Enterprise · 500+ employees

Portfolio governance, board-grade output.

One AI system is a project. Two hundred AI systems is a portfolio. Veritome gives compliance, risk and IT a single instrument for the whole estate — with the role-based access, the audit trail and the exports for your records and counsel that the audit committee asks for.

No card · EU-hosted · 5 minutes to a first classification
Veritome systems portfolio — every AI system with its role, risk tier and journey position
What we hear from groups

Three problems consultants do not solve.

What we hear

Every business unit has its own list. We don't have one register.

What the product does

Multi-organisation and multi-team support out of the box. One register at group level, segmented views per unit, the same engine underneath.

What we hear

Our quarterly compliance update is a slide deck someone hand-makes.

What the product does

The dashboard already has the numbers — portfolio completion, averages by tier, gate blockers, near-complete systems. The board summary is generated as a sealed PDF.

What we hear

Audit asked for evidence per system per article. Nobody could produce it on the day.

What the product does

Evidence attaches at obligation-item level, hash-sealed. The regulator-view dossier exports per system; the public verify URL means auditors do not need a login.

What changes at scale

Built for the 200-system estate, not the 2-system pilot.

01

Multi-organisation architecture

One identity, many organisations: each subsidiary keeps its own systems and obligations; group leads switch between them from one login.

02

Role-based access and SSO

Compliance, risk, IT, business-unit owner — with OIDC single sign-on. Permissions enforced at the API.

03

Phase gates across the portfolio

Six gated phases per system; the dashboard surfaces every system stuck behind a gate so the bottleneck is visible.

04

Risk-tier weighted scoring

Portfolio progress is risk-weighted, with a breakdown by tier. A prohibited system zeroes the portfolio.

05

API, webhooks and MCP

A REST API with an OpenAPI spec, outbound webhooks and an MCP server. Run Veritome beside ServiceNow, Jira or your GRC tool.

06

An audit trail you can produce

Every change logged with the user, the timestamp and what changed; hash-chained and anchored daily. Breaks are surfaced, not hidden.

In practice

Three estates, three governance models.

Use case 01

A retail bank with 80 in-house models — provider for proprietary risk models, deployer for vendor systems.

  • Separate organisations keep the in-house provider obligations apart from the vendor-deployer obligations.
  • The phase-gate view surfaces the systems blocked at Assess — exactly where conformity assessments are pending.
  • Each model's Annex IV assembles from the model card, the risk plan and the governance plan.
  • The quarterly board pack is the portfolio view, generated as a sealed PDF.
Veritome obligations register — engine-derived duties with owners, dates and status
Use case 02

A multinational pharma group with 30 AI systems across R&D, clinical and commercial.

  • Annex III §5 (essential services) and §3 (education) systems trigger different obligation sets.
  • The FRIA runs for the public-impact systems and is passed on the others.
  • The regulator-view dossier is the artefact the authority asks for; the verify URL spares the audit team a dozen email threads.
  • The AI-literacy programme is tracked group-wide for the Art. 4 sign-off.
Veritome reports — the organisation compliance report, board summary and audit-preparation pack as sealed PDFs
Use case 03

An insurance group consolidating risk management, GDPR and EU AI Act work into one instrument.

  • The Art. 9 risk plan integrates with the enterprise risk register via the API.
  • Residual sign-off feeds the Solvency II ORSA narrative — same evidence, two regimes.
  • GPAI obligations on internally fine-tuned models tracked separately from third-party deployments.
  • The AI-literacy programme distributed across the group; completion per subsidiary.
Veritome AI literacy — six role-based training programmes with per-person completion tracking for Article 4
What enterprises lean on

The capabilities that scale with the estate.

Straight answers

Questions groups ask

Can one instrument hold a group with several subsidiaries?

Yes. One identity, many organisations: each subsidiary keeps its own systems, classifications and obligations, and group compliance leads switch between them from one login. A group-level view rolls the estate up for the audit committee.

How does Veritome fit beside ISO/IEC 27001 and NIST AI RMF?

Both run as programmes on the same register. The clauses ISO/IEC 42001 and 27001 share are one record each, and a NIST AI RMF profile is generated for the counterparty who asks for one. Coverage is one matrix, exportable per framework.

Is there an API?

Yes — a REST API with an OpenAPI 3.1 specification, outbound webhooks for system, incident, obligation and evidence events, and an MCP server. Run Veritome beside ServiceNow, Jira or your GRC tool and share evidence both ways.

What does the board see?

The dashboard already has the numbers — portfolio completion, averages by risk tier, gate blockers, systems near completion — and the board summary is generated on a schedule as a sealed PDF. A prohibited system zeroes the portfolio; there is no hiding behind an average.