Skip to main content
ISO/IEC 42001Aligned
NIST AI RMFAligned
EU AI ActCompliant
ARCHITECTURE

Not a compliance checklist. An architecture.

EStrategic
AI GovernancePoliciesMaturity DiagnosisOrganizational ContextRegulatory Monitoring
MOperational
AI InventoryImpact AssessmentDecision RegisterIncident ManagementPrompt Library
CControl & Compliance
RisksAuditEvidenceISO 42001 · EU AI Act · NISTAutomatic escalations
SCross-cutting Support
WorkflowVersioningDigital SignatureExportAutomationNotifications

E governs. M executes. C oversees. S enables.

The highest functional density sits at E ∩ C — the GRC core — confirming that SoberanIA is built for AI governance, regulatory compliance, and institutional auditing.

Not to document. To operate.

WHY NOW

Three signals your company needs AI governance today

📊

Investors and auditors ask about AI governance

Investment funds and audit firms already include AI governance in their due diligence. Without a formal framework, your company loses credibility.

📋

Enterprise clients require ISO 42001 in RFPs

Large enterprises are including ISO 42001 as a requirement in their procurement processes. Without certification, you are left out.

🚨

Shadow AI is already happening in your organization

Your teams are already using ChatGPT, Copilot, and other AI tools with corporate data. Without visibility or control, risk grows every day.

HOW IT WORKS

From zero to operational governance in 4 steps

1
📦

Inventory

Register all AI systems in use — including ChatGPT and generative AI tools.

2
⚠️

Risks

Assess the impact and risk of each system using ISO 42001 methodology.

3
📝

Policies

Define and digitally sign your organization's AI governance policies.

4
📊

Compliance Dashboard

Monitor ISO 42001 compliance progress in real time with executive reports.

DIFFERENTIATORS

What no other platform does

SoberanIA includes features that replace tools your company already pays for separately.

🔍

External Auditor Portal

Invite your ISO auditor with a unique, time-limited link. Configure their access window, set entry and expiration dates, and the auditor accesses directly in read-only mode. No internal credentials shared. No team intervention needed. Access automatically revoked when the audit ends.

Included from Professional plan
✍️

AI-Generated Committee Minutes with Digital Signature

Your AI governance committee finishes the session and the minutes are already drafted. AI generates the formal draft in under 30 seconds. You edit, approve, and DocuSign notifies signatories automatically. Minutes digitally signed and archived with full traceability — without leaving the platform.

Replaces: Word + DocuSign + manual management
💬

Shadow AI Control via WhatsApp

Your team already uses WhatsApp for work. SoberanIA gives you a secure corporate channel where authorized users query AI policies, approve documents, and escalate risks directly from WhatsApp. With anomaly detection, plan quotas, and OTP verification. Private AI on Amazon Bedrock — your data never leaves to public APIs.

Unique in the market
📊

How much is your company spending on OpenAI and Anthropic?

SoberanIA syncs real token consumption from each provider's official API. See spending by user, module, and day. Internal platform usage dashboard plus real data from your provider account. No spreadsheets, no surprises at month-end billing.

For CTOs who want real control
🎓

Training with ISO 42001 compliance certificates

Create AI governance training programs with integrated course player, inline quizzes, and a verifiable certificate with unique code. Every employee who completes a module generates automatic compliance evidence linked to the corresponding ISO 42001 controls. Ready for any auditor.

Training evidence ready for auditors

Minimum Viable Governance in 90 days

Inventory, policy, risks, and compliance dashboard — operational in 3 months. No 12-month projects.

USE CASES

Governance for every sector

AI risk looks different by industry — SoberanIA covers them all

🏦

Banking & Fintech

High risk: credit scoring, fraud detection, KYC

  • Document credit model explainability for regulatory audits
  • Bias testing on loan approval algorithms
  • Vendor governance for scoring model providers
Learn more →
🏥

Insurance

High risk: actuarial pricing, claims review, fraud

  • Audit trail for actuarial models for regulators
  • Fair pricing documentation (no discriminatory factors)
  • AI claims decisions — explainable and reversible
Learn more →
💊

Private Healthcare

High risk: assisted diagnosis, triage, resource allocation

  • Impact assessment for diagnostic models
  • Traceability of AI-assisted clinical decisions
  • Governance of sensitive patient data
Learn more →
👥

HR & Recruiting

High risk: AI hiring, performance scoring

  • Bias assessment in CV screening tools
  • Explainability documentation for hiring decisions
  • Employee notification of AI use in HR processes
Learn more →
🛒

Retail & E-commerce

Medium risk: dynamic pricing, recommendations, forecasting

  • Price discrimination documentation
  • Recommendation algorithm transparency
  • ChatGPT usage policy for marketing teams
Learn more →
THE PLATFORM

Each module maps to a specific ISO 42001 clause

6 key modules with visual evidence — not vaporware

ISO 42001 §5.2Legal risk ↓

AI Policy with Digital Signature

Markdown editor with multi-signer digital signature, version control, approval workflow, and full traceability — who signed, when, from where.

AI Policy with Digital Signature — screenshot
ISO 42001 §8.2Shadow AI ↓

AI System Inventory

Inventory with technical metadata, risk level (low/medium/high), compliance status, lifecycle stage, and decision traceability per system. Includes ChatGPT and generative AI.

AI System Inventory — screenshot
ISO 42001 §6.1.2Liability ↓

Algorithmic Impact Assessment

Structured AIIA across 5 dimensions: fairness, privacy, safety, transparency, and autonomy — with weighted scoring and automatic recommendations. Audit-ready output.

