Answer a control once.
Satisfy four frameworks.
Stratify collapses NIST AI RMF, ISO/IEC 42001, ISO/IEC 23894 and the EU AI Act into one set of 62 plain-English controls. Answer them once and watch 179 framework clauses turn green at the same time — with the evidence attached and the audit trail already written.
No credit card. Every framework unlocked during the trial.
- NIST AI RMF4 functions · 72 subcategories72
- ISO/IEC 42001AIMS clauses + 38 Annex A controls51
- ISO/IEC 23894Principles · framework · process29
- EU AI ActObligations across the risk tiers27
Stop answering the same question four times
Most teams run parallel compliance tracks: a NIST workbook, an ISO Statement of Applicability, an AI Act readiness sheet, and a folder of evidence duplicated across all three. The work is the same. The documentation is not.
Stratify inverts it. You maintain one control set. Every clause that control contributes to updates the moment you answer — and the crosswalk view shows exactly which clauses are met, partially met, or still open in each framework.
- Coverage is rated honestly — full, partial, or supporting
- Clause status derives from your answers, not from a checkbox you tick twice
- Mark a control not applicable and the justification travels with it
| Framework | Clause | Coverage |
|---|---|---|
| NIST AI RMF | GOVERN 1.6 | full |
| ISO/IEC 42001 | A.4.2 | full |
| ISO/IEC 42001 | A.4.5 | partial |
| ISO/IEC 23894 | 6.3.2 | partial |
| EU AI Act | Article 6 | partial |
AI governance became mandatory before it became affordable
The deadline is already here
EU AI Act prohibitions and the AI literacy duty have applied since February 2025. GPAI obligations landed in August 2025. The high-risk regime follows in August 2026. This is law with extraterritorial reach — it binds any provider placing a system on the EU market.
Your GRC tool doesn't cover it
Traditional GRC platforms model controls, not models. They have no concept of an AI system inventory, autonomy level, drift, an Annex III use case, or a fundamental rights impact assessment.
The specialists price you out
Credo AI, Holistic AI, OneTrust and IBM OpenPages start between $30,000 and $200,000 a year. That is a rational price for a Fortune 500 program and an impossible one for a 40-person company that just got an AI questionnaire from its largest customer.
What you get on day one
AI system inventory
Register every model, API, agent and embedded feature — including the shadow AI in your SaaS stack. Each system gets an owner, a lifecycle stage, and a risk profile.
Explainable risk scoring
A 0–100 composite across autonomy, data sensitivity, consequence, oversight gap, scale, regulatory exposure and supply chain. Every point traces to a named driver — no black-box score you can't defend.
EU AI Act tier classification
Screens each system against Article 5 prohibited practices and Annex III high-risk use cases, then returns the tier and the specific article-by-article obligations that follow.
ISO 23894 risk methodology
The framework almost no platform operationalizes: identification, analysis, evaluation, treatment planning, residual risk acceptance, monitoring and reporting — as a real process, not a checkbox.
Deduplicated evidence repository
Upload the model card once and attach it to the eleven controls it proves. SHA-256 recorded at ingest, expiry tracked, so stale evidence surfaces before an auditor finds it.
Hash-chained audit trail
Every action is appended with a hash covering the previous entry. Edit or delete a row and verification fails — which is what makes the trail tamper-evident rather than merely promised.
One-click audit packet
Control set, clause coverage per framework, evidence index with digests, risk register and the verified audit trail — as a single document you hand to an auditor, a customer, or the board.
Sector overlays
Healthcare, finance and defense packs layer sector-specific controls — clinical validation, model risk management, adverse action reasoning, CUI boundaries — on top of the core set.
You have already done more of this than you think
Upload the policies, SOPs, model cards, vendor questionnaires and security documents you already wrote. Claude reads them against all 62 controls and tells you which ones they evidence — with a verbatim quote from your own document as the citation.
A three-week consulting engagement becomes a three-minute upload. And nothing is applied automatically: every finding is a proposal your compliance officer accepts or rejects, and the decision is recorded in the audit trail.
“All data used in automated processing must be classified and approved by the Data Governance Committee prior to use.”
“Annual penetration testing is performed against all production applications.”
Findings shown are illustrative. Real output cites your document verbatim.
Priced for the companies the incumbents skipped
Every plan starts with a 14-day trial with all four frameworks unlocked and no card required. Annual billing saves two months.
Starter
For the team that just got asked for an AI policy
- NIST AI RMF + EU AI Act
- 5 AI systems, 3 seats
- Unified control set and evidence repository
- Risk scoring and EU AI Act tier classification
- 5 Claude policy analyses / month
Growth
Most chosenFor the team that has to prove it to a customer or an auditor
- All four frameworks fully crosswalked
- 25 AI systems, 15 seats
- One-click audit packet export
- 50 Claude policy analyses / month
- Immutable, hash-chained audit trail
Scale
For the team running AI governance as a program
- Unlimited AI systems and seats
- Sector overlays: healthcare, finance, defense
- SSO / SAML
- 250 Claude policy analyses / month
- API access and priority support
For comparison: comparable AI governance platforms are priced from $30,000 to $200,000 per year.
Find out where you actually stand
Register your AI systems, upload the documents you already have, and get a gap report across all four frameworks. Most teams have their first readiness picture inside an hour.