Hael
Sign inRequest a demo
The system of record for AI governance

Pass the AI review.
Win the deal.

Enterprise buyers now screen for ISO/IEC 42001 before they send you an RFP. Hael registers every AI system you build or buy, classifies it against ISO 42001, the EU AI Act and NIST, and produces the sealed records, questionnaire answers and evidence a buyer's security team actually accepts.

app.hael.ai / registry
AI SYSTEMS · 7 IN SCOPE
HAEL BANK · ISOLATED
AGT-014
Customer Onboarding Agent
Owner · M. Okafor · Annex III 5(b)
HIGH RISK
FRD-021Fraud Scoring Model
HIGH RISKHELD OPEN
UND-014Underwriting Copilot
HIGH RISKLIVE
MOD-908Foundation Model v3.4
IN SCOPECURRENT
CHT-102Support Chat Assistant
LIMITED RISKLIVE
AGT-014 · ANNEX IV
Art. 9  Risk management
CTRL-614 · M. Okafor
SOURCED
Art. 14  Human oversight
CTRL-227 · R. Adeyemi
HELD OPEN
Generate Annex IV
ONE RECORD · EVERY ARTEFACT DOWNSTREAM · V2026.07
Annex IV regenerated
CTRL-614 changed · sealed 7f3a…c92e · 09:41
The gate

The AI section of the questionnaire is where deals stall.

Enterprise security questionnaires now carry an AI governance module. The CAIQ and SIG Lite both added one. They ask for model provenance, training-data rights, human oversight, AI sub-processors, and whether you hold ISO/IEC 42001 or a documented roadmap to it. SOC 2 does not answer any of these questions, and buyers no longer accept it as though it does.

Most AI vendors fail this section — not because the questions are hard, but because nothing in their organisation produces the evidence that answers them. Hael produces it, and answers the questionnaire from it, with every answer cited to a sealed record.

See which sections you would fail today →
RFP-2114 · 34 QUESTIONS
SOURCED
Q07 · Model training data provenance
Cited to DAT-021 · foundation model v3.4
SOURCED
Q12 · Human oversight design
Cited to CTRL-227 · R. Adeyemi
ANSWERED
Q17 · Incident notification SLA
Cited to POL-006 · 72h regulator, 24h buyer
ANSWERED
Q21 · Sub-processor list
Pending evidence · vendor D confirmation
HELD OPEN
Q26 · Bias monitoring cadence
Cited to CTL-117 · monthly, last 2026-06-14
SOURCED
Q29 · Post-market monitoring
Cited to AGT-014 · runtime logs, 90-day
ANSWERED
Q34 · Data residency & tenancy
Cited to POL-003 · EU primary, per-tenant keys
ANSWERED
ACME BANK · 33 ANSWERED · 1 HELD · EVERY ANSWER CITED TO THE RECORD
What vendors get

Show up to the review with the answers already written.

Answers the questionnaire
Every AI security and governance questionnaire, answered from your record in minutes, with citations. Held when an answer cannot be grounded, never fabricated.
Stands up a Trust Center
A public assurance page assembled from your record: classifications, controls, evidence behind an NDA gate. The buyer's security team self-serves before they ever email you.
Proves readiness up front
The free framework readiness check shows your standing against EU AI Act, ISO 42001, NIST AI RMF and GDPR: what applies, what buyers expect, and where you stand.
One record

One operating record for every AI system you run.

Hael gives every AI system and agent a single live record — owner, purpose, risk, controls, evidence, vendors, documents and disclosures, together in one place.

Everything else — the documents, the questionnaire answers, the board view, the trust page — is generated from that record. Spreadsheets, policy folders and one-off reviews can't keep up; one record can.

FRD-021 · FRAUD SCORING MODEL
ONE RECORD
EU AI Act
Annex III 5(b) · credit scoring
MAPPED
ISO/IEC 42001
Clause 8.4 · AIMS operational
SOURCED
NIST AI RMF
Govern · Map · Measure · Manage
MAPPED
GDPR
Art. 22 · automated decisioning
SOURCED
Owner
Head of Model Risk
SINCE 2026-05-02
Residual risk
Reviewed weekly · CTRL-614
HELD OPEN
EVERY FRAMEWORK · SAME RECORD · NEVER RE-KEYED
Governance documents

Documents generated from operating state, not templates.

