# AI governance that answers to the board and the regulator.

> AI governance in ColossalX turns what the platform sees, controls and tests into a position you can defend to a board or regulator: a trust score that explains itself, a risk register quantified in money, frameworks assessed from live signals and an audit run to a sealed archive. Evidence collects itself, graded by how it was obtained and timestamped daily.

A trust score that explains itself, AI risk in money, frameworks assessed from live signals, audits run to a sealed archive, and evidence an auditor can check.

Canonical page: https://colossalx.tech/platform/govern · Last reviewed: 6 Oct 2026

## The threat and the control

- **The threat:** The board asks how exposed the AI estate is, and the answer is a slide of adjectives.
- **The control:** ColossalX answers with a graded score, a loss range in money and evidence an auditor can re-check.

## The question: Where do we stand?

Where an x ends up: x, accounted for.

Four capabilities answer one question, where do we stand, and each reads the same spine: one issue queue, one risk register, one trust score, one evidence store and one reports hub.

## ColossalX Trust Engine

A trust score that explains itself: five pillars, security, compliance, risk, resilience and AI governance, graded A+ to F from live evidence. A pillar with no evidence carries no weight, and a grade resting on too little is marked provisional. The page names what pulls the score down, how far the next grade is, and the action that supplies each missing piece of evidence. [ColossalX Trust Engine](https://colossalx.tech/platform/trust-engine)

*Illustration:* Trust score · provisional: C. Security measured; Compliance measured; Risk measured; Resilience not measured; AI governance measured. Resilience has no evidence, so provisional

## Risk quantification

A risk register that fills itself from compliance gaps, audit findings, code scans, proven attacks and threat-intelligence decisions. Entries are de-duplicated and closed when the source closes. Critical assets raise impact, never lower it. FAIR turns any entry into an annual loss range with a one-in-twenty-year tail. An acceptance beyond your appetite goes to the board with a reason and an end date, then lapses back to analysis. [Risk quantification](https://colossalx.tech/platform/risk-quantification)

*Illustration:* FAIR · loss range: an illustrative loss distribution with its range shaded, the likely loss marked and the your appetite as a dashed line.

## Compliance and AI governance

Frameworks mapped and assessed against, never certified. They include NIST AI RMF, the EU AI Act, ISO/IEC 42001, SOC 2, GDPR, India DPDP, PCI DSS, and the SEBI and IRDAI cyber circulars. Each control carries the status a person decided beside a health label from live signals, and a control with no runtime signal is not assessable: excluded, never silently passed, while evidence is graded and timestamped. [Compliance and AI governance](https://colossalx.tech/platform/compliance)

*Illustration:* One control, many frameworks: Guardrails on AI inputs and outputs maps to EU AI Act (Art. 15); NIST AI RMF (MANAGE 2.1). Mapped to and assessed against, not certified.

## Audit

Run an audit of AI systems and the third parties behind them, from a risk-based plan to a sealed, timestamped archive. An engagement opens only when the evidence for its trigger exists, design is tested before operation, samples replay identically and each finding gets a management response. The preparer never reviews and the signer never prepared, and findings flow into owned work and the risk register. [Audit](https://colossalx.tech/platform/audit)

*Illustration:* Audit archive · AI agents: Engagement AI agents, second half; Workpapers Design and operation tested; Findings Answered and tracked; Sign-off Not the preparer; Timestamp From a public authority. Sealed archive.

## How it works: From one proven attack to the board pack.

One attack proven on an agent, followed until the board and auditor can see it: a risk entry, a loss range in money, a decision by a named owner, a proven fix and timestamped evidence.

### Workflow: one proven attack, accounted for (illustrative)

1. **Exposure proven.** A red-team run proves an attack, and the register gets a risk.
   Source: sealed red-team run; Risk: tool misuse (ASI02) on research-agent; Entry: written, de-duplicated
2. **Quantified in money.** FAIR gives the risk an annual loss range and a one-in-twenty-year tail.
   Likely: $13K a year; Range: $4K to $31K; 1 in 20 years: $31K or more | Above appetite
3. **Owner decides.** A named owner treats it; accepting it would need a board minute.
   Head of risk: Treat: guardrail change, due in two weeks | [Treat] [Accept]
4. **Proven and recorded.** The fix is proven, the trust score moves, and evidence is timestamped.
   Closed on evidence · Score updated · Timestamped daily | x, accounted for

## How we know

- A pillar with no evidence carries no weight, and a thin grade is marked provisional.
- Evidence is graded A to D from facts the server recorded, never from what a client said.
- Not assessable is a first-class answer: excluded from the score, never counted as a pass.
- Risk acceptances must expire, and those beyond appetite need a board minute.

