Eight questions, in the order they rule a vendor out
Ordered by what eliminates options fastest rather than by what is most interesting to discuss. A tool that cannot model your role cannot produce your obligations, so that question comes before anything about dashboards or integrations.
| Ask | Why it decides something | A good answer |
|---|---|---|
| Which frameworks does it actually carry, and at what depth? | Most tools claim several and implement one properly. The difference shows in whether it holds clause-level records or a checklist named after the standard. | A named list, with what each one produces. Ask to see the obligation set for one of your systems — not a feature matrix. |
| Does it model your ROLE, or only your systems? | Under the EU AI Act a provider and a deployer of the same system owe different duties, and one organisation can hold both roles for different systems. A tool that records only the system cannot derive either duty set. | Role is recorded per system and the obligations change when it changes. Article 16 duties for a provider, Article 26 duties for a deployer. |
| What does it produce that you could hand to someone? | The deliverable is the point. Registers and dashboards are how you get there; an Annex IV file, a fundamental rights assessment or a Statement of Applicability is what an auditor, a customer or an authority actually asks for. | Named documents you can export, with the data behind each field traceable to who entered it and when. |
| Where does your data live, and who processes it? | You are buying compliance software with compliance data in it. Hosting and sub-processors are a GDPR question about your own processing before they are a preference. | A published sub-processor register, a data processing agreement you can read before buying, and a straight answer on where the AI features run. |
| Does evidence count once, or once per framework? | One control often satisfies obligations under more than one regime. If the tool cannot reuse a record across frameworks, you will maintain the same evidence several times. | One evidence record linked to every obligation it closes, with the basis for each reuse stated rather than assumed. |
| Is the price published? | An unpublished price is a sales cycle, and for an organisation under fifty people it is usually also a signal that you are not the customer the product was built for. | A price list with limits on it. If it is quote-only, ask what the smallest deployment they have sold looks like. |
| What happens when the law changes? | The EU AI Act timetable moved twice in 2026. A tool that hard-codes dates and article numbers into content rather than deriving them will quietly teach you a superseded rule. | A dated record of what changed and when the content was last reviewed against the consolidated text. |
| Can you get your data out? | Compliance records outlive vendor relationships, and some of them carry statutory retention periods measured in years. | Export in a structured, machine-readable format, available without asking, and a written retention position for after you leave. |
Five categories, and who each one is for
"AI governance software" covers products built for different buyers. Most shortlists go wrong at this step rather than at the feature comparison: an enterprise governance suite and an EU-AI-Act-native tool are not competing for the same organisation, and comparing them feature by feature hides that.
| Category | Examples | Who it suits | What to watch for |
|---|---|---|---|
| Enterprise GRC suites | OneTrust, TrustArc | Large organisations that already run privacy, security and third-party risk in one place and want AI governance to join it. | Priced and implemented for that scale. The EU AI Act module is one of many, and the buying cycle is a procurement cycle. |
| AI governance platforms | Credo AI, Holistic AI, Saidot | Organisations with a model portfolio and a data-science function, wanting policy, risk and model oversight together. | Strongest where there are models to govern. Less useful if you mostly BUY AI rather than build it, which is most SMEs. |
| Security compliance automation | Vanta, Drata, Scytale | Teams whose first need is SOC 2 or ISO/IEC 27001 and who want the EU AI Act alongside it on one control set. | Built around continuous control monitoring of infrastructure. Depth on the Act itself varies, and evidence of a passing control is not an Annex IV file. |
| EU-AI-Act-native tools | Veritome, Legalithm, EuroComply | European organisations whose driver is the Act specifically, and who need the documents rather than a dashboard. | Younger products with smaller ecosystems. Ask what happens when your scope widens beyond the Act. |
| Consultants and law firms | Advisory engagements | A one-off classification question, a contested Article 6 call, or a board that needs an opinion signed by someone insured. | Advice is not a system of record. The obligations recur; a report does not update itself, and published SME readiness estimates run well into five figures. |
Do these two things before you book a demo
Count your AI systems and write down what each one does. Almost every shortlist is built before this exists, and it is the input every vendor will ask for in the first ten minutes. It also tends to settle the decision on its own: an organisation with three limited-risk systems and one framework is buying something different from one with twenty systems and a high-risk classification.
Establish your role for each one. Provider, deployer, importer or distributor — and it can differ per system. The duties, the documents and therefore the tool you need all follow from it. Our free obligation check answers both in about five minutes and stores nothing.
Questions people ask before they buy
Do I need AI governance software at all?
What is the difference between AI governance software and GRC software?
How much should this cost?
Can any tool make my organisation compliant?
Should I wait, given the timetable moved?
How many frameworks should one tool cover?
- Twelve tools comparedWhat each product actually produces, with sources — the shortlist version of this page.
- Veritome vs the alternativesHead-to-head tables, including where each competitor genuinely wins.
- Check what you oweNine questions, no account, nothing stored. The input every vendor will ask you for.
- The five frameworksWhat each one asks, what it does not give you, and where they genuinely meet.