Hael generates the governance artefacts enterprises actually need: technical files, impact assessments, model cards, monitoring plans, vendor evidence packs, board reports and regulator-ready records.

Every claim is tied to the system, control, approval or evidence item that supports it. If the source is missing, the section is held open rather than invented.

FRD-021 · GENERATED ARTEFACT
SEALED
Annex IV · Technical File
FRD-021 · Fraud Scoring Model
14 controls · 12 sources · MRM validated 2026-06-18
SEALEDV2026.06 · 7f3a…c92e
§1 General description
from Registry
SOURCED
§2 Detailed description
from Documents · 12 sources
SOURCED
§3 Monitoring
2 evidence items pending
HELD OPEN
GENERATED FROM OPERATING STATE · NOT A TEMPLATE
Hael Counsel

Ask your governance anything. Get an answer from your own record.

Hael Counsel — your AI governance copilot — answers from your live record and the obligations mapped to it, with every answer cited to the record, control and owner behind it.

It drafts the entry for a new AI system and matches risks to controls. It suggests; your team decides.

app.hael.ai / counsel
Which of our systems are affected by the EU AI Act Annex III changes?
Hael Counsel
Three systems in scope: AGT-014, UND-014 and FRD-021. FRD-021 is held open pending a residual-risk attestation.
AGT-014CTRL-614Annex IV
Ask about a system, control or framework
GROUNDED IN YOUR RECORD · NEVER USED TO TRAIN SHARED MODELS
Continuous governance

When AI changes, the governance record changes with it.

A model update, new data source, changed vendor, new jurisdiction, altered agent permission or fresh incident can change the governance position of a system. A new or amended regulation flags every system it touches.

Hael detects the change, flags affected documents and disclosures, routes the review and preserves the history.

CHANGE EVENT · 14:32
DRIFT
Detected
AGT-014 prompt template changed
14:32:07
Impact
3 dependent artefacts stale
PENDING
Annex IV §2
regenerated · re-sealed
SOURCED
Model card v3.5
regenerated · re-sealed
SOURCED
Trust Center
posture updated
LIVE
RFP-2114 · Q17
answer aged with the record
CURRENT
THE RECORD MOVED · EVERYTHING DOWNSTREAM MOVED WITH IT
Proof

The same record answers every audience.

Boards need oversight. Regulators need evidence. Buyers need assurance. Auditors need traceability. Security teams need control.

Hael gives each audience the right view of the same governance record, so the answer sent to a buyer matches the document reviewed by legal and the evidence retained for audit.

app.hael.ai / trust / audiences
AUDITOR
BUYER
REGULATOR
BOARD
AUDITOR VIEW
ISO 42001 · 8.4
Evidence pack · 14 controls
Sampled read-only · SHA-256 chain verified
SEALED7-YEAR RETENTION
Sampling
read-only auditor access
READ-ONLY
BUYER VIEW
RFP-2114
34/34 answered · cited
ANSWERED
Trust Center
12 controls · NDA-gated
NDA-GATED
Review cycle
closed in 6 business days
6 DAYS
SAME RECORD · SAME SOURCE · DIFFERENT LENS
Board
Current AI posture, risk movement and accountable owners.
Regulator
Governance files, controls, evidence and decision history.
Buyer
AI assurance responses and controlled evidence access.
Auditor
Line-by-line provenance from claim to source record.
For the enterprise

Running AI across the enterprise? Govern the estate on one record.

The record a vendor answers from is the same record an enterprise governs with. Register every system and agent you build or buy, classify each one against every framework in scope, generate the documents regulators and boards ask for, and keep the whole estate current as the rules change.

Model risk, AI obligations and supervisory expectations on one record, for the systems a bank, insurer or asset manager runs.
Board-grade readiness: one defensible posture per system and across the estate, every point explained, no spreadsheet rebuilds.
Built by regulatory practitioners who have authorised and supervised regulated firms over decades of regulatory practice.
HAEL BANK · ESTATE READINESS
71/100
Systems in scope
42 registered · 9 high-risk
CURRENT
EU AI Act
9 systems · Annex IV held
MAPPED
ISO/IEC 42001
certification audit underway
PENDING
Open items
6 gaps · owners assigned
HELD OPEN
Board pack
generated from the estate
SOURCED
ONE POSTURE PER SYSTEM · ONE VIEW OF THE ESTATE
Platform

The full AI governance lifecycle, on one system.

