AIQURIS · The AI Lifecycle Management Platform

Every AI deployment,
under control.

Go to the platform

AI is moving faster than organisations can control it.

AIQURIS works out the risks, requirements and controls of every AI deployment, tracks whether they are in place, and keeps them current. So AI deployments go live faster, with a clear basis for every decision.

From one deployment to your entire AI portfolio. For SMEs and enterprises alike.

WorkspaceILLUSTRATIVE
Alex Chen

AI register

Every deployment, with its risk, its status and what needs attention.

Deployments registered42Across 6 business units
Assessments completed6938 IMPACT+ · 24 RISK+ · 7 CONTROL+
Reviews needing attention72 due within 14 days
DeploymentOwnerIMPACT+RISK+StatusNext action
Visual defect inspectionComputer vision · AI-024Manufacturing qualityModerateModerateReview due Review changed contextDue 6 Oct · context change recorded
Candidate screening assistant ↗Decision support · AI-031Talent acquisitionMajorCriticalIn assessmentProvide control evidenceDue 29 Sept · 24 required actions open
Credit origination affordability assistantDecision support · AI-009Risk and lendingMajorCriticalReassessmentProvide testing evidenceDue 4 Oct · 3 controls open
Grid load forecastingPredictive AI · AI-052Network operationsModerateModerateIn operationReview on material changeCondition-based · last assessed 8 Aug
Contract summarisation copilotGenerative AI · AI-066Legal and compliancePendingPendingAwaiting triageComplete IMPACT+ triageRegistered 9 Sept
Internal knowledge chatbotGenerative AI · AI-018IT and operationsMinorNot requiredIn operationScheduled reviewDue 15 Nov
Showing 6 sample deploymentsSee one deployment in detail ↗

Every deployment in one AI register, with its risk, its status and what needs attention. Control, deployment by deployment. Visibility across all of them.

The challenge

You have policies. You test. You monitor. You have experts.
So where's the gap?

Deployments still stall in pilot, or go live with unmanaged risk.

01Generic

Policies and frameworks

Set requirements for AI in general. They don't say what a deployment needs, or whether it is in place.

02Partial

Testing

A snapshot. Only one of many controls a deployment needs.

03Partial

Monitoring

Covers selected aspects, after the fact. Shows what happens, not what should be controlled.

04Manual

Expert assessments

Manual and person-dependent. They don't scale, and go out of date when a deployment changes.

None of them works out what each deployment needs, or keeps it current.

AIQURIS closes the gap.

It works out what your specific deployment needs, maps it against what you already do, and shows what's missing, at every stage of the AI lifecycle.

Because it starts from the risks of the actual deployment, it is:

  • Deployment-specific, not generic.
  • Comprehensive, not partial.
  • Automated, not manual.

Decide with confidence. Defend with evidence.

Why it is hard

Same AI system. Different risk.

AI risk is hard to tell. It cuts across disciplines, differs by deployment and changes over time, and the controls differ with it. Below, one system in four sectors: same technology, four different risk profiles.

SAME SYSTEM · FOUR CONTEXTS Knowledge assistant: answers staff questions from internal documents
Risk domainFinancial servicesAdvisers answering client product questionsHealthcareClinicians checking treatment guidelinesDefence & critical infrastructureControl-room operators querying operating proceduresManufacturingTechnicians querying machine maintenance manuals
SafetyNegligibleCriticalHighCritical
SecurityHighHighCriticalModerate
PerformanceModerateHighHighHigh
Legal complianceCriticalHighHighModerate
EthicsModerateHighModerateLow
SustainabilityLowLowLowLow
Deepest controls onLegal complianceSafetySecuritySafety
The system is the same. The risk and the controls are not. Illustrative profiles. Actual severities are derived for each deployment.

So risks and controls have to be worked out deployment by deployment, and updated whenever something changes.

How it works

Walk through your deployment.
AIQURIS works out the rest.

A guided intake captures everything that matters about your deployment. The engine then applies the standards, regulations and policies AIQURIS maintains, and works out the risks, requirements and controls it needs to be safe, perform and comply.

