For operators
Sell one recurring AI governance evidence service to every client, and run it with the same loop each time instead of rebuilding the answer by hand.
See the service loopHow it works
RIVAL is the service-delivery platform for MSPs and compliance advisers that manage AI governance for SME clients. When a client is asked how it controls AI, it guides you from that request through evidence review and gap remediation to a reviewed, dated evidence pack under your own brand, then keeps the evidence current for the next request.
For operators
Sell one recurring AI governance evidence service to every client, and run it with the same loop each time instead of rebuilding the answer by hand.
See the service loopFor people
Practice the AI decisions that matter in your work, a few minutes at a time, when a review finds a gap in your role.
See the role examplesThe entry point
A customer sends a supplier questionnaire with an AI section. An insurer adds AI questions to a renewal. An auditor, a tender, or the board asks how the organization controls AI. The client turns to its operator.
The operator records the request: who asked, why, which scope, when it is due, the source material, and the individual questions. Each question links to the evidence claims that answer it, and the request carries its own status from received to answered and closed.
Requests and questions are recorded by hand. There is no automated questionnaire parsing and no answer library; the value is the reviewed evidence behind each answer.
The service loop
An operator serves many client organizations through one platform. Each organization keeps its own people, requests, reviews, policy work, and evidence separate. The operator sells the AI governance evidence service; the client receives a reviewed evidence pack and a scheduled refresh.
The MSP, Microsoft partner, or security or compliance consultancy that runs the service.
The company that receives the request, and whose people map AI use, acknowledge policy, and build evidence.
The operator runs the same ten steps for each request, and starts again when a new request arrives or evidence goes stale.
A client receives an external or internal AI governance request.
You record who asked, why, what it covers, and when it is due.
RIVAL maps the request and its questions to versioned evidence claims.
You attach or import the evidence the client already has.
RIVAL shows which claims are current, stale, missing, unsupported, or not applicable.
Missing and unsupported claims become owned remediation actions.
AI map, policy, acknowledgements, drills, or other controls produce the missing evidence.
A person approves the review, which freezes claims, states, and links.
RIVAL generates the reviewed evidence pack and its response index.
Freshness rules and the review cycle schedule the next review.
One attention item, as the operator sees it Request due in 9 days · 3 claims missing. Owner: the operator. Next step: import the tool inventory, assign the policy version to marketing, and add one short drill on data handling. That turns three missing claims into current ones before the due date.
The service carries the operator's brand. The platform stays visible where delivery and trust require it.
The deliverable
Every claim in a review carries one state: current, stale, missing, unsupported, or not applicable. Stale, missing, and unsupported claims are gaps with one owner and one next action.
A person links evidence to each claim and approves the review. Approval freezes the claims, states, and links, and the pack is generated from that frozen review, scoped, dated, and versioned under the operator's brand.
A review cycle schedules the next review before evidence goes stale. The next pack lists what changed since the previous approved review, and each new request starts from the current review instead of from zero.
A reviewed evidence pack turns that record into a scoped, dated report of the request, known AI use, policies, actions, practice, gaps, remediation, and changes since the previous review, with the records behind each statement. It documents recorded actions and current state, not a legal opinion or a guarantee of compliance.
Evidence inputs
The import workflow is not live yet. The first release covers manual evidence entry, file uploads and references, CSV imports, Microsoft 365 audit-log exports and supported audit APIs, awareness-platform reports such as training completions, and exports from discovery, security, governance, and compliance tools.
Direct connectors to those tools come after that release. None is live today, and we name none until it works.
RIVAL does not pull data out of Microsoft Purview; audit-log exports and supported audit APIs are the route. It does not replace Purview, discovery tools, KnowBe4, Vanta, Cynomi, or technical controls. It brings human, policy, review, and technical evidence together in the operator's workflow.
Where the law fits
Article 4 of Regulation (EU) 2024/1689, as amended by the Digital Omnibus on AI in July 2026, requires providers and deployers within the Act's scope to take measures that support the development of AI literacy of staff and other people who operate or use AI systems on their behalf. It does not require them to guarantee any specific level of literacy.