MODULE
Hael Counsel
Three systems fall under Annex III(5). Two have current files; one held open.
↳ AGT-014 · UND-014 · FRD-021
Hael Counsel — grounded answers, intake drafting and risk-matched controls, cited to your record.
MODULE
Registry
UND-014High
FRD-021Limited
CHT-031Minimal
Every AI system and agent captured with owner, purpose, data, vendor, lifecycle and risk state.
MODULE
Classification
AI Act
ISO
NIST
UND-014
FRD-021
CHT-031
Each system assessed against the frameworks, policies and jurisdictions that apply.
MODULE
Documents
Annex IVv2.4
DPIAv1.3
Model cardv1.7
Governance artefacts generated from live records, reviewed and source-linked.
MODULE
Monitoring
Scope changedHIGH RISK
Annex IV staleSTALE
Disclosure heldCOUNSEL
Changes detected, stale outputs flagged and reviews routed.
MODULE
Vendor diligence
AnthropicCURRENT
OpenAIREVIEW DUE
CohereHELD OPEN
AI vendors assessed from both sides of the relationship.
MODULE
Incident response
INC-0214 · output biasHELD OPEN
INC-0211 · data leakSEALED
INC-0207 · driftSEALED
AI incidents recorded, investigated, evidenced and reported.
MODULE
Trust centre
Trust centreLIVE
NDA evidenceNDA-GATED
Buyer requests14 · 7D
A controlled assurance layer for customers, auditors and partners.
MODULE
Evidence & audit trail
Residual risk is reviewed weekly, with quarterly sign-off.
↳ AUR-001 · M. Okafor (GC)
Every claim tied to the evidence, approval and record behind it.
MODULE
Readiness
Estate readiness64 / 100
BAND · DEVELOPING
AGT-014PENDING
A defensible posture score for every system and your whole estate.
MODULE
Regulatory change
EU AI Act · Annex IIIAMENDED
3 systems flaggedREVIEW DUE
ISO 42001 · §8.4CURRENT
When a framework changes, every affected system lights up.
Framework coverage

Mapped to the regimes shaping enterprise AI.

Hael supports the frameworks enterprises are already being asked to evidence across legal, security, procurement and governance reviews.

EU AI Act
ISO/IEC 42001
NIST AI RMF
GDPR for AI
NYC Local Law 144
Colorado AI Act
Custom enterprise policies
CLASSIFICATION MATRIX · LIVE
CoveredScopedN/A
SystemAI ActISO 42001NISTGDPRNYC 144CO AIEnterprise
Customer Decisioning Agent
AGT-014
CoveredCoveredCoveredN/ACoveredScopedCovered
Underwriting Copilot
UND-014
N/ACoveredCoveredCoveredScopedCoveredCovered
Fraud Scoring Model
FRD-021
CoveredCoveredCoveredScopedN/ACoveredCovered
Support Chat Assistant
CHT-031
CoveredN/AScopedCoveredCoveredCoveredCovered
CV Screening Assistant
SCR-330
CoveredScopedCoveredCoveredCoveredN/AScoped
OBLIGATIONS · CONTROLS · OWNERS · EVIDENCE STATE MAPPED PER CELLLIVE
Enterprise foundation

Built for the organisations where AI accountability matters.

Hael is designed for regulated, complex and high-accountability enterprises deploying AI across teams, vendors, products and jurisdictions.

Security, permissions, review history, evidence lineage and controlled sharing are part of the governance model from the start.

TRUST & CONTROL
SEALED
PERMISSIONS
Read
Edit
Approve
General Counsel
CISO
AI Governance
External auditor
AUDIT LOG · LAST 24HEV-9301 → EV-9314
14:32M. Okaforscope.outputs[+ "credit_limit_decision"]
13:18R. Lindqvistapproval.cro · Q3 sign-off
11:04P. Reyescontrol.iso42001.§8.4 · updated
CONTROLLED EXTERNAL SHARING
Trust centreLIVE
NDA evidence roomNDA-GATED4 BUYERS
Regulator packWATERMARKED
Auditor viewREAD-ONLYTIME-BOUND
CHAIN VERIFIED · EV-9301 → EV-9314
See Hael

Bring one live AI system. See the full record.

In one session: register a system, classify it, generate its documents, and answer a real questionnaire from it.