The AIQURIS method: governing sources (standards, sector frameworks, regulations, contracts, policies) are applied to the deployment and its context, worked out by AIQURIS into impact, risk, controls, evidence and remaining risk, leading to a go-live decision and AI under control.
Standards
Sector Frameworks
Regulations
Policies
Contracts
DeploymentContext
Impact
Risk
Controls
Evidence
Remaining risk
Go-liveDecision
AI under
control
Governing Sources Worked out by AIQURIS AI under control

Every control is linked to its source and to the evidence it requires.

The missing link

The critical connector between AI governance and your AI deployments.

Governance sets the rules. Teams build and run the deployments. Legal, cybersecurity, risk and the business each see one part. AIQURIS sits in between and connects them all: which rules apply to each deployment, where it stands, and who acts next.

How the engine works
AI governancePolicies, standards, regulations
Requirements for each deployment
  • Business ownerGo-live decision
  • AI CoETests and technical controls
  • CybersecuritySecurity controls
AIQURISAI LIFECYCLE
MANAGEMENT
  • LegalRegulatory obligations
  • Risk, compliance and governanceRisk exposure, evidence, compliance status
Status and evidence
AI deploymentsSystems, data, models, operations
Top to bottom: from the rules to what each deployment needs.Across: every function gets its part from one place.

It doesn't add to your stack. It connects it.

Example

Find the gaps before go-live, not after.

One real deployment, traced from risk to evidence. AIQURIS assessed a candidate screening assistant before its recruitment pilot went live.

Candidate screening assistant

Decision support · AI-031 · Talent acquisition
01What AIQURIS found
5 exposure areas12 findings24 required actions
02One risk, traced to evidence
RISK

Hiring fairness and discrimination Critical

Protected attributes or proxy signals could unfairly exclude candidates from progressing.

REQUIREMENT

No automated rejection

Protected attributes must not influence results.

CONTROL

Human review and attribute testing

Human review before any rejection. Testing that protected and proxy attributes do not affect scores.

EVIDENCE

Results and records

Test results against defined thresholds. Review records showing that people made the decisions.

The other four exposure areas
Critical

Regulatory compliance and transparency

The published privacy policy does not describe the AI assistant, creating a blocker for screening decisions.

High

Human oversight and workflow control

Interface defaults, hidden filtering or cut-offs could turn decision support into automated exclusion.

High

Screening quality and validation

Ambiguous criteria and extraction errors could produce unreliable scores and ranking errors.

High

Data privacy and vendor assurance

Applicant data in prompts, responses and logs requires verified minimisation, retention and vendor controls.

03The outcome

RECOMMENDATIONProvide evidence for the critical controls before go-live.

DECISIONTalent acquisition held the pilot until the evidence is in.

Summarised from an AIQURIS assessment of a real deployment. Ratings are before mitigation (inherent risk).

Know the risks, and exactly what to do, before go-live.

Lifecycle

After go-live,
control continues.

One connected record across the deployment's life, shared by every function involved. When the deployment or its governing sources change, requirements, controls and evidence are updated together.

  1. 01Define
  2. 02Assess
  3. 03Implement and decide
  4. 04Operate
  5. 05Change and review
  6. 06Retire
GO-LIVE
↺ Material change returns to assessment

EXAMPLE The approved job criteria changed after go-live. Requirements reassessed, controls reopened, evidence updated, decision on continued operation updated.

Every product includes reassessments. CONTROL+ adds defined change triggers.

The deployment changes. The controls keep up.

Products

The right depth for every AI deployment.

One platform, three levels of depth. Start with IMPACT+ and go deeper only where the risk calls for it, so effort and cost match the deployment.

IMPACT+

What can go wrong?

Who could be harmed, and how badly.

YOU RECEIVE
  • Deployment registered in the AI register
  • Affected stakeholders and potential harms
  • Impact tier
  • Routing: limited follow-up, or RISK+
RISK+

How does it go wrong?

How the harm could occur, and which controls address it.

EVERYTHING IN IMPACT+, PLUS
  • Risk profile across all six risk domains
  • Applicable requirements and high-level controls, as a checklist
  • Declared control status and open gaps
  • High-level testing and monitoring guidance
  • Recommendation: proceed, or move to CONTROL+
CONTROL+

What prevents it?

