PLATFORM · FEATURES

Everything a consultant needs to deliver structured AI governance — and nothing they don't.

EdenTouch AI Governance Delivery OS is built around a single delivery cycle: inventory, risk, vendor, decisions, actions, quarterly review, report. Every feature serves that cycle. Nothing is there for show.

CORE MODULES

The full governance delivery stack.

Every module connects. Risk feeds decisions. Decisions feed actions. Actions feed the quarterly review. The quarterly review generates the report. The structure is the product.

Consultant Portfolio Dashboard

Your operating cockpit. See every active client, their governance health score, overdue actions, and the single most important next step — across your entire portfolio, at a glance.

Client Workspaces

Each client gets a fully isolated workspace. AI systems, risk assessments, vendor evaluations, decisions, evidence, and reports — all separated by design. No data crosses between clients.

AI Inventory

Document every AI system a client is using. Vendor, use case, data types, who is affected, human oversight level, lifecycle stage. The foundation that every risk assessment and governance decision builds on.

Risk Assessments

Four-category risk triage: Technical, Compliance, Business, and Ethical. Likelihood and impact scored. Plain-English risk summaries generated. Board-ready findings — not raw numbers.

Vendor Evaluations

Eight structured evaluation sections — from training data and bias testing through to contract readiness and incident history. Surface red flags before they become client problems.

Governance Decisions

Record every governance decision against an AI system: Approve, Approve with Conditions, Reject, Escalate. With rationale, conditions, approver, and review dates. Accountability by design.

Action Tracker

Turn risk findings into assigned, tracked actions. Owner, priority, due date, status — per workspace, per client. Nothing falls through the cracks between quarterly reviews.

Incident Log

Log and track AI incidents as they happen — technical failures, bias issues, data concerns, vendor problems. Build a structured record that informs the next quarterly review.

Quarterly Review Engine

The retainer engine. Structure every quarterly review with a full health snapshot — new systems, risk changes, vendor updates, incidents, overdue actions. Then generate the board-ready report.

Report Generation

Eight report types. AI Inventory, Risk Assessment, Vendor Evaluation, Incident, Quarterly Governance Health — generated in minutes, branded for your practice, ready to go to the client.

Evidence Library

Organise governance evidence across ten document types. Upload to platform storage or connect the client's Microsoft SharePoint — so evidence lives in their environment, not yours.

Shadow AI Intake Queue

Let people report AI tools they see in use — no admin access needed to submit. Triage as a Consultant Partner or Organisation Admin: promote to inventory, document as low-risk, flag for investigation, or close. Every triage decision logged. Surface what's happening before it becomes a governance gap.

Governance Guide AI Assistant

The embedded intelligence. Summarises risk assessments, flags what is missing, drafts executive briefings, prepares meeting agendas, and identifies the single most important next action. Always with the practitioner in charge.

EU AI ACT READINESS

Structured readiness review — not compliance certification.

A layered readiness workflow that helps you and your clients prepare for EU AI Act obligations through evidence, oversight documentation, and ongoing review — supported by EdenTouch, not determined by it.

AI Act Classification

Classify each AI system by role, risk class, and Annex III domain. Flag potential prohibited-use concerns for expert review — without making legal determinations.

Evidence & Obligation Tracking

Document oversight owners, transparency measures, GPAI dependencies, and deployer obligations. Link evidence to every requirement area and surface coverage gaps.

Change Monitoring

Log meaningful changes to AI systems — purpose, data, vendor, oversight. Flag substantial-change indicators and trigger reassessment actions that feed into quarterly reviews.

Readiness Evidence Pack

Compile inventory, risk, vendor, and evidence data into a client-ready readiness pack with an executive summary and delivery language templates.

Management System Readiness View

See governance maturity across seven categories using qualitative signals — Emerging, Developing, Established. A readiness lens, not a compliance score.

Delivery Language Templates

Reusable scope statements, disclaimers, and executive intros — written in the careful language of readiness review, not compliance certification.

These features support structured AI governance readiness review. They do not provide legal advice, regulatory certification, conformity assessment, or a guarantee of compliance.

MULTI-JURISDICTION READINESS

One inventory — three readiness contexts.

Beyond the EU AI Act, EdenTouch supports US and UK readiness lenses — plus a consultant-populated relationship map that shows how every system, data source, and vendor connects. Each context is a readiness layer — not a legal determination.

US Context Readiness

Apply a NIST AI RMF maturity lens — Govern, Map, Measure, Manage signals. Screen for NIST AI 600-1 generative AI considerations. Flag high-impact sectors and note state-level AI laws. A US readiness layer — not a legal determination.

UK Context Readiness

Assess against the UK's five cross-sectoral AI principles. Screen by sector regulator. Record UK GDPR, AI assurance evidence, NCSC secure AI considerations, and AI Security Institute advanced AI risk notes. A UK readiness layer — not regulator approval.

AI Relationship Map

Document how AI systems, data sources, vendors, human roles, and output destinations connect. Feeds into, depends on, supplies data to, oversees, escalates to, produces output for. Trace propagation paths — what happens downstream if one system changes or fails. Consultant-populated — no automated discovery.

These readiness contexts support structured governance review across geographies. They do not provide legal advice, regulatory certification, regulator approval, or a guarantee of compliance.

DATA SOVEREIGNTY

Microsoft storage — built in, not bolted on.

Where clients ask "where does our governance data live?" — you have a clear, honest answer. Three optional Microsoft integrations that move control closer to the client.

Microsoft Sign-In

Authenticate using existing Microsoft 365 credentials. No new password to manage. Identity handled by Microsoft.

OneDrive Report Export

Generated reports export directly to your personal OneDrive. The platform does not retain a copy. Your reports stay yours.

SharePoint Evidence Storage

Client evidence uploads directly to their connected SharePoint. The platform holds a reference. The client owns the file.

These integrations support client-controlled document workflows. They do not guarantee legal compliance, regulatory certification, or data residency obligations.

FOR CONSULTANTS

What the platform makes possible.

These are not marketing promises. They are what the delivery cycle is designed to produce — for every client, in every engagement.

  • Move a new client from discovery to first governance report in a single structured session.
  • Run quarterly retainer reviews with a consistent structure every time — no rebuilding from scratch.
  • Deliver board-ready documentation that reflects the quality of your practice.
  • Give clients a clear, ongoing record of every AI governance decision made on their behalf.
  • Scale your practice without scaling your overhead.

AI INTELLIGENCE LAYER

Governance Guide is not a chatbot. It is a delivery partner.

Embedded across every workflow, Governance Guide reads your workspace data and helps you move forward — risk summaries in plain English, gaps identified before the report reaches the client, executive briefings structured for board-level audiences, next actions prioritised by what matters most.

The practitioner stays responsible. Every output is for review and refinement — not for copying and sending.

How Governance Guide works →

Ready to see it in a real governance workflow?

Pilot access is structured, selective, and built for consultants who have a real use case to test against.