Notifications
You're all caught up.

Know which AI you run, how risky it is, and who said yes

AI governance is how an organization keeps track of the AI systems it builds, buys and runs, decides how much scrutiny each one needs, and records who approved each system for use and why. This page explains what a program involves and why organizations run one.

30-day demo, no credit card, unlimited team members. Watney, exports and scheduled report emails, auditor and guest links, the transparency page and public badge, the API and MCP server, webhooks and SIEM forwarding come with a plan.

The parts of an AI governance program

AI now arrives in an organization in several ways: a model a team builds, a vendor product, a feature switched on inside software you already pay for. A governance program is how those uses are found, weighed, approved and written down, so the organization can answer for each one.

An inventory of AI systems

You cannot govern a system nobody listed. A registry records each AI system, the models it uses and their versions, and the vendors that supply them, with your due diligence on each vendor.

A risk tier for each system

Not every system needs the same scrutiny. A risk tier sets how closely a system is reviewed and how long an approval lasts before it is revisited.

Assessment against a framework

A framework such as the NIST AI RMF gives the program one consistent set of questions, asked of the organization as a whole and of each AI system.

Review and approval

Before a system is used, named people decide whether it should be, and each records a reason. Each approval carries a review date set by its risk tier; when it arrives a re-review opens automatically, so the decision is made again as the system and its context change.

Model and system cards

Cards describe a model or a system in a form a reviewer, an auditor or the public can read, and a published version is fixed so it can be relied on later.

Transparency

Publishing system cards lets the people a system affects see what it is and how it is governed.

Records that stay current

Risks, AI incidents, vendors, policies, training, changes and access reviews, kept next to the systems they concern, with an audit trail of who changed what.

People make the decisions

Software can draft and suggest. The approval, the risk tier and the decision to publish belong to the people your policy names.

What governance is not. A governance program is not a certificate, and running one does not by itself mean an organization meets any law or standard. Backsplice supports the program: it keeps the registry, runs the assessments, routes the reviews and records the decisions. The judgments stay with your organization and its advisers.

Governance starts with a list of what you run

Every other part of a program depends on the inventory. A system that is not on it is not assessed, not reviewed and not monitored, and nobody can say who approved it. The NIST AI RMF puts it among its first Govern outcomes:

“Mechanisms are in place to inventory AI systems and are resourced according to organizational risk priorities.”
NIST AI RMF 1.0, GOVERN 1.6

Quoted from NIST's published framework, which is voluntary guidance rather than law.

An inventory worth governing from records more than a name:

  • ✓
    How the system is sourced. Built in-house, vendor AI product, AI feature inside other software. The last is the easiest to miss.
  • ✓
    The models it uses, with versions. So a model change is visible rather than silent.
  • ✓
    The vendors behind it. Including whether a vendor trains on your data and whether an agreement is on file.
System, its purpose and how it is sourced
Models used, by version
AI vendors and due diligence
Risk tier and lifecycle stage
Assessments, reviews and cards
Next review date, set by the approval

More scrutiny where more can go wrong

Reviewing every AI system the same way either wastes effort on low-risk tools or under-reviews the systems that matter. The NIST AI RMF asks organizations to set the level of risk management activity by their own risk tolerance (GOVERN 1.3). A risk tier is how a program does that.

Higher tier

A wider review, a shorter approval

A system that makes automated decisions about people, or that customers use directly, may call for more approvers, agreement from all of them, and a sooner re-review.

Lower tier

A lighter review, the same record

An internal assistant whose output a person checks may need a single approver and a longer approval period. It is still registered, assessed and recorded like every other system.

In Backsplice, a system's risk tier sets who must approve it and whether any, a majority or all of them must agree, under your risk-tier policy (a weaker per-system policy needs an org admin and a reason). An approval lasts for a period set by the tier (High: 6 months; Moderate: 12 months; Low: 12 months; Unclassified: 6 months), then prompts a re-review.

A framework gives the program its questions

Without a framework, each review asks whatever its reviewers happen to think of. The NIST AI Risk Management Framework is voluntary guidance from the US National Institute of Standards and Technology, organized into four functions: Govern, Map, Measure and Manage. NIST AI 600-1, the Generative AI Profile, adds the risks particular to generative AI.

A program answers some questions once, for the organization, and others for each system. In Backsplice the program assessment asks the governance questions, each system assessment asks the questions about that system, and the generative AI questions are asked only of a system that uses generative AI.

Backsplice includes NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile) on every plan and in the demo. ISO/IEC 42001 and the EU AI Act are next; they are not included today.

NIST AI RMF 1.0
NIST AI 600-1 (Generative AI Profile)
Next: ISO/IEC 42001 and the EU AI Act, not yet included

A decision, a name and a reason

The point of the review is a decision someone owns. The NIST AI RMF describes it as a determination of whether a system should go ahead:

“A determination is made as to whether the AI system achieves its intended purposes and stated objectives and whether its development or deployment should proceed.”
NIST AI RMF 1.0, MANAGE 1.1
Decision
What it means
What happens next
Approve
The system may be used as reviewed
The approval runs until its period ends
Approve with conditions
The system may be used once conditions are met
Each condition is tracked until it is met
Reject
The system should not be used
The reason stays on the record
Send back
The reviewers need more before they decide
The system returns for another review

Every decision carries a reason, each approval opens a re-review when its review date arrives, and the approval dossier exports the whole record when someone asks how a system was approved.