AI Assurance: the controls in detail, the remaining risk, the evidence.

EVERYTHING IN RISK+, PLUS
  • Assessment against the relevant standards, regulations and your own policies, clause by clause
  • Detailed controls, test protocols and monitoring specifications
  • Vendor assessment
  • Remaining (residual) risk, measured against your risk appetite
  • Lifecycle: change triggers and reassessment
FOR SMEs

No AI governance team needed. Start with one deployment and pay per deployment.

FOR ENTERPRISES

One AI register for the whole portfolio. CONTROL+ where the risk calls for it, with expert-supported setup.

The higher the stakes, the deeper the control.

AIQURIS co-founders Dr Martin Saerbeck (left) and Dr Andreas Hauser (right)
AIQURIS co-founders Dr Martin Saerbeck and Dr Andreas Hauser.

Why AIQURIS

Decades of safety-critical expertise.
Behind every assessment.

AIQURIS was founded by Dr Andreas Hauser and Dr Martin Saerbeck. Engineering, certification, digital systems and mathematical modelling, now applied to AI. Seven years developing the AIQURIS methodology, the early years within TÜV SÜD’s global AI quality practice. AIQURIS is independent.

ISO/IEC 42001ISO/IEC 5259IEEE 7000 series

Selected standards contributed to. Meet the founders and explore their standards work ↗

“The solution AIQURIS presented is the first I know of in the market that closes the gap by combining AI risk management and requirements from technical standards in a tool-based way.”
Head of AI Data and Compliance
Leading German automotive OEM

Expert knowledge, applied automatically to every deployment.

PROGRAMMES AND MEMBERSHIPS
IMDA Spark CompanyAI Verify Foundation member

IMDA Spark Company · AI Verify Foundation member

STANDARDS COMMITTEES
  • ISO/IEC JTC 1/SC 42
  • DIN
  • Enterprise Singapore · SMF

The team sits on the committees that write the AI standards.

CUSTOMERS IN
  • Public transport
  • Healthcare
  • Pharma
  • Maritime
  • Telco

FAQ

What buyers ask before they start.

Straight answers to the questions we hear most in client conversations.

How does AIQURIS make sure the relevant risks of an AI deployment are identified?

AIQURIS applies a structured, risk-based method grounded in established risk engineering, the same way for every deployment.

It starts with the stakeholders and potential impacts, links them to hazards and risks, identifies the regulations, standards and other governing sources that apply, and derives the requirements and the controls that meet them. It is not a black-box LLM producing an answer: the method runs on a structured knowledge graph and ontology, so every requirement can be traced back to its source, its risk and its control.

The result is only as good as the description of the deployment, which is why AIQURIS guides that step closely.

How the engine works

Isn't this just a sophisticated due-diligence questionnaire?

No. A questionnaire starts with fixed questions. AIQURIS starts with the deployment: its use case, context, risks and applicable requirements.

The questions that go to a vendor or an internal team are generated from that analysis, so an HR screening tool and a medical AI system get very different questions. Generic procurement and governance questionnaires do not make that distinction at deployment level.

Is an AI risk assessment a one-off, or does it stay current?

It stays current. Every AIQURIS assessment includes 12 months of platform access, during which the deployment is reassessed when something material changes.

There are three triggers: changes to the regulations or standards that apply (AIQURIS tracks them and can alert you); changes to the deployment itself, such as its use, data or context; and material changes by the AI vendor, such as a new model or new capabilities.

This is triggered reassessment across the AI lifecycle, not real-time monitoring. Where continuous monitoring is needed, for example of bias, a specialist tool can do that, and the assessment shows where it is needed.

See the lifecycle

How long does an AI risk assessment take?

Hours or days, not months.

A traditional expert assessment of a single AI deployment typically takes three to nine months. With AIQURIS, IMPACT+ and RISK+ take a few hours, and CONTROL+ a few days. The AI Deployment Assessment Sprint takes one real deployment through an assessment within three weeks, with five hours of your team's time.

About the Sprint

What is AI lifecycle management?

AI lifecycle management keeps each AI deployment under control, from first idea to retirement.