## Where a governed x goes next.

Governance does not end on a dashboard. The same records reach the people, tools and reports that act on them.

- **One issue queue.** Findings from testing, scanning, intelligence, audit and compliance land in one owned queue.
- **Evidence store.** Evidence collects itself, graded A to D, second-person verified, withdrawn but never deleted.
- **Policies people accept.** An AI policy generated or uploaded, published by version and accepted by named people.
- **Reports hub.** 11 report types as branded PDFs, scheduled and signed off by a second person.
- **Your GRC tools.** The risk register syncs out to GRC, ticketing and SIEM tools, signed and outbound only.

## Specs: delivery and data

- **Delivery:** SaaS, from one login.
- **Isolation:** Each customer runs in an isolated workspace with its own database.
- **Certifications:** None held. Frameworks are mapped to and assessed against.

## Frameworks

- Mapped to NIST AI RMF: AI controls assessed from live signals.
- Mapped to EU AI Act: AI-governance controls cross-mapped, with evidence.
- Mapped to ISO/IEC 42001: The same AI controls, with clause references.
- Mapped to India DPDP: Consent and data governance controls.
- Mapped to SOC 2: Baseline controls with graded evidence.

## What it does not do

- ColossalX holds no certification, and mapping a framework to its controls does not confer conformity with that framework.
- Framework control sets are baselines, not clause-by-clause mappings, and several controls have no runtime signal yet.
- Jurisdiction packs and audit checklists are starting content for your counsel to review, not legal advice.
- FAIR is only as good as the ranges your analysts enter; no workspace is seeded with loss estimates.

*Illustration:* Sign-off · separation of duties: audit preparer to management sign-off, "Approve the audit report for the AI agents engagement". Checks: Signer did no work failed, Reason shown passed. Verdict: refused, Signer never preparer.

## Questions

### What is an AI governance platform?

An AI governance platform keeps an organisation's use of AI accountable: what is in use, who owns it, which risks it carries, which rules and frameworks apply, and the evidence that controls work. ColossalX does this from its own runtime and testing data, so the position it reports is measured rather than filled in by questionnaire.

### What is the difference between AI governance and AI security?

AI security finds, stops and tests: it finds AI in use, refuses unsafe requests and attacks your own defences. AI governance accounts for it: risk in money, frameworks assessed, policies accepted, audits run and evidence kept. In ColossalX both run on one spine, so a proven attack moves the governance record without anyone retyping it.

### Which frameworks does ColossalX map to?

NIST AI RMF, the EU AI Act, ISO/IEC 42001, SOC 2, GDPR, India DPDP, PCI DSS and the SEBI and IRDAI cyber circulars, with AI-governance controls cross-mapped to NIS2. Each is mapped to and assessed against, never certified: ColossalX holds no certification, and its framework control sets are baselines rather than clause-by-clause mappings.

### How does ColossalX produce evidence an auditor can check?

Evidence collects itself from runtime signals and is graded A to D by how it was obtained. It can be verified by a second person, originals are kept byte-exact, a daily manifest of the whole store is timestamped by a public authority, and withdrawn evidence is flagged with a reason rather than deleted.

### Who in an organisation owns AI governance?

Usually several people: a head of AI governance or a DPO for policy and data, risk for the register, compliance for frameworks, internal audit for assurance and the CISO for security. ColossalX gives each a role and enforces separation of duties on the server, so a preparer cannot sign off their own work.

### What does the board see?

A grade it can read, with its reasons: the trust score across five pillars, the top risks as loss ranges with a one-in-twenty-year tail, acceptances above appetite awaiting a board minute, and reports signed off by a second person. Where evidence is thin, the grade says provisional instead of flattering the position.

## Related

- [See](https://colossalx.tech/platform/see)
- [Control](https://colossalx.tech/platform/control)
- [Prove](https://colossalx.tech/platform/prove)

---

ColossalX is an AI security and governance platform from Quantexra Labs LLP, delivered as SaaS. Book a walkthrough: https://colossalx.tech/demo · client.success@quantexra.tech
