AI risk management companies, products & suppliers
AI risk-management products score and treat risks across AI systems — privacy, safety, security, third parties — often mapping to NIST AI RMF or ISO-style processes. Buyers want a risk register with treatments, not a chatbot policy.
What is AI risk management?
AI risk-management products score and treat risks across AI systems — privacy, safety, security, third parties — often mapping to NIST AI RMF or ISO-style processes. Buyers want a risk register with treatments, not a chatbot policy.
What problems does it solve?
Risk is discussed in slides but not recorded against a live system with an owner and due date.
Typical business use cases
- Risk registers
- Vendor AI risk
- Treatment tracking
Important capabilities
- Scoring
- Workflow
- Framework mapping
- Reporting
What buyers should evaluate
- Framework fit
- Scoring transparency
- Integration to inventory
Risks and governance considerations
Traffic-light scores with no test underneath.
Procurement checklist
- Methodology disclosure
- Export
- Link to systems
- Owners
Relevant AI Trustmark assurance
Trustmark risk class is independently determined during assessment and is not imported from a vendor GRC score.
Companies and providers
Claimed suppliers appear first so buyers can start with listings the company has taken ownership of. Payment does not buy this order.
Archer publishes Archer Evolv Risk, Archer AI Governance, and Archer IRM as named AI products. Archer is used for AI risk management and Regulatory compliance work. Archer is recor
Operationalize Trusted AI governance with Credo AI: discover AI, enforce policies, prove compliance, and manage risk across every model, agent, and application. Credo AI publishes
Diligent's trusted GRC software helps boards and leaders clarify risk, elevate governance, and manage compliance in one secure, AI-powered platform. Diligent publishes Diligent Hig
Optro’s AI Governance solution ensures compliance, manages risk, and drives responsible AI innovation at scale. FairNow publishes FairNow AI Governance Platform as named AI product
Holistic AI is the leading enterprise AI governance platform. One end-to-end tool to identify, protect, and enforce AI governance at scale. Holistic AI publishes Holistic AI Govern
LogicGate Risk Cloud is the leading AI-powered GRC platform with 30+ applications for enterprise risk, third-party risk, cyber risk and compliance management. LogicGate publishes L
Manage Tomorrow’s Surprises Today with LogicManager’s Leading (ERM) Enterprise Risk Management Software. Improve Performance with a risk-based approach to ERM. LogicManager is used
MetricStream provides Governance, Risk and Compliance (GRC) software solutions that allow companies across various industries to streamline and automate their enterprise-wide GRC p
Microsoft Corporation sells Windows, Azure, Microsoft 365 and Copilot AI products. Public pages cover cloud, productivity and developer APIs used by enterprises and consumers. Micr
The world’s largest risk management software provider offers the ability to reduce risk, increase efficiency, and improve organizational performance. Riskonnect publishes Riskonnec
SAI360 publishes SAI360 Regulatory Compliance Manager, SAI360 Policy Management, and SAI360 Enterprise & Operational Risk as named AI products. SAI360 is used for AI risk managemen
ServiceNow sells workflow software for IT, customer and employee operations, with Now Assist AI features. Public pages cover enterprise workflow platforms. ServiceNow publishes Ser
Products
Claimed products appear first. Ranking packs and payment do not change this list.
- Archer Evolv Risk· Archer
- Archer IRM· Archer
- Diligent One Platform· Diligent
- FairNow AI Governance Platform· FairNow
- LogicGate Risk Cloud· LogicGate
- LogicManager· LogicManager
- MetricStream ConnectedGRC· MetricStream
- Riskonnect Integrated Risk Management· Riskonnect
- SAI360 Enterprise & Operational Risk· SAI360
- ServiceNow Integrated Risk Management· ServiceNow
Also used in this category
These products have a different primary category so they do not compete for the same ranking queries. They are listed here because buyers still encounter them in this job.
- Credo AI Governance Platform· Credo AI
- Holistic AI Governance Platform· Holistic AI
- Microsoft Purview AI Hub· Microsoft
Related categories
Relevant procurement and assurance guides
Frequently asked questions
Will this change a Trustmark score?
No. Directory and GRC tools cannot buy or alter independent assessment outcomes.
What is AI risk management?
AI risk-management products score and treat risks across AI systems — privacy, safety, security, third parties — often mapping to NIST AI RMF or ISO-style processes. Buyers want a risk register with treatments, not a chatbot policy.
Is an AI governance questionnaire the same as independent verification?
No. Governance platforms help an organisation inventory systems and attest to policy. They do not replace independent testing of a production product. A completed questionnaire is operator documentation unless independently sampled.
What human oversight should buyers specify for consequential AI decisions?
Oversight is not a confirm button. Buyers should specify who can approve or stop an outcome, whether they have time and competence, what they see, and how that review is logged. Independent assessment records the oversight that was evidenced for the named scope.
What model or provider changes should a buyer insist on being told about?
Material change usually includes a new model family, new region, new subprocessor, new write-capable tool, or a change that affects logging, privacy or human oversight. Those changes should trigger evidence refresh rather than a silent release.
How should buyers verify where AI customer data is processed?
Ask for the named processing locations, cloud regions and any subprocessors that see prompts, files or outputs. A directory listing is not evidence of residency. Independent assessment records the locations that were in scope on the assessment date.
Does a TrustMark on one product cover the rest of the company?
No. Independent assessment is scoped to the named organisation and, where relevant, the named product. Category pages list suppliers as a topic label. They do not imply that every listed company has been assessed.
What incident-handling evidence is useful for AI suppliers?
Buyers should see how AI-specific failures are detected, contained and notified — including unsafe outputs, data leakage and unauthorised agent actions. An incident policy that never mentions models, prompts or tools is incomplete for this class of product.