Skip to content
Products/Govern layer/ENGRAP AI
Governance, risk and assurance

ENGRAP AI

The governance, risk and assurance platform for every AI system your organisation runs.

ZNYX enforces policy on each call. ENGRAP owns the layer above it: what AI you run, who approved it, which risks were accepted, what evidence exists and what a supervisor would be shown on a Tuesday with two weeks’ notice. It is a register and an assurance workflow, not a dashboard of green ticks.

Assurance boardIN REVIEW
46
AI systems in register
9
High-risk classified
3
Awaiting committee
92%
Evidence complete
Model card missing post-deployment monitoring section
claims triage assistant · owner notified · 09:12
DPIA approved with two residual risks accepted
HR screening pilot · signed by DPO · 09:40
Third-party model version changed under an existing approval
vendor notice · re-assessment triggered · 10:03
Annex IV pack exported for external audit
credit decisioning · 214 evidence items · 10:21
1 register
Every model, agent and vendor service in one inventory
Annex IV
Documentation mapped clause by clause, not summarised
70%
Less manual effort assembling an audit pack
8 weeks
From first workshop to a defensible register
Capabilities

Six things a compliance lead stops chasing over email.

Each module stands alone, and all of them read from the same register, so the risk team, the model owners and the auditors finally see one version of the estate.

AI system inventory

Every model, agent, prompt-based feature and embedded vendor capability, with owner, purpose, data classes, deployment stage and dependencies recorded rather than remembered.

You can answer “what AI do we run” in a meeting
Risk classification and assessment

Structured assessment against the frameworks you are held to, with obligations derived from the classification instead of chosen by whoever filled in the form.

Consistent classification across business units
Model and system documentation

Model cards, data statements, evaluation summaries and change history generated from what the system actually is, with gaps flagged as work items.

Documentation that stays current after launch
Control evidence collection

Evidence pulled from your pipelines, evaluation runs and runtime logs on a schedule, so assurance is a continuous record rather than a pre-audit scramble.

Evidence with a timestamp and a source
Committee and approval workflow

Review gates, quorum, conditions and residual-risk acceptance, with the decision and its rationale attached to the system it governs.

Decisions that can be explained a year later
Assurance reporting

Board, regulator and customer views of the same underlying register, produced without a quarter of spreadsheet reconciliation.

One register, several audiences
Why a register is not a spreadsheet

Governance fails between the policy and the model, not in the policy.

The realityWhat ENGRAP AI does about it
Policy exists; practice driftsENGRAP ties each obligation to the system it applies to and the evidence that proves it, so drift becomes a visible gap instead of an assumption.
Nobody owns the inventoryDiscovery is continuous. New endpoints, vendor features and agent deployments are surfaced for classification rather than discovered during an audit.
Documentation is written onceModel cards are regenerated from the current system and versioned against it, with an explicit diff when behaviour changes.
Evidence is reconstructedControls emit evidence as they run. An audit pack is an export, not a project.
Risk sits in a siloModel owners, data protection, security and the business see the same record with the same language, and the committee sees what changed since last time.
Fits your estate

Sits beside the platforms you already govern with.

ENGRAP is the assurance layer, not another place to work. It reads from your MLOps stack, your ticketing system and ZNYX, and writes obligations back as tasks in the tools people already open.

Runtime enforcementReads ZNYX decisions and policy versions, so what was enforced and what was approved can be compared.
MLOps and pipelinesEvaluation results, training metadata and deployment events ingested from your existing CI and model registry.
GRC and ticketingObligations and findings land in ServiceNow, Jira or your existing GRC tool as work with owners and dates.
Identity and accessRoles inherited from your directory, with segregation between model owner, reviewer and approver enforced.
DeploymentRuns in your tenancy. The register and its evidence never leave your boundary.
Rollout

A defensible register in eight weeks.

Weeks 1 to 2
Discover the estate

Inventory workshops plus automated discovery across cloud accounts, vendor contracts and code, to find the AI nobody registered.

Weeks 3 to 4
Classify and prioritise

Risk classification for what we found, with obligations derived per system and the high-risk set queued for full assessment.

Weeks 5 to 6
Wire the evidence

Automated evidence collection connected for the priority systems, so the controls start producing a record immediately.

Weeks 7 to 8
Stand up the committee

Review gates, approval workflow and the first board pack, run once with us in the room and then handed over.

Common questions

How is this different from ZNYX?

ZNYX is runtime: it evaluates prompts, outputs, tool calls and retrieval against policy and returns a decision inside your perimeter. ENGRAP is organisational: it holds the inventory, the risk assessments, the documentation, the approvals and the evidence. They are useful separately and stronger together, because ENGRAP can prove what ZNYX enforced.

Do we need ENGRAP if we already have a GRC tool?

Often you need both. Generic GRC tools model controls well but know nothing about models, evaluations or prompt changes. ENGRAP carries the AI-specific record and pushes obligations into the GRC tool you already run.

Which frameworks are supported?

The EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework are mapped out of the box, and internal policies can be added as first-class frameworks with their own obligations.

Who fills all this in?

Less of it than you expect. Inventory and evidence are collected automatically where a system exists; humans supply purpose, context and judgement. The aim is that nobody re-types what a pipeline already knows.

Can an external auditor be given access?

Yes, scoped and read-only, to a specific system or framework for a specific period, with their access itself recorded.

Bring us your hardest question from an auditor.

Send the question you least want to be asked about an AI system in production. We will show you what ENGRAP would have on file to answer it.

Book a governance review