Hael
Book a meeting
Resources

The AI governance knowledge centre.

Framework guides, the vendor playbook, honest comparisons, the regulatory brief library and free tools — one entry point, kept current by the people producing the artefacts.

Diagnostics

Two diagnostics you can run today

The same first questions we ask in a scoping call, without the call. Both give you a written result you can put in front of your board.

Readiness check

Where you stand against SOC 2, ISO 27001 or ISO/IEC 42001, and which sections of a buyer review you would fail today.

Open →
AI impact assessment

Risk tier, the obligations that follow, and the artefacts an assessor will ask to see for one AI system.

Open →
Security reviews

Security questionnaires, explained

The CAIQ, the SIG, the DDQ and the VSA, and the AI section that now sits inside all of them. What each one is, who sends it, and what a strong answer looks like.

What is the CAIQ?

The Cloud Security Alliance's standard questionnaire, built on the Cloud Controls Matrix.

Open →
What is the SIG questionnaire?

Shared Assessments' heavyweight of third-party risk. Core and Lite, both now carrying AI content.

Open →
What is a vendor DDQ?

The catch-all name for the bespoke questionnaires enterprises assemble in-house.

Open →
What is the VSA questionnaire?

The Vendor Security Alliance's standardised questionnaire, used widely across technology procurement.

Open →
The AI section

Where reviews now stall, and what a buyer expects to be shown.

Open →
All questionnaire guides
Model answers

The answer library

Every question in the CAIQ and SIG Lite AI section, with a model answer, the evidence a buyer expects behind it, and why the weak version fails. Free, no sign-up.

The answer library

Ten questions across five categories, written the way we would answer them for a client.

Open →
Open the answer library
Frameworks

Framework guides

Plain-English guides to the frameworks we take clients through, cited to the source and kept current.

ISO/IEC 42001

The AI management system standard enterprise buyers now screen for.

Open →
EU AI Act

High-risk obligations translated into artefacts and controls.

Open →
NIST AI RMF

Govern, Map, Measure and Manage, mapped to enterprise controls.

Open →
GDPR Article 22

Automated decision-making: lawful basis, DPIA, ROPA and the Article 22 tests.

Open →
All frameworks
Working with your stack

Alongside your compliance platform

Most clients already run Vanta, Drata, Secureframe or Sprinto. The platform holds the evidence. We produce it, and take you through the audit.

Working alongside compliance platforms

What the platform does, what the auditor does, and what sits with us.

Open →
Regulatory library

Regulatory briefs

Short, dated briefs on the questions boards and buyers actually ask, each cited to the instrument it interprets.

Regulatory library

Dated and cited. Written by the people who deliver the engagements.

Open →
Browse the library
Insights

Insights

Longer pieces on certification, internal audit and buyer assurance, written for the people who have to operationalise it.

Insights

Published guides from our practitioners.

Open →
All insights

See Hael run against one of your own AI systems.

Request a walkthrough, or explore the platform in your own time.

Book a meetingExplore the platform