Algorithmic Impact Assessment — screenshot
ISO 42001 §8.7Response time ↓

AI Incident Management

Full lifecycle: registration with categorization (bias, data leak, model failure, misuse), responsible assignment, escalation, root cause analysis, and lessons learned.

AI Incident Management — screenshot
ISO 42001 §9.1Board reporting ✓

Compliance Tracking

Real-time progress per ISO 42001 control with evidence uploads, action plans, and executive dashboard. One-click exportable compliance report to PDF.

Compliance Tracking — screenshot
ISO 42001 §8.5ChatGPT control ✓

Prompt Library

Centralized corporate prompt library: approved prompts by role, data classification rules, prohibited model list, and usage analytics. The control layer for ChatGPT, Copilot, Gemini, and Claude.

Prompt Library — screenshot
ISO 42001 COVERAGE

Normative coverage — 6 key areas

Each clause mapped to a SoberanIA module

��️
ISO 42001:2023

First international standard for AI Management Systems

🇺🇸
NIST AI RMF

NIST AI Risk Management Framework

🇪🇺
EU AI Act

Regulation 2024/1689 — Risk-based classification

ISO ClauseAreaBusiness RiskSoberanIA ModuleStatus
§5.2AI PolicyNo accountability when AI failsPolicy + Digital Signature
§8.2AI System InventoryShadow AI, undocumented modelsAI System Inventory
§6.1.2Algorithmic Impact AssessmentDiscriminatory decisions, lawsuitsImpact Assessments
§8.7Incident ManagementUndetected bias, regulatory exposureIncident Management
§9.1Compliance TrackingInvisible compliance driftCompliance Tracking
§8.5Generative AI ControlShadow AI, IP leaks, hallucinationsPrompt Library
INTEGRATION HUB

Connect the AI your teams already use

Centralize control of ChatGPT, Copilot, Claude, and Gemini from SoberanIA. With your own API keys, corporate SSO, and legal electronic signatures.

Integration Hub Enterprise

Connect ChatGPT, Copilot, Claude, and Gemini with your own API keys, enable login with your corporate directory (Google Workspace or Microsoft 365), and send documents for electronic signature with DocuSign — all from the same AI governance panel.

LLM FinOps

AI spending visibility by area, user, and project. Soft monthly limits per provider and alerts when approaching the cap.

Corporate SSO

Login with Google Workspace or Microsoft 365 account. Automatic provisioning (JIT) and roles mapped to your company directory.

DocuSign Electronic Signature

Send policies, contracts, and governance documents for signature directly from the platform. Real-time webhook and full traceability.

PRICING

Plans for every governance stage

Platform + Implementation — choose the right plan for your company

For CTOs and Compliance teams

MVG

Pricing based on your governance readiness
  • ✅ Signed AI policy
  • ✅ 1 governed AI system
  • ✅ 35-control ISO 42001 baseline
  • ✅ Critical system AIIA
  • ✅ Governance committee activated
  • ✅ Initial team training
  • ✅ 90 days platform included
  • ✅ Guarantee: 60% compliance or 50% refunded

* For companies with existing governance, implementation cost is quoted based on your current governance state, documented AI systems, and registered risks. → Request a custom quote

Companies with basic governance, need platform

Growth

Per-user pricing · minimum 5 users
  • ✅ Full platform access (15 modules)
  • ✅ ISO 42001 compliance dashboard
  • ✅ Prompt Library
  • ✅ Incident management
  • ✅ Email support

Multinationals, corporate groups

Enterprise

Custom quote
  • ✅ Everything in Professional
  • ✅ Unlimited users and AI systems
  • ✅ API integrations (ERP, GRC, SIEM)
  • ✅ SLA + dedicated account manager
  • ✅ 12-month post-implementation support
  • ✅ External ISO 42001 auditor included
🏅

Founding Member — only 10 spots until June 2026: 90 days platform at no cost + 30% discount on MVG consulting during the first year. In exchange: logo on homepage, shared case study at 90 days, 1 callable reference per quarter.

FOUNDING MEMBERS

Founding Members Program

Be part of SoberanIA's founding group

10 spots7 remaining

Deadline: June 30, 2026

What you receive

  • ✅ 90 days platform at no cost
  • ✅ Consulting discount
  • ✅ Access to product roadmap
  • ✅ Direct line to the founder
  • ✅ Monthly virtual advisory board

What we ask in return

  • 🤝 Logo on SoberanIA homepage
  • 🤝 Shared case study at 90 days
  • 🤝 1 callable reference per quarter
  • 🤝 Monthly product feedback

Apply to the program

The founder

Juan David Vallejo Robayo

I've spent over 15 years building technology and seeing the same pattern repeat: organizations adopt faster than they structure. Today that challenge is called AI. I built SoberanIA so that AI can stop being an experiment and operate with traceability, control, and accountability.

View on LinkedIn →
FAQ

Frequently Asked Questions

Everything you need to know before getting started

Have more questions? Talk directly with our team.

AI Governance Assessment — Free

22 questions, 5 minutes — discover your company's real exposure to AI risk

Question 1 of 22 (5%)

🏛️ Policy & Governance 💡 A policy documents principles, responsibilities, and procedures for AI use

Does your organization have a formal AI use policy?

Governance shouldn't live in documents.
SoberanIA turns it into an operating layer.

Start with the platform — operational governance in 48 hours. Add guided implementation when you need it.