Skip to main content
Early pricing is live. Access is by request — ask with an email address.Early pricing is live. Access is by request.
AI governance

Govern every AI system from one accountable record

AI governance is the working discipline of knowing every AI system your company runs, who answers for each one, and what each one costs, risks, and returns. Oabo Scorecard keeps that knowledge as one accountable record per system — owner, spend, claims, and the evidence behind them.

This page is for the people accountable for that answer: a head of AI, a risk or governance lead, a CFO who signs what the board sees. The decision it serves is the one governance exists to make well — which AI systems to keep funding, which to fix, and which to stop — and what evidence you can put behind that call.

Published August 21, 2026 · Last reviewed August 21, 2026

The EU AI Act, NIST AI RMF, and ISO/IEC 42001 start from the same record

If your mandate names a framework, start with what the frameworks themselves start with. The EU AI Act attaches obligations system by system, according to the role you hold and the risk class each system falls into — and you cannot classify a system you have not listed. NIST AI RMF, the U.S. AI Risk Management Framework, is voluntary rather than binding, and its four functions — govern, map, measure, manage — all begin with knowing which systems exist and who answers for each. ISO/IEC 42001, the management-system standard for AI, expects an organization to know and document the AI systems inside its scope, and to keep records showing the work happened.

That shared starting demand — an inventory, a named owner per system, evidence that survives a second reader — is the record Oabo keeps. The boundary is just as plain: Oabo does not certify compliance with the EU AI Act, NIST AI RMF, ISO/IEC 42001, or any other framework, and no software alone can. The record shows its work; the judgment stays with your reviewers, your auditors, and your counsel. A regulated-industries pack — an off-by-default module with a compliance-framework library and per-agent attestations — is on the roadmap, not part of the product today.

Governance sits between the inventory and the proof

The sequence starts with an AI system inventory, because you cannot govern what is not on the record. It ends in AI ROI measurement, because the point of the record is a number you can defend. Governance is the discipline in between: named owners, evidence states, and decisions written down. If you are starting from zero, start at the inventory. If your inventory exists and your board is asking what AI returned, go straight to measurement.

How the record works, input to decision

  1. Inputs

    Three kinds of input, kept apart because they mean different things: what a team states about its AI, what your systems and provider bills report, and what finance records. Nothing arrives as a fact — it arrives as what it is: a claim, a meter reading, or a ledger entry.

  2. Records

    Every agent and model gets one record with a named owner, so every question has someone to go to. The record holds what the system does, what it costs, what it claims to return, and which risks are open. Every application write adds a linked event to the organization’s hash chain, preserving reviewable history.

  3. Evidence states

    Every value number carries a stage and skips none. Potential — someone believes the system helps. Claimed — someone states a figure and signs their name. Verified — a second person checks the evidence behind it. Hardened — the figure reconciles to a specific general-ledger event. The stage is set by the server, never by the number’s author, so nobody promotes their own claim.

  4. Readouts

    Cost sits beside value in the AI value ledger, and value stays in its own registers — never collapsed into one number. The Grade reports how complete the evidence is on two separate scores, count coverage and rate provenance, always as a pair. The board readout says plainly which parts are still self-reported.

  5. Decision

    Renew, fix, or stop — with the record attached. Only supported facts move; the rest holds where it is until it earns the move. Walk one claim through exactly this, or open the guided proof sample — the one ungated look at a working record.

Four kinds of value, kept apart on purpose

Realized cash is money finance recorded. Capacity hours are time a team got back — hours are not dollars, and they stay hours until finance records the conversion. Structural value is what changed in how the organization works, carried as signed attestations rather than counted output. Modeled estimates are labelled estimates, and a model is not a result. Oabo keeps the four in separate registers and never sums them, because a total that mixes them is a number you cannot defend — and a record that can only produce good news is not a record.

Where the usual tools stop

Most companies already govern AI with something. Each of these is good at its own job, and each stops short of the same thing: a stage on every number, and evidence that survives a challenge.

A spreadsheet

A spreadsheet inventory is a real start, and better than nothing on the record. What it cannot do is hold a stage on a number, refuse an unsupported promotion, or show that a cell changed after the fact. It goes stale silently, and the person who owns row forty finds out at review time.

A one-time assessment

An assessment is a photograph, and it is accurate the week it is taken. Models change, prices change, and the value case that held in March may not hold in September — model change should reopen the business case. A record stays current because the work keeps writing to it.

