A framework-neutral AI governance assessment for organisations that build, buy or use AI. It is anchored to POPIA section 71 (automated decision-making, the operative South African legal hook, since no AI-specific statute is yet in force) and King V Principle 10, and aligned with ISO/IEC 42001 and the NIST AI Risk Management Framework. It covers AI policy and accountability, a system inventory, impact assessment, bias and transparency, human oversight, and generative-AI acceptable use, the biggest real exposure for most organisations.
This framework contributes to the following governance domains in your Encircle score:
Encircle scores your AI governance across the domains it touches and asks for the artefacts that make AI oversight real, an AI policy, a system register, impact assessments, human-oversight records and a generative-AI acceptable-use standard. Because it is framework-neutral, a single assessment maps onto POPIA, King V, ISO/IEC 42001 and NIST at once. Every gap becomes an assigned remediation task.
Encircle tells you when your AI governance is in place, the policy, inventory, impact assessments and oversight controls a responsible organisation should hold. This is governance readiness, not certification; ISO/IEC 42001 certification, where you want it, is issued by an accredited body.
Live demo
The same organisation seen through the AI Governance lens. Red is where the exposure is. Switch lens to see how the picture changes under another framework.
Select a framework
AI Governance: no AI policy, system register or generative-AI acceptable-use standard evidenced. AI & Data craters to 18%, pulling Technology, Compliance and Ethics with it.