a runtime monitoring tool for our models?
No. AIssure is a point-in-time, independent assessment over your AI governance; it does not instrument or monitor deployed models. Runtime platforms are second-line tooling operated by the firm that owns the models. AIssure is the third-line opinion that consumes their evidence — an external attestation, never an operator of the controls it assesses. Keeping those roles separate is what gives the assessment its independence.
How does the audit relate to DORA and ISO 42001?
It maps each material AI use-case to the specific obligations that apply — DORA's ICT and operational-resilience requirements, and the management-system controls in ISO/IEC 42001 — with every finding traced to primary regulatory text on a graph of 14,000+ provisions. For firms heading towards accreditation, that evidence base is certification-ready: it is exactly what an accredited ISO/IEC 42001 certification body expects to see, though only that body can certify.
Start with a thirty-minute read on your readiness.
A high-level, question-only session — 12 to 16 questions, no evidence to prepare — for an initial view of your AI governance maturity and readiness. It sets the scene for a full engagement: the audit platform deployed and evidence-based assessments run, self-serve or consultant-supported.