The risk comes from the deployment: what the AI is used for, where, by whom and with which data. The hazards behind that risk can arise at any point in the AI lifecycle, from data and training to integration, operation and change. So the controls that address them have to be established along the whole lifecycle, not just checked once at go-live.

AI lifecycle management works out the risks, requirements and controls for each deployment, tracks whether the controls are in place at every stage, and keeps them current as the deployment, the regulations or the technology change. AIQURIS is the platform for it.

Which product do I need: IMPACT+, RISK+ or CONTROL+?

Start with IMPACT+. The deployment's impact and risk decide how deep you need to go.

IMPACT+ screens the deployment: who could be harmed, and how badly. It sets an impact tier and routes you to limited follow-up or to RISK+. RISK+ builds the risk profile across all six risk domains, with the applicable requirements and high-level controls as a checklist, and recommends whether to proceed or move to CONTROL+. CONTROL+ goes clause by clause through the relevant standards, regulations and your own policies, specifies the controls in detail and determines the remaining risk against your risk appetite.

CONTROL+ is not only for high-risk deployments: use it wherever you need that depth. Not sure where to start? The AI Deployment Assessment Sprint is the guided way in.

See the products

What kinds of AI can AIQURIS assess?

Any AI deployment, whether you build it or buy it.

This includes, for example, predictive and machine-learning systems, computer vision, generative AI such as chatbots, copilots and assistants built on large language models, and agentic AI. It covers systems developed in-house as well as AI bought from vendors; for bought AI, the vendor is part of the assessment.

What matters is not the technology but the deployment: the same model can carry very different risks in different uses. Deployments where AI controls safety-relevant hardware are scoped individually in a first call.

How does AIQURIS relate to ISO/IEC 42001 certification?

ISO/IEC 42001 certifies your AI management system. AIQURIS makes it concrete for each AI deployment, and that makes certification much easier to prepare.

ISO/IEC 42001 requires organisations to assess the risks and impacts of their AI systems and to establish controls across the AI lifecycle. AIQURIS does exactly that, deployment by deployment, and produces the documented, traceable basis an auditor expects to see.

It also shows which requirements of the standard your organisation actually needs, and in what depth, given the AI deployments it really has. That puts your management system and its Statement of Applicability on a factual basis, instead of implementing everything just in case.

AIQURIS is not a certification body: its outputs support a certification audit but do not determine its outcome. The AIQURIS founders were actively involved in developing ISO/IEC 42001.

Does AIQURIS help with EU AI Act compliance?

Yes. For every deployment in the EU, AIQURIS works out which EU AI Act obligations apply and whether they are met.

What the AI is used for, and in which context, sets its risk classification under the Act, and with it obligations such as human oversight, transparency, data governance and record-keeping. AIQURIS turns them into requirements, links them to the controls that meet them and records the evidence, in the same assessment as data protection law and the other sources that apply.

The AIQURIS team sits on the committees that write the standards, so it knows the harmonised standards being developed for the EU AI Act and how to interpret them. AIQURIS does not give legal advice, and the decision stays with you.

Which regulations and standards does AIQURIS assess against?

The ones that apply to your deployment, worked out for its use and its jurisdiction.

AIQURIS maintains the governing sources for you: regulations such as the EU AI Act and data protection law, international standards such as ISO/IEC 42001, ISO/IEC 25059 and ISO/IEC 5259, industry frameworks, and your own internal policies where relevant.

Singapore, the EU, the UK, Australia and the US are covered as standard. Other jurisdictions are available on request.

How does AIQURIS work with our existing GRC platform?

AIQURIS does not replace your GRC platform; it feeds it. It provides the deployment-specific AI risks, requirements and controls that a general governance, risk and compliance environment usually does not contain.

The results can be mapped into the structure you already use, from an Excel control register to an enterprise GRC system. AIQURIS is API-based, so outputs can be integrated directly, subject to your required format and your GRC provider allowing the integration. The aim is not a parallel AI risk process, but AI-specific detail inside the risk and control environment you already run.

How does AIQURIS assess third-party AI vendors?

It looks at two things: the AI solution and how the vendor develops and governs it.

For the solution, AIQURIS asks for evidence matched to the identified risks, such as accuracy, robustness or penetration test results, or data-quality evidence. For the vendor, it covers development processes, training data, data governance and organisational controls.

