AI governance software buyer's guide and RFP checklist

Every GRC vendor now sells an AI governance module, and most of them are a register with a policy library bolted on. This guide sets out the capabilities that genuinely matter, the RFP questions that expose weak products, and a scoring model you can reuse.

Michael McCarroll25 years in IT governance Last verified August 2026
12 min read

Decide what problem you are buying for

Three buying triggers dominate, and they lead to different shortlists. The first is procurement pressure: buyers are asking AI questions and you need credible published answers fast. The second is regulatory scope: you are a provider or a deployer of high-risk systems under the EU AI Act and need documentation and conformity artefacts. The third is certification: you have committed to ISO 42001 and need a management system, not a register.

Write your trigger down before you take a demo. Vendors optimise their pitch for the largest addressable pain, which may not be yours, and a tool that is excellent at generating public trust statements can be weak at technical documentation — and vice versa.

  • Trigger 1: sales and procurement questions blocking deals.
  • Trigger 2: regulatory obligations under the EU AI Act.
  • Trigger 3: ISO 42001 certification programme.
  • Trigger 4: internal risk after an AI incident or near miss.

Capabilities that actually matter

Beyond the inventory and the policy library, the capabilities that separate useful tools from expensive spreadsheets are remediation, evidence and integration. Remediation means the platform tells you what to do about a failed control in plain English, names an owner, sets a due date and chases it. Evidence means artefacts are captured with dates, versions and approvals so an auditor can verify them without a workshop. Integration means the AI programme shares its risk register, actions and evidence vault with your ISMS.

Also test role modelling. The AI Act's provider and deployer duties differ substantially, and many tools implicitly assume you are one or the other. If you build an AI feature and also use third-party assistants internally, you need both modelled in the same workspace with different assessment templates.

  • AI system inventory with owners, data flows, providers and hosting regions.
  • AI impact assessment and DPIA in one workflow, versioned with sign-off.
  • Control mapping to ISO 42001 Annex A, ISO 27001 and EU AI Act articles.
  • Remediation actions with owners, due dates and automated reminders.
  • Evidence vault with immutable dates and export packs.
  • Public trust statement or trust centre for buyer self-service.
  • Integrations: identity, ITSM/Jira, cloud posture, document storage.

The RFP question set

Send the same twelve questions to every vendor and compare the answers side by side. Vague responses on data handling and export are the clearest early warning signs; a vendor that cannot tell you how to get your data out is telling you something about the next renewal.

  • How do you model provider vs deployer duties for the same organisation?
  • Which frameworks are mapped out of the box, and how are mappings maintained?
  • Show an impact assessment produced by the tool, exported as a PDF.
  • How are remediation actions assigned, chased and evidenced as complete?
  • What does the auditor-facing evidence export contain?
  • Which AI features exist in your own product, and what happens to our data?
  • Where is our data hosted, and what are your retention and deletion terms?
  • How do we export everything if we leave?
  • What integrations exist with our ISMS, ITSM and identity provider?
  • What is the realistic implementation effort in customer days?
  • What is included in the price, and what is metered?
  • Which reference customers of our size and sector can we speak to?

Pricing traps to check before signing

Per-AI-system pricing creates a perverse incentive to under-report your inventory, which is the opposite of what governance requires. Metered AI assistance can be reasonable, but ask for the cap and the overage rate in writing. Implementation packages sold as mandatory are common in enterprise GRC and often exceed year-one licence cost — check whether self-onboarding is genuinely supported.

Finally, model three years rather than one. Many tools price aggressively in year one and rely on renewal uplift once your evidence lives inside them. A clean export path is your only real negotiating leverage at renewal, which is why it belongs in the RFP.

A scoring model you can reuse

Score each vendor out of five on six weighted dimensions and require the proof of concept to move the score, not the sales deck. Weight evidence and remediation highest, because they are where AI governance stops being paperwork; weight breadth of framework coverage lowest, because most vendors claim everything and the mappings are rarely the constraint.

  • Evidence quality and export (weight 25%).
  • Remediation and workflow (25%).
  • Fit to your role and use cases (20%).
  • Integration with existing ISMS and tooling (15%).
  • Total three-year cost including implementation (10%).
  • Framework coverage and mapping maintenance (5%).

Score us against your own checklist

ISO-STANDARD.app covers AI inventory, impact assessments, remediation with named owners, evidence exports and a public trust profile — and shares one risk register with your ISO 27001 workspace. Run the proof of concept with your own AI systems.

ISO-STANDARD.app ships a ready-to-adopt AI governance software workspace with the risk register, controls catalogue, policies and audit-ready exports already wired together — no spreadsheet sprawl, no consultant lock-in.

Free downloads for this topic

Prefer a conversation? Email hello@iso-standard.app — a real human responds within one business day.

Frequently asked questions

What is AI governance software?
Software that maintains an inventory of AI systems, assesses and records their risks and impacts, holds the policies and controls that manage them, tracks remediation, and produces the evidence needed for frameworks such as ISO 42001, the EU AI Act and enterprise buyer questionnaires. Good tools sit alongside — or inside — an existing information security management system rather than beside it.
Do we need dedicated AI governance software or can our GRC tool cope?
If your GRC platform can model AI systems with their data sources, model providers and affected people, run AI-specific impact assessments, and evidence human oversight, extending it is cheaper. If it can only hold a generic risk register with an 'AI' tag, you will end up managing the real work in documents. Test with a real AI use case before deciding.
What should AI governance software cost?
For an SME, expect low hundreds of pounds per month for a workspace including AI governance alongside ISO 27001 and privacy modules. Standalone enterprise AI governance suites are typically five figures a year plus implementation. Watch for per-AI-system pricing, which punishes you for maintaining an honest inventory.
How do we run a fair proof of concept?
Pick two real AI systems — one internal assistant, one customer-facing feature — and give every vendor the same task: register them, complete an impact assessment, raise and assign a remediation action, and export the evidence pack. Time each step and read the exported output as an auditor would. Scripted demos hide exactly the friction you will live with daily.
Related guides

Not sure where you stand? Score your ISMS against clauses 4–10 and Annex A in a few minutes.

Free gap analysis
Trust & security
ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation
← All guidesHome →