The European Commission states that no specific level, test, training or certificate is mandated, and that an organization can keep an internal record of its trainings and other guiding initiatives. RIVAL records the measures an organization takes, as the work happens.
Article 2 sets the territorial scope. Article 3 defines providers and deployers. The operative provisions include no organization-size threshold.
Article 113 applied Chapters I and II, including Article 4, from 2 February 2025. National market surveillance authorities supervise and enforce Article 4 from August 2026.
In the Netherlands, the Cyberbeveiligingswet has applied since 15 August 2026 to about 8,000 organizations with a duty of care that includes their supply chain. Their suppliers and advisers may receive the questions next. Neither law requires an evidence pack; both make current, reviewable answers more useful.
Decisions stay with the organization.
Source: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744, Articles 2, 3, 4, and 113; European Commission AI literacy questions and answers, updated 27 July 2026; Rijksoverheid, 7 July 2026. Open the consolidated regulation on EUR-Lex Read the Commission's AI literacy questions and answers
AI Governance Core
AI Governance Core is included in the base service. It supplies the base evidence claims, evidence rules, review structure, and gap actions the service runs on. AI Literacy Core sits inside it with maintained principles, role tracks, and scenarios that support an organization's AI-literacy measures.
A scenario puts one principle into a specific risk, work situation, role, AI tool, and consequence. One drill uses one scenario. A drill is one remediation method, not a course.
The content is a growing library maintained with traceable versions, so every review and every drill answer names the version it used. Maintained packs can extend the service later, after the base service works.
Mastery reflects how well a person handles one principle. Seniority never reduces practice.
Freshness gives recent practice more weight and schedules repetition when knowledge becomes stale.
A role change switches the role track and schedules a refresh for the new risks.
For people
When a review finds a role, judgment, or competence gap, short practice is one way to close it. A role profile describes a person's risk and required practice. A role track supplies the scenarios for that role.
Decide whether visitor details belong in an AI-assisted email.
Judge whether AI may influence a decision about a person.
Check the conditions before an AI tool summarizes a candidate's CV.
Verify a generated public claim before it represents the organization.
Review generated code and protect internal source from unintended disclosure.
Illustrative drill
This specimen is illustrative, is not an assignment, and writes no data.
Duration: 30 seconds to 3 minutes.
01 · Situation
You want an AI tool to summarize a candidate's CV before an interview.
02 · Decision options
A. Paste the CV into the tool. B. Check the approved tool, purpose, and data rules first. C. Ask a colleague to paste it.
03 · Direct feedback
B is the safest first move. Approval and purpose matter before personal data enters a tool.
04 · Transferable principle
Check the tool, purpose, and data before you share information with AI.
From action to evidence
The evidence ledger records meaningful actions when they happen, instead of asking the organization to reconstruct them later.
Every drill answer is stored as an evidence event and adjusts what that person practices next.
Pricing and how to start
€199 per operator per month with three active clients included, and €49 per additional active client per month. No per-person charge. An active client is one inside an active review cycle. Prices exclude VAT where applicable, and you set your own client prices. This is the initial launch price.
First client launch · €495: onboarding, one client organization, one scoped request or review, one reviewed evidence pack under your brand, a proposal or statement-of-work template supplied during the launch, and the pricing and margin tool. The fee is credited against your first three subscription months.
If a complete supplied evidence set cannot be converted into an approved evidence pack within 30 days, the launch fee is refunded. A complete set means you and your client supplied the scoped request, its source material, the existing records, named gap owners, and timely approvals; missing cooperation extends the period and triggers no refund. The launch guarantees no legal compliance, certification, or acceptance by any insurer, buyer, or regulator.
See the full pricing, the launch terms, and your own economics
The example evidence pack and the methodology page show what your client receives and where the limits are. Docs explains the terms and user journeys. Sign-in is for people whose access has already been provisioned.