Versatile AI Risk Assessment

Understand AI risks, assess them transparently and manage them with confidence

Versatile AI Risk Assessment brings system context, threats, controls, the EU AI Act and GDPR together in one continuous assessment. You receive a clear risk rating, prioritised actions and an audit‑ready evidence package for approvals, internal reviews and customer questions.

  • System context, threats and controls in one assessment
  • EU AI Act and GDPR classified in a structured way
  • Share risk ratings, actions and evidence directly
The result

From assessment to a sound basis for decisions

Versatile AI Risk Assessment connects risk ratings, prioritised actions and regulatory classification with the evidence your teams need for approvals, reviews and further work.

Example evaluation from the demo assessment: metrics, risk matrix and threats sorted by residual risk. Example data.
  • Risks classified consistentlyInherent risk, residual risk and work status for each AI system at a glance.
  • Action needs prioritisedCritical threats, missing controls and open actions become visible and can be addressed deliberately.
  • Regulatory classification documentedRole, risk class, obligations and points relevant to GDPR and DPIAs remain recorded in a traceable way.
  • Evidence ready for further usePDF reports, XLSX, CSV and JSON plus connections to EAM and ITSM systems for approvals, reviews and further work.
Community Edition

Try it, keep working freely, download modules

The live demo is already the full Community Edition. Your working state stays local in your browser and can be preserved and re‑imported as a versioned project file. Use the application freely for personal work, education, research and nonprofit purposes.

Full application

Keep working freely

Choose the risk model; both editions use the same catalogues and keep their working states separate.

Standard model (additive)

Finely graded risk values from 0 to 11 based on protection level, likelihood and exploitability. For detailed comparison and prioritisation.

Start without the example project

3×3 matrix edition

The classic matrix of likelihood and impact in three levels each. For working with the established three‑level grid.

Start without the example project

The example project shows the methodology in a fully completed assessment and can be removed in the application at any time. PDF reports carry a Community watermark.

Free downloads

Single subject areas as modules

Each module of the full application is also available on its own: free of charge, as a single HTML file, entirely local in your browser.

  • KI‑Risiko‑Check

    Threat and risk analysis with 52 curated threats, risk matrices and baseline comparison.

  • EU‑KI‑VO‑Check

    Guided assessment under the EU AI Act down to the EU risk class, with obligation catalogue and deadlines.

  • DSGVO‑Check

    Data protection assessment with DPIA screening: 93 questions in 10 sections and a role‑based obligation status.

For commercial use, the full application and the modules are available as Professional editions. Get in touch

The challenge

When answers are missing, AI governance becomes a bottleneck

Every AI application needs three clear answers: What is in use? How was it assessed? Why was it approved? When this information is scattered, delays and additional review effort follow.

What is in use?

The purpose, status, owners and criticality of new AI applications are not captured centrally. The actual inventory remains unclear.

How was it assessed?

Data protection, information security, legal and business teams document their findings separately. There is no aligned risk picture.

Why was it approved?

Rationale, conditions and evidence are not linked end to end. Decisions can only be evidenced later with additional effort.

If one answer is missing, the basis for the decision remains incomplete.

Versatile AI Risk Assessment in use

Insights from the assessment workflow

From system context to GDPR classification: every view comes from the Community Edition and shows how inputs, assessments and evidence work together.

How Versatile AI Risk Assessment creates transparency

How a traceable AI risk assessment takes shape

Versatile AI Risk Assessment connects capture, threat analysis, risk assessment, regulatory classification and exports in one continuous workflow. Each step builds traceably on the previous one.

  1. Capture the system and deployment context

    Record purpose, data categories, owners, deployment phase and criticality of the AI system.

  2. Determine relevant threats

    Apply the curated catalogue, check relevance and assess inherent risk.

  3. Document controls and residual risk

    Record existing and planned actions, their rationale and the remaining residual risk.

  4. Assess the EU AI Act and GDPR

    Document role, risk class, obligations, data protection questions and DPIA needs for professional review.

  5. Export and connect evidence

    Prepare reports and machine‑readable formats for approvals, reviews and downstream systems.

  • CMDBLinked to the configuration item
  • ITSM toolsAttached to tickets & changes
  • EA repositoryPlaced in the system landscape
  • AI inventoryAI register · EU AI Act
  • Risk register (GRC)Residual risks into the GRC tool
  • ISMS & auditISO 27001 · internal audit
Which working context is yours?

Four situations. Four fitting ways to use Versatile AI Risk Assessment.

Good governance does not start with a feature list, but with the people who carry responsibility. Find the situation that reflects your work – and see immediately which version supports it.

Peter, Katrin, Anna and Thomas are fictional example profiles with illustrative quotes, not customer testimonials.