Vendors do not just answer yes or no. Where it matters, they must provide reports, test results or certifications. Missing evidence is never treated as a requirement met: less transparency means more uncertainty, a potentially higher assessed risk and additional controls. Material vendor statements should then be reflected in the contract, so the vendor is accountable for them.

Does AIQURIS replace testing of the AI system?

No. AIQURIS determines which testing a deployment actually needs.

The sequence is the same as in security: first establish what can go wrong and which requirements apply, then decide on the controls. Those controls may include penetration testing, robustness testing, data-quality testing or other technical validation. Testing without that step risks being arbitrary: you test what is easy to test, not what matters. Where your risk appetite calls for independent testing in a particular area, it becomes one of the required controls.

How does AIQURIS cover cybersecurity requirements for a specific jurisdiction?

In two steps. First, AIQURIS identifies which regulatory, cybersecurity and standards documents apply to the deployment and its jurisdiction, drawing on its regulatory knowledge, research and external sources where appropriate.

Second, those documents go through the same method as every other governing source and are translated into deployment-specific requirements and controls. Cybersecurity is therefore not a separate exercise but part of the same structured assessment, alongside the other five risk domains.

Who is responsible for the decision to deploy an AI system?

Your organisation. AIQURIS gives you a documented, traceable basis for the decision, but the decision to deploy, and to accept the remaining (residual) risk, stays with you.

Because the method is standards-based, repeatable and recorded, the assessment also shows which method and state-of-the-art practices were applied at the time. That helps you demonstrate due diligence later, to auditors, regulators or your board.

Does AIQURIS replace legal advice or our compliance team?

No. AIQURIS does not give legal advice. It carries out a compliance assessment: it identifies which regulatory requirements apply to a specific AI deployment and assesses whether they are met.

A lawyer interprets the law. AIQURIS translates the applicable requirements into concrete requirements and controls for that deployment, much as technical certification does for products. The advantage over a purely manual approach is consistency: two consultants may assess the same deployment differently, while AIQURIS applies the same method and the same six risk domains every time. Your legal and compliance teams stay in charge, with a structured basis to work from.

What information does AIQURIS need from us, and how is it protected?

A description of the deployment. Access to the AI system itself is only needed where the assessment calls for it.

AIQURIS needs to understand the deployment: its purpose, users, data categories, jurisdiction, the system and vendor, and the controls already in place. The assessment does not need access to the AI system, your models or your production data. Access only becomes relevant once a specific requirement calls for it, for example a penetration test or a monitoring solution, and then only for that purpose. Where evidence is needed, such as test reports, you share the documents.

All information is protected and encrypted in line with current best practice. If it must not leave your own environment, AIQURIS can run inside it.

Can AIQURIS run in a contained environment?

Yes. The AIQURIS platform is containerised and can run in any environment, including your own cloud or on your premises.

The language model component can run inside it too, as a containerised model, where one is available and accepted by your organisation. Deployment information, source documents and results then stay inside your perimeter.

No black box. A traceable basis for every decision.

Get started

Start with an Assessment Sprint.
Five hours of your team's time.

The AI Deployment Assessment Sprint is guided by AIQURIS from start to finish. We prepare the assessment; your team gives five hours across three sessions. Within three weeks, you have one real deployment assessed at RISK+ depth, and actions with named owners.

01

Briefing. 1 hour

Choose a deployment, in planning or already in production. AIQURIS then screens its impact and prepares the risk profile, requirements and controls.

02

Workshop. 3 hours

The accountable stakeholders in the room. Validate the risks, challenge the controls, agree what closes the gaps.

03

Readout. 1 hour

Leave with an assessment record and an action list with named owners. Run the next deployments yourself on the platform.

Questions first? Contact info@aiquris.com

From one deployment to your entire AI portfolio.

Dashboard and lifecycle views are illustrative.

Privacy Overview

We use cookies to operate our website, ensure its proper functioning, improve performance, analyse traffic, and support our marketing activities. Some cookies are strictly necessary and cannot be disabled. Others can be enabled or disabled below according to your preferences. For full details, please see our Privacy Policy.