A cost dashboard

A cost dashboard tells you what you spent. It does not say what the spend returned, who answers for it, or whether the return survived a second reader. Spend beside evidence is the difference between a bill and a record.

A model registry

A model registry tracks artifacts and versions for the team that builds them, and it is the right tool for that job. It does not carry cost, value claims, owners outside engineering, or a readout a board can read.

A broad GRC suite

The wide governance-risk-and-compliance platforms carry many risk domains, and if you run one, keep running it. The question to put to any tool — including ours — is the same: show the work behind one AI number. The claim, the evidence, the stage, and who signed. That single question is the job this record is built for.

What Oabo does — and does not do

It does
  • Keeps one record per AI system, each with a named owner.
  • Puts a server-set evidence stage on every value number — Potential, Claimed, Verified, Hardened.
  • Keeps cost beside value, in separate registers that are never summed.
  • Writes every change to a hash-chained audit trail.
  • Produces the board readout and sealed audit packs, stating plainly which parts are still self-reported.
It does not
  • It does not verify your claims against your books for you. A person names the general-ledger event behind a claim and signs for it.
  • It does not issue compliance verdicts — not against the EU AI Act, NIST AI RMF, ISO/IEC 42001, or any other framework. The assurance workspace records work status — evidence linked, a question ready for review — never a judgment on your regulatory position.
  • It does not model your ROI for you, and it does not promise a return. Estimates are labelled estimates and stay outside every hardened total.
  • It does not replace your GRC platform or your model registry. It holds the record they do not: inventory tied to cost, value, and evidence.
  • It does not sell self-serve access. You request access with an email address, and a person approves it.

Questions governance buyers ask

What is AI governance software?

Software that keeps the governance record: which AI systems exist, who owns each one, what each costs and returns, and what evidence stands behind the numbers. The test of any AI governance software is not the length of its framework list — it is whether it can show the work behind one number.

What belongs in an AI governance inventory?

Every agent and model in use, including the ones nobody announced. For each: a named owner, what it does, what it costs, what it claims to return, and which risks are open. An inventory without owners is a list — the owner is what makes it governance. The AI system inventory page covers how the register is built and kept current.

Which AI governance metrics matter?

Start with coverage: how much of your AI estate is on the record at all, and how much of the spend is attributed to a system rather than sitting unassigned. Then evidence: what stage your value numbers sit at, and how much is still self-reported. The public scoreboard is stark — 2% of the S&P 500 can say what AI returned, a share the AI Value Gap Tracker follows quarter by quarter. Your internal metric is whether you could.

Is operational AI governance different from an annual review?

Yes, and the difference is when the record is made. Operational AI governance writes the record as the work happens: a system is registered when it starts, a claim carries its stage from the day it is stated, a change is audited the moment it lands. An annual review reconstructs all of that afterward, from whatever survived. Reconstruction is slower, and it cannot recover a stage a number never carried.

Will governance slow our AI teams down?

Registering a system takes a name and the team it works for; costs and usage connect afterward. What is slow is the alternative: assembling evidence at review time from shared drives and email threads. The record is made in passing, or it is made under pressure.

Does this make us compliant?

No — not with the EU AI Act, not with NIST AI RMF, not with ISO/IEC 42001 — and be wary of anything that says otherwise. Oabo records work status against your review process — evidence linked, questions ready — and never issues a verdict on your position. What it gives an examiner or auditor is a record that shows its work; the judgment stays with the people qualified to make it. The regulated-bank use case shows the shape: your examiner will ask — have the evidence linked.

How long until we have something to show the board?

Three checkpoints, and only the first is ours to hit. Week one: AI spend and workflow counts are visible. Day 30: finance countersigns the rate card, and the first cash backed by a general-ledger entry appears. Day 90: an independent reviewer can rebuild every value claim from your own records. What no timeline can shorten is evidence grade — it rises only as support is added and a second person reviews it. If your team cannot supply sources and reviewers, those dates move.

How do we get access, and what does it cost?

You ask, with an email address and nothing else. A person reads every request and decides; an approved link opens your workspace, which starts empty. Pricing is public. There is no discovery form and no qualification step — and no self-serve door either.

See the record working, then ask for your own

The guided proof sample is the one ungated look — a working record with sample data, read-only. How it works walks a single claim from stated to defended. When you want this for your own systems, asking takes one email address; a person reads the request, and an approved link opens a workspace that starts empty.

Request accessSee pricing