Exploring Risk and Compliance

  • Release version: Zurich
  • Updated May 13, 2026
  • 2 minutes to read
  • Risk and Compliance in AI Control Tower provides visibility into risk, compliance, and governance status across your AI portfolio.

    Risk and Compliance overview

    Risk and Compliance in AI Control Tower provides governance visibility for AI systems at both the portfolio level and the individual AI system level. These views provide governance visibility into risk, compliance, and governance status without requiring users to work directly in the underlying governance workflows.

    The Risk and Compliance views show summarized governance signals across AI assets. These signals include action items, regulatory risk classification, compliance posture, compliance score, aggregated risk posture, and risk heat maps. The generated summaries help stakeholders identify trends, prioritize attention, and focus on higher-risk areas of the AI portfolio.

    At the AI system level, Risk and Compliance views provide more specific context for a single asset. Users can review regulatory classification status, compliance score, and compliance posture for priority frameworks. Users can also review aggregated risk rating, risk heat maps, and related governance records such as assessments, risks, controls, issues, and policy exceptions.

    AI Control Tower surfaces these governance outcomes for visibility and oversight. Risk assessments, control execution, remediation, and other governance activities are managed through related governance solutions and supporting workflows.

    Risk and Compliance users

    Table 1. Users
    User Description
    AI governance stakeholder Uses portfolio-level summaries to understand overall governance posture, identify priority action items, and monitor how AI assets are classified and governed across the organization.
    AI steward or asset stakeholder Uses the asset-level Risk and Compliance view to understand the governance posture of an individual AI system, including its assessment status, compliance score, aggregated risk rating, and related governance records.
    Governance reviewer Uses framework-specific and risk-specific views to understand which areas require follow-up, such as unresolved issues, incomplete assessments, ineffective controls, or missing governance data.

    Risk and Compliance benefits

    Table 2. Benefits by feature
    Feature Benefit Users
    Top action items Identify high-priority governance work that requires immediate attention. AI governance stakeholder, governance reviewer
    Regulatory risk classification Understand how AI assets are grouped by regulatory acceptability and identify assets that require closer review. AI governance stakeholder, governance reviewer
    Compliance score and compliance posture for priority frameworks Understand compliance posture for configured frameworks and see where issues affect governance coverage. AI governance stakeholder, AI steward or asset stakeholder
    Aggregated risk rating and risk heat map Understand how inherent risk and control effectiveness influence residual risk for an AI system. AI steward or asset stakeholder, governance reviewer
    Assessments, risks, controls, issues, and policy exceptions Review governance records associated with a specific AI system without leaving the AI system context. AI steward or asset stakeholder