Curated list of resources at the intersection of AI and Governance, Risk, and Compliance (GRC). Includes frameworks for governing AI systems and AI-powered tools for GRC automation.
- Drata - Automated compliance platform with AI-powered security questionnaire responses and real-time monitoring for SOC 2, ISO 27001, and HIPAA.
- Vanta - Lightweight compliance automation for startups supporting 30+ frameworks with evidence collection and monitoring.
- Secureframe - Compliance automation with high-touch guidance for complex multi-framework environments.
- Sprinto - AI-driven compliance automation platform with risk-based prioritization and continuous control monitoring.
- Thoropass - End-to-end compliance platform combining automation software with auditor services.
- AuditBoard - Connected risk platform with AI-powered audit management, SOX compliance, and risk assessment.
- Workiva - Cloud platform for audit, risk, and compliance with AI-assisted document analysis and reporting.
- MindBridge - AI-powered financial audit analytics detecting anomalies and risks in transactional data.
- LogicGate - Risk Cloud platform with AI-driven risk quantification and automated control assessments.
- Resolver - Integrated risk intelligence platform with AI-powered risk correlation and predictive analytics.
- ServiceNow GRC - Enterprise GRC with AI-driven risk insights and automated policy management.
- Claude for Enterprise - AI assistant for policy analysis, compliance document review, and risk assessment workflows.
- Microsoft Copilot for Security - AI-powered security operations with threat intelligence and compliance guidance.
- ChatGPT Enterprise - Secure AI assistant for GRC document analysis, policy drafting, and audit preparation.
- NIST AI Risk Management Framework - Voluntary US framework for identifying, assessing, and mitigating AI risks with four core functions (Govern, Map, Measure, Manage).
- EU AI Act - European regulation establishing risk-based AI requirements with prohibited practices, high-risk obligations, and transparency rules.
- ISO/IEC 42001 - International standard for AI Management Systems (AIMS) providing certification framework for responsible AI governance.
- OECD AI Principles - International guidelines for trustworthy AI covering human-centered values, transparency, and accountability.
- Singapore Model AI Governance Framework - Practical guidance for deploying AI responsibly with implementation examples.
- MITRE ATLAS - Knowledge base of adversarial tactics and techniques specific to AI systems for threat modeling and security assessment.
- OWASP AI Exchange - Comprehensive framework covering 300+ pages of AI security guidance including threats, controls, and risk analysis for all types of AI systems.
- Berryville Institute of Machine Learning - Architectural risk analysis framework and taxonomy for identifying ML and LLM security risks.
- MIT AI Risk Repository - Searchable database of 700+ AI risks with causal taxonomies for comprehensive risk assessment.
- Cloud Security Alliance AI Controls - Security controls framework for AI deployments in cloud environments with shared responsibility guidance.
- Microsoft Responsible AI - Principles, tools, and practices for building AI systems that are fair, reliable, and transparent.
- Google AI Principles - Framework for developing AI applications that are socially beneficial, avoid bias, and maintain accountability.
- Partnership on AI - Multi-stakeholder organization developing best practices for responsible AI development and deployment.
- AI Ethics Lab - Research and resources on ethical AI development, algorithmic fairness, and AI governance.
- MLflow - Open-source platform for ML lifecycle management including experiment tracking, model registry, and deployment.
- Weights & Biases - ML experiment tracking and model management platform with versioning, lineage, and collaboration features.
- Fiddler AI - Model performance monitoring and explainability platform for detecting drift, bias, and compliance issues.
- Arthur AI - ML monitoring platform providing model performance, fairness, and explainability insights for production systems.
- Collibra - Data intelligence platform with AI-assisted data cataloging, lineage tracking, and governance automation.
- Alation - Data catalog with ML-powered discovery, governance, and compliance for AI/ML data pipelines.
- Immuta - Data access control platform with policy-based governance for sensitive data used in ML training.
- DataRobot MLOps - End-to-end ML operations with model governance, monitoring, and compliance tracking.
- IAPP AIGP - Artificial Intelligence Governance Professional certification covering AI governance frameworks, risk management, and ethics.
- ISACA CGEIT - Certified in Governance of Enterprise IT for professionals managing AI governance within enterprise IT.
- CRISC - Certified in Risk and Information Systems Control for IT risk professionals managing AI-related risks.
- CISA - Certified Information Systems Auditor for auditing AI systems and automated controls.
- CompTIA Security+ - Foundational cybersecurity certification covering risk management and compliance fundamentals.
- MIT AI Ethics and Governance - Executive education on AI strategy, ethics, and governance implications.
- Stanford HAI Courses - Human-Centered AI Institute courses on responsible AI development and policy.
- Coursera AI Ethics - Free course covering ethical frameworks for AI decision-making and bias mitigation.
- edX AI Governance - University-backed courses on AI regulation, policy, and governance frameworks.
- SANS Security Awareness - Security training programs covering risk management, compliance, and security controls.
- LinkedIn Learning GRC Path - Curated learning path for GRC fundamentals including risk assessment and audit.
- Pluralsight Security Compliance - Technical compliance training for security professionals entering GRC.
- ISACA Learning - Professional development in audit, risk, governance, and cybersecurity.
Ready-to-use Claude prompts for GRC compliance workflows. See the prompts/ directory for usage instructions.
Compliance Frameworks:
- SOC 2 Audit Preparation - Generate timeline-based audit preparation checklist
- PCI DSS Gap Analysis - Identify compliance gaps with risk-prioritized remediation
- FedRAMP Compliance Assessment - Assess authorization readiness with control gap analysis
- FISMA Control Evaluation - Evaluate NIST 800-53 control implementation status
AI Governance:
- NIST AI RMF Risk Assessment - Comprehensive AI risk assessment across GOVERN, MAP, MEASURE, MANAGE functions
Customizable policy templates for AI governance. See the templates/ directory for customization instructions.
- AI Acceptable Use Policy - Guidelines for acceptable use of AI technologies (NIST AI RMF, ISO 42001)
- AI Risk Assessment Framework - Structured framework for identifying and mitigating AI risks (NIST AI RMF)
- Model Development Lifecycle Standard - Governance checkpoints for ML model development (MLOps, ISO 42001)
Automation scripts for compliance evidence collection. See the scripts/ directory for prerequisites and usage.
- AWS Evidence Collector (Python) - Collect SOC 2 compliance evidence from AWS
- GitHub SOC 2 Checker (Bash) - Audit GitHub organization settings against SOC 2 requirements
- Template Generator (Bash) - Generate customized policy documents from templates
See CONTRIBUTING.md for details on how to contribute.
To the extent possible under law, the authors have waived all copyright and related rights to this work. See LICENSE for details (CC0-1.0).