Category 12 of 12 · Controls: Accountability and evidence
AI governance and GRC
Inventory, policy, risk assessment, and evidence collection for AI systems and agents, mapped to frameworks such as the EU AI Act, ISO 42001, and the NIST AI RMF.
Vendors, by signal score
- #1Credo AI10
AI governance platform: a registry of AI use cases, models, vendors, and agents with agent cards, risk and control libraries including agentic risks, policy packs for the EU AI Act, NIST AI RMF, and ISO 42001, and audit-ready reporting.
- #2PromptArmor10
AI third-party risk intelligence for the agent supply chain: vendor reports scored across 26 AI risk vectors and mapped to the NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS, indirect prompt injection assessment of vendor connectors, and continuous monitoring of vendor AI changes.
Ranked within this category only. How the score works.
Also covers this category
- Aurascape23
AI usage control and agent governance: discovers public, embedded, and shadow AI apps and agents, protects sensitive data in prompts, governs coding assistants, and routes agent tool calls through a gateway that enforces policy before actions reach external systems.
- Securiti AIAcquired by Veeam30
Data security posture management, privacy, and AI governance platform; its Gencore AI builds permission-aware retrieval pipelines with prompt, retrieval, and response firewalls. Acquired by Veeam in 2025.
- Zenity49
Agent security and governance platform: catalogs agents across SaaS, custom frameworks, and endpoints, correlates each agent's identities with its tools, data, and behavior, and detects and blocks prompt injection, data leakage, and unauthorized tool calls at runtime.
Questions to ask a vendor
- Does the inventory include agents and their owners, not only models?
- Does it collect evidence automatically from your runtime controls?
- Which frameworks does it map to out of the box?
Go deeper
FAQ
- Where do I compare AI governance platforms in depth?
- GRC Compass keeps the full governance vendor profiles and a buyer guide. This map lists governance vendors only where they cover agents.
- What does ISO 42001 certify?
- An organisation's AI management system: its policies, roles, and processes for developing or using AI. It does not certify that a specific model or agent is safe.