Write down what each system is, and let people read it

An approval records a decision. A card records what was decided about: what the model or system is, what it is for, and what its owners know about it. Cards are how that knowledge outlives the meeting where it was discussed.

  • ✓
    Model cards and system cards. One for each model you record and each system you run.
  • ✓
    A fixed version once published. In Backsplice, publishing freezes that version with a tamper-evident seal, so a later edit makes a new version.
  • ✓
    A public transparency page. On a paid plan, list your published system cards where the people they affect can read them.
Reviewers see the same description
A published version cannot be quietly rewritten
Auditors read the card, not the meeting notes
The public sees what you chose to publish

Priced by how many AI systems you govern, never by seat

Governance is a team activity. The people who own a system, the people who review it, and the people who approve it all need to be in the record. So we do not charge per seat: every plan, and the demo, has unlimited team members.

$999/yr Premium, annual
$99/mo Premium, monthly

Premium includes 1 AI system. Enterprise is $499 a month or $4,999 a year with no limit. The features are the same on both, and Watney's fair-use limit scales with the plan.

Unlimited team members

Everyone who owns, reviews or approves a system can be in the record, on every plan.

Every framework pack

NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile), on every plan and in the demo.

Watney

Included on Premium and Enterprise at no extra charge, within fair-use limits. Not part of the demo.

SAML single sign-on and SCIM

On every plan, and in the demo.

A data processing agreement

An organization admin accepts it for the organization before any governance records can be created or changed. Organization setup (profile, members, sign-in and integration settings) can be done first.

Exports, API and transparency page

Watney, exports and scheduled report emails, auditor and guest links, the transparency page and public badge, the API and MCP server, webhooks and SIEM forwarding come with a plan.

See full pricing and plan comparison, or the product overview.

Questions people ask about AI governance

What is AI governance? +

AI governance is the set of practices an organization uses to decide which AI systems it will use and how. In practice that means keeping an inventory of AI systems, judging how much risk each one carries, assessing them against a framework, having named people approve each system before it is used, documenting what each system is, and revisiting those decisions as things change.

Is AI governance required by law? +

That depends on where you operate, what your AI systems do, and your sector, and the law in this area is changing quickly. Many organizations run a program on a voluntary framework such as the NIST AI RMF whatever their legal position, because it gives them one consistent record. Backsplice does not decide which laws apply to you, and nothing here is legal advice.

What is the NIST AI RMF? +

The AI Risk Management Framework is voluntary guidance published by the US National Institute of Standards and Technology. It is organized into four functions: Govern, Map, Measure and Manage. NIST AI 600-1, the Generative AI Profile, is its companion for generative AI. Backsplice includes both as framework packs: NIST AI RMF 1.0 and NIST AI 600-1 (Generative AI Profile).

Why keep a registry of AI systems? +

Because every other part of the program depends on it. You cannot assess, approve or monitor a system nobody listed. AI also arrives in more ways than a team building a model: a vendor product, or a feature switched on inside software you already use. A registry records each system, the models it uses and their versions, and the vendors that supply them.

What is a risk tier for? +

It keeps scrutiny proportionate. A system that makes automated decisions about people may deserve a wider review than an internal drafting assistant a person checks. In Backsplice, the risk tier sets who must approve a system, whether any, a majority or all of them must agree, and how long the approval lasts (High: 6 months; Moderate: 12 months; Low: 12 months; Unclassified: 6 months).

What are model cards and system cards? +

Short documents that describe a model or an AI system in a form other people can read. In Backsplice, publishing a card freezes that version with a tamper-evident seal, so a later edit creates a new version instead of rewriting the old one. Published system cards can be listed on a public transparency page on a paid plan.

Does the AI make any of the decisions? +

No. Watney, the AI assistant in Backsplice, proposes and never decides. It drafts cards, suggests intake triage, and answers questions grounded on your records. It does not approve a system, set a risk tier, or publish anything. An organization admin must opt in before Watney reads your data, and it sends the model provider only what a task needs. Its own system card names the provider and the models.

What does it cost, and are there per-seat fees? +

No per-seat fees, with unlimited team members on every plan. Start with a 30-day demo, no card. Premium is $99 a month or $999 a year and includes 1 AI system; Enterprise is $499 a month or $4,999 a year with no limit. The features are the same on both, and Watney's fair-use limit scales with the plan.

Not legal advice. Backsplice is an AI governance platform, not a law firm, and nothing on this page is legal advice. The NIST AI RMF is voluntary guidance. Which laws apply to your AI systems depends on your organization, where it operates and what the systems do; have your counsel review what you rely on.

Start with your first AI system

Register it, assess it and take it through review in a 30-day demo, no credit card needed.