Peter wants to understand how it works.

Data protection · Information security · Research & education

Before starting a project, Peter wants to work through a structured AI risk assessment himself – with no installation, user account or commitment.

“I want to experience the method through a complete example before deciding on productive use.”
  • Work through a complete example assessment
  • Assess threats and controls himself
  • See the EU AI Act and GDPR in context
  • Generate a PDF report and back up the working state as a project file
The right version for PeterFree of charge

Community Edition

The complete application with example data runs directly in the browser. No server, no sign‑up and no transfer of assessment data.

  • Ready immediatelyNo installation or implementation project.
  • Professionally completeAssessment, classification and PDF report.
  • Portable working stateAuto‑save plus a project file for backup and device transfer.
  • Non‑commercialPersonal use, education, research and nonprofit work.
Transparency and trust

Create transparency. Be transparent.

Assessment data stays in the browser. The application works without tracking and discloses its components, vulnerability status and licences. This allows IT, information security and procurement to review it themselves before approval.

The review dossier with every delivery Four pieces of evidence you can verify yourself before approval.
  • SBOM Bill of materials for every component View directly
  • VEX Vulnerability status for the SBOM View directly
  • Licence inventory Licences used in the build View directly
  • Content assurance Catalogue version, sources and checksum Full scope: Professional / Enterprise View the summary

All evidence comes from the current Community bundle and ships with every delivery. IT, information security and procurement can verify it independently. The professional catalogues currently comprise 2,546 reviewed content items from 63 named sources (threat analysis, EU AI Act, GDPR/EDPB).

Pricing for the offline editions

Purchase once, use indefinitely

The Community Edition remains free for the long term. Professional and Enterprise are purchased once; the delivered version remains usable indefinitely. Maintenance, updates and support are renewed after twelve months when needed.

Terms for Professional and Enterprise

Licence model Purchase once Use the agreed version for the long term.
Included in the price 12 months of maintenance Updates and the stated support.
Afterwards Renew when needed No automatic renewal.
Community Edition

Work locally and non‑commercially free of charge

Free for the long term
€0

for the permitted non‑commercial scope

Included in the first year Community updates as available
Scope
  • Assessment: system context, threats, the EU AI Act and GDPR
  • Local working state: auto‑save and a versioned project file
  • PDF report: with a Community notice for non‑commercial use
Ongoing cost €0 no renewal required
Start the live demo
Professional Offline

Assess and manage AI systems in production

One‑off licence price
€2,490
plus VAT

per named‑user licence

Included in the first year 12 months of maintenance, updates and email support
Scope
  • Portfolio: manage multiple AI systems locally
  • Complete exports: PDF, DOCX, XLSX, CSV, JSON and OSCAL
  • Productive use: commercial rights and robust evidence packages
From year 2 €490 / year optional, with no automatic renewal
Request a 30-minute fit check
Enterprise / White‑Label Offline

Integrated into your brand and system landscape

Starting price
from €12,900
plus VAT

per organisation and agreed delivery scope

Included in the first year Core white‑label configuration, acceptance documents and 12 months of maintenance
Scope
  • White label: adapt brand, language and appearance
  • Your methodology: integrate catalogues, models and templates
  • System handovers: connect EAM, GRC and ITSM processes
From year 2 from €1,980 / year based on the agreed delivery scope
Request a fixed‑price proposal
The business case for your budget

Why €2,490 often pays for itself with the first AI system

A manual AI risk analysis under the EU AI Act and GDPR ties up expert resources or drives consulting costs. Versatile AI Risk Assessment turns it into structured work of hours instead of days. Typical market ranges for orientation:

Approach Typical effort Outcome and risks
Manual review in Excel or Word 25–40 working hoursoften €2,500–4,000 of internal effort per AI system Scattered spreadsheets, patchy evidence and heavy coordination between IT, legal and the business unit.
External consulting €4,000–12,000per assessment or engagement A one‑off report with a fixed cut‑off date: every later change is commissioned and paid for again.
SaaS platform subscription €6,000–15,000 per yearongoing, roughly €500–1,250 per month Recurring costs, vendor dependency and assessment data in a third‑party cloud.
Professional Offline €2,490 one‑offoptional €490 per year from year two Often pays for itself with the first system: all data stays local, standardised review reports, usable indefinitely.

For independent auditors and data protection consultants: the licence is often recouped with the first billed client engagement.

Versatile AI Risk Assessment ConnectedDesign partner preview · not generally available

One shared working state for teams, roles and approvals, operated in your environment

Versatile AI Risk Assessment Connected brings the complete assessment workflow into central multi‑user operation. Teams work on the same state, access follows clear roles, sign‑in runs through your identity provider, and the review workflow and audit trail make decisions traceable. The principle remains the same: your data stays in your environment.

