ENGRAP AI
The governance, risk and assurance platform for every AI system your organisation runs.
ZNYX enforces policy on each call. ENGRAP owns the layer above it: what AI you run, who approved it, which risks were accepted, what evidence exists and what a supervisor would be shown on a Tuesday with two weeks’ notice. It is a register and an assurance workflow, not a dashboard of green ticks.
Six things a compliance lead stops chasing over email.
Each module stands alone, and all of them read from the same register, so the risk team, the model owners and the auditors finally see one version of the estate.
Every model, agent, prompt-based feature and embedded vendor capability, with owner, purpose, data classes, deployment stage and dependencies recorded rather than remembered.
Structured assessment against the frameworks you are held to, with obligations derived from the classification instead of chosen by whoever filled in the form.
Model cards, data statements, evaluation summaries and change history generated from what the system actually is, with gaps flagged as work items.
Evidence pulled from your pipelines, evaluation runs and runtime logs on a schedule, so assurance is a continuous record rather than a pre-audit scramble.
Review gates, quorum, conditions and residual-risk acceptance, with the decision and its rationale attached to the system it governs.
Board, regulator and customer views of the same underlying register, produced without a quarter of spreadsheet reconciliation.
Governance fails between the policy and the model, not in the policy.
Sits beside the platforms you already govern with.
ENGRAP is the assurance layer, not another place to work. It reads from your MLOps stack, your ticketing system and ZNYX, and writes obligations back as tasks in the tools people already open.
A defensible register in eight weeks.
Inventory workshops plus automated discovery across cloud accounts, vendor contracts and code, to find the AI nobody registered.
Risk classification for what we found, with obligations derived per system and the high-risk set queued for full assessment.
Automated evidence collection connected for the priority systems, so the controls start producing a record immediately.
Review gates, approval workflow and the first board pack, run once with us in the room and then handed over.
Common questions
ZNYX is runtime: it evaluates prompts, outputs, tool calls and retrieval against policy and returns a decision inside your perimeter. ENGRAP is organisational: it holds the inventory, the risk assessments, the documentation, the approvals and the evidence. They are useful separately and stronger together, because ENGRAP can prove what ZNYX enforced.
Often you need both. Generic GRC tools model controls well but know nothing about models, evaluations or prompt changes. ENGRAP carries the AI-specific record and pushes obligations into the GRC tool you already run.
The EU AI Act, ISO/IEC 42001 and the NIST AI Risk Management Framework are mapped out of the box, and internal policies can be added as first-class frameworks with their own obligations.
Less of it than you expect. Inventory and evidence are collected automatically where a system exists; humans supply purpose, context and judgement. The aim is that nobody re-types what a pipeline already knows.
Yes, scoped and read-only, to a specific system or framework for a specific period, with their access itself recorded.
Bring us your hardest question from an auditor.
Send the question you least want to be asked about an AI system in production. We will show you what ENGRAP would have on file to answer it.
Book a governance review→