All views are original screenshots from a running reference stack with demo data; personas and the brand “Musterbank AG” are fictitious. Connected is not yet part of today’s editions; scope and timing are agreed together with pilot partners.

Capabilities

What the Connected build adds for teams

Six building blocks turn the single assessment into one shared, traceable working state.

Workspaces with a review workflow

Assessments live centrally per team or client. Every state follows a clear path from draft through review to approval and archive. Approved states are locked; only authorised members can reopen them.

Eight roles, clear responsibility, SSO

Sign‑in runs via your identity provider; the application itself manages no passwords. Those who manage structure and operation do not see content; those who review content do not change it. This keeps administration, professional assessment and approval clearly separated. Particularly sensitive actions require re‑authentication.

Confidentiality on a need‑to‑know basis

Confidential assessments are visible only to the people named for them. They do not appear in the lists and metrics of any other role.

Shared versioning with a clear history

Every saved state is versioned on the server. Editing locks and visible conflict notices coordinate simultaneous changes. The audit trail makes progress and approvals traceable for authorised teams.

Cockpit, inventory and metrics

The governance cockpit condenses risk index, coverage and open items into a plain‑language management summary. The AI inventory keeps the estate current, with filters and full‑text search.

All exports on board

Reports and working states as PDF, XLSX, CSV, DOCX and JSON, plus connections to EAM and ITSM systems, straight from the evaluation.

Operation and security

Secure by design and operated in your infrastructure

Sovereignty Everything runs on your side

No SaaS component, no external runtime dependencies, no data leaving your environment. The stack runs on your hardware or in your cloud and stays operable down to isolated environments. You keep control of data, operation and updates.

Data security Secure defaults from day one

Secure defaults instead of after‑the‑fact configuration: encrypted connections, strict content policies, session and access protection plus confirmations for sensitive actions are active from the start, in every deployment variant.

Hardening A minimal attack surface, provably delivered

The application is delivered from a minimal container without a shell or package manager; all services run unprivileged and with no path to privilege escalation. Every release is independently traceable via a bill of materials (SBOM), vulnerability status (VEX) and checksums.

White‑Label

The same application, your brand, consistently across every view

Deployment and collaboration

Two operating models for different ways of working.

Community, Professional Offline, Enterprise / White‑Label Offline and Connected share the same methodological core. They differ in where the application is operated, how people collaborate and how results are handed over.

Offline

Independent, portable and ready to use.

The Offline versions run as a complete browser‑based application on the respective device. The application and assessment data stay local, work remains possible in protected or changing environments, and results are handed over deliberately as a file or evidence package.

Directly in the browserLocal and portableControlled handover
Connected · self‑hosted

Collaborative, role‑based and centrally organised.

Connected is being developed for organisations in which multiple roles work on one shared, authoritative state. Permissions, review, approval, versioning and history are brought together in the organisation’s infrastructure – self‑hosted and not vendor‑operated SaaS.

Shared working stateRoles and permissionsTraceable history

The comparison table can be scrolled horizontally.

Version comparison by requirements, operation and availability
What do you need? CommunityDurable & non‑commercialProfessional OfflineProductive & independentEnterprise / White‑Label OfflineBrand & methodologyConnectedCentral collaboration
Runs locally as a single file – no server requiredIncludedIncludedIncludedNot included
Commercial, productive assessmentsNot includedIncludedIncludedWithin pilot scope
Multiple assessments / AI systems1 active state; more via project filesLocal portfolioLocal portfolioCentral AI inventory within pilot scope
Complete exports & evidence packagesPDF + project fileIncludedIncludedWithin pilot scope
Own brand, catalogues & handoversNot includedNot includedIncludedBy agreement
SSO, central roles & permissionsNot includedNot includedNot includedWithin pilot scope
Review, approval & audit trailNot includedNot includedNot includedWithin pilot scope
OperationOn your deviceOn your deviceOn your deviceSelf‑hosted in your infrastructure
AvailabilityTry nowGet in touchGet in touchIn development · pilot / partner
Community Durable & non‑commercial
Runs locally as a single file – no server required
Included
Commercial, productive assessments
Not included
Multiple assessments / AI systems
1 active state; more via project files
Complete exports & evidence packages
PDF + project file
Own brand, catalogues & handovers
Not included
SSO, central roles & permissions
Not included
Review, approval & audit trail
Not included
Operation
On your device
Availability
Try now
Professional Offline Productive & independent
Runs locally as a single file – no server required
Included
Commercial, productive assessments
Included
Multiple assessments / AI systems
Local portfolio
Complete exports & evidence packages
Included
Own brand, catalogues & handovers
Not included
SSO, central roles & permissions
Not included
Review, approval & audit trail
Not included
Operation
On your device
Availability
Get in touch
Enterprise / White‑Label Offline Brand & methodology
Runs locally as a single file – no server required
Included
Commercial, productive assessments
Included
Multiple assessments / AI systems
Local portfolio
Complete exports & evidence packages
Included
Own brand, catalogues & handovers
Included
SSO, central roles & permissions
Not included
Review, approval & audit trail
Not included
Operation
On your device
Availability
Get in touch
Connected Central collaboration
Runs locally as a single file – no server required
Not included
Commercial, productive assessments
Within pilot scope
Multiple assessments / AI systems
Central AI inventory within pilot scope
Complete exports & evidence packages
Within pilot scope
Own brand, catalogues & handovers
By agreement
SSO, central roles & permissions
Within pilot scope
Review, approval & audit trail
Within pilot scope
Operation
Self‑hosted in your infrastructure
Availability
In development · pilot / partner

The right version follows from your working context.

Offline supports independent, portable and clearly separated work. Connected is intended for a shared data state with multiple roles and governed approvals. Both models keep operation and data under your control.

Before we talk

Answers to the key questions before deployment

From data flows and deployment to evidence, regulatory classification and procurement: here you will find the answers that matter.

What can I try myself in the live demo?

You open the full Community Edition directly in your browser: assess the example AI system, review the system‑type based threat selection, generate PDF reports and preserve the working state as a versioned project file for later re‑import. Completely without sign‑up, without real data and without any data transfer to a server.

What data leaves the browser?

No assessment data is transferred automatically. The working state is stored automatically in local browser storage. A file leaves the application only when you explicitly export a PDF report or project file.

How transparent is the methodology behind it?

A tool that promotes transparency has to be measured by the same standard. On the engineering side, the application ships with a bill of materials (SBOM), the vulnerability status (VEX) and the licences used; this lets Versatile AI Risk Assessment be reviewed independently before approval. The professional content is assured as well: the threat catalogue and the EU AI Act and GDPR content, more than 2,500 reviewed items in total, pass through a documented review and approval process with named sources and automated checks. Professional and Enterprise deliveries include this proof as content assurance documentation: catalogue release, source register, check results and checksum.

Does using it make me automatically legally safe and compliant?

No. Versatile AI Risk Assessment creates the transparency and structure for exactly these decisions: it shows, organises and documents. The final legal, professional and regulatory classification is made by the responsible roles in your organisation – Versatile AI Risk Assessment does not guarantee or certify it.

What does the pricing model look like?

The Community Edition remains free of charge. Professional Offline costs a one‑off €2,490 per named user, including 12 months of updates and email support. From the second year, updates and support can be extended for €490 per year. Enterprise / White‑Label Offline starts at a one‑off €12,900 per organisation and agreed delivery scope; maintenance starts at €1,980 per year from year two. All amounts exclude VAT. The delivered version remains usable without a maintenance renewal; there is no usage‑based billing and no automatic renewal.

How are Community, Professional, Enterprise and Connected provided?

The Community Edition and standard operation run as a client‑side single file with no server in the background. Professional adds the capabilities for productive use. Enterprise adds white label, customer‑specific catalogues and connections. Connected is separate from these and is the central multi‑user version in development for operation in your environment.

What results can I share internally?

Depending on the edition you get reports (PDF), workbooks (XLSX) and machine‑readable formats (CSV, JSON) plus connections to EAM and ITSM systems. That gives you an evidence package for approvals, internal reviews, due diligence, procurement and customer questions.

Do you support us with internal procurement and IT security review?

Yes. For your procurement and IT security review we provide a solid basis on request: data flow, operating model, scope of delivery, catalogue status, third‑party software used as well as SBOM/VEX documents. This gives IT, information security, procurement and compliance a well‑founded basis for the adoption decision.

Is there a central multi‑user version (Connected)?

Yes. Versatile AI Risk Assessment Connected brings teams together on one shared, centrally stored state in your environment. Sign‑in runs through your identity provider. The roles and permissions model governs responsibility and access, while the review workflow and audit trail make every change traceable. All views in the Connected section are original screenshots from the running reference stack. As a partner, you use the current state early and help set the priorities.

Contact

Let us clarify the right next step

Whether you want to order Professional, adapt Enterprise or white label, or help shape Connected as a partner: briefly tell us about your plans. We will respond personally with the appropriate next steps, usually within one business day. Your details are only transferred to us when you submit the form.

Your enquiry

Your details

Message details

Fields marked with * are required.