How it works

From a client's request to a reviewed evidence pack, and back again.

RIVAL is the service-delivery platform for MSPs and compliance advisers that manage AI governance for SME clients. When a client is asked how it controls AI, it guides you from that request through evidence review and gap remediation to a reviewed, dated evidence pack under your own brand, then keeps the evidence current for the next request.

For operators

Sell one recurring AI governance evidence service to every client, and run it with the same loop each time instead of rebuilding the answer by hand.

See the service loop

For people

Practice the AI decisions that matter in your work, a few minutes at a time, when a review finds a gap in your role.

See the role examples

The service loop

One operator. Several client organizations. One loop.

An operator serves many client organizations through one platform. Each organization keeps its own people, requests, reviews, policy work, and evidence separate. The operator sells the AI governance evidence service; the client receives a reviewed evidence pack and a scheduled refresh.

01

Operator

The MSP, Microsoft partner, or security or compliance consultancy that runs the service.

02

Client organization

The company that receives the request, and whose people map AI use, acknowledge policy, and build evidence.

One loop, repeated for every request

The operator runs the same ten steps for each request, and starts again when a new request arrives or evidence goes stale.

  1. 01

    Request

    A client receives an external or internal AI governance request.

  2. 02

    Scope

    You record who asked, why, what it covers, and when it is due.

  3. 03

    Map

    RIVAL maps the request and its questions to versioned evidence claims.

  4. 04

    Import

    You attach or import the evidence the client already has.

  5. 05

    Classify

    RIVAL shows which claims are current, stale, missing, unsupported, or not applicable.

  6. 06

    Assign

    Missing and unsupported claims become owned remediation actions.

  7. 07

    Resolve

    AI map, policy, acknowledgements, drills, or other controls produce the missing evidence.

  8. 08

    Approve

    A person approves the review, which freezes claims, states, and links.

  9. 09

    Deliver

    RIVAL generates the reviewed evidence pack and its response index.

  10. 10

    Schedule

    Freshness rules and the review cycle schedule the next review.

One attention item, as the operator sees it Request due in 9 days · 3 claims missing. Owner: the operator. Next step: import the tool inventory, assign the policy version to marketing, and add one short drill on data handling. That turns three missing claims into current ones before the due date.

The service carries the operator's brand. The platform stays visible where delivery and trust require it.

The deliverable

A reviewed evidence pack, approved by a person

  1. 01Request and scope
  2. 02Review and gaps
  3. 03Remediation and approval
  4. 04Reviewed pack

Every claim in a review carries one state: current, stale, missing, unsupported, or not applicable. Stale, missing, and unsupported claims are gaps with one owner and one next action.

A person links evidence to each claim and approves the review. Approval freezes the claims, states, and links, and the pack is generated from that frozen review, scoped, dated, and versioned under the operator's brand.

A review cycle schedules the next review before evidence goes stale. The next pack lists what changed since the previous approved review, and each new request starts from the current review instead of from zero.

A reviewed evidence pack turns that record into a scoped, dated report of the request, known AI use, policies, actions, practice, gaps, remediation, and changes since the previous review, with the records behind each statement. It documents recorded actions and current state, not a legal opinion or a guarantee of compliance.

Evidence inputs

Bring evidence from the tools your clients already use

The import workflow is not live yet. The first release covers manual evidence entry, file uploads and references, CSV imports, Microsoft 365 audit-log exports and supported audit APIs, awareness-platform reports such as training completions, and exports from discovery, security, governance, and compliance tools.

Direct connectors to those tools come after that release. None is live today, and we name none until it works.

RIVAL does not pull data out of Microsoft Purview; audit-log exports and supported audit APIs are the route. It does not replace Purview, discovery tools, KnowBe4, Vanta, Cynomi, or technical controls. It brings human, policy, review, and technical evidence together in the operator's workflow.

AI Governance Core

Maintained content behind the service

AI Governance Core is included in the base service. It supplies the base evidence claims, evidence rules, review structure, and gap actions the service runs on. AI Literacy Core sits inside it with maintained principles, role tracks, and scenarios that support an organization's AI-literacy measures.

A scenario puts one principle into a specific risk, work situation, role, AI tool, and consequence. One drill uses one scenario. A drill is one remediation method, not a course.

The content is a growing library maintained with traceable versions, so every review and every drill answer names the version it used. Maintained packs can extend the service later, after the base service works.

Mastery reflects how well a person handles one principle. Seniority never reduces practice.

Freshness gives recent practice more weight and schedules repetition when knowledge becomes stale.

A role change switches the role track and schedules a refresh for the new risks.

For people

One organization, different kinds of risk

When a review finds a role, judgment, or competence gap, short practice is one way to close it. A role profile describes a person's risk and required practice. A role track supplies the scenarios for that role.

  1. 01

    Reception

    Decide whether visitor details belong in an AI-assisted email.

  2. 02

    Management

    Judge whether AI may influence a decision about a person.

  3. 03

    Recruitment

    Check the conditions before an AI tool summarizes a candidate's CV.

  4. 04

    Communications

    Verify a generated public claim before it represents the organization.

  5. 05

    Development

    Review generated code and protect internal source from unintended disclosure.

Illustrative drill

A small decision, tied to real work

This specimen is illustrative, is not an assignment, and writes no data.

Duration: 30 seconds to 3 minutes.

01 · Situation

You want an AI tool to summarize a candidate's CV before an interview.

02 · Decision options

A. Paste the CV into the tool. B. Check the approved tool, purpose, and data rules first. C. Ask a colleague to paste it.

03 · Direct feedback

B is the safest first move. Approval and purpose matter before personal data enters a tool.

04 · Transferable principle

Check the tool, purpose, and data before you share information with AI.

From action to evidence

Record the action when it happens

The evidence ledger records meaningful actions when they happen, instead of asking the organization to reconstruct them later.

Every drill answer is stored as an evidence event and adjusts what that person practices next.

Pricing and how to start

Initial launch price, and a first-client launch

€199 per operator per month with three active clients included, and €49 per additional active client per month. No per-person charge. An active client is one inside an active review cycle. Prices exclude VAT where applicable, and you set your own client prices. This is the initial launch price.

First client launch · €495: onboarding, one client organization, one scoped request or review, one reviewed evidence pack under your brand, a proposal or statement-of-work template supplied during the launch, and the pricing and margin tool. The fee is credited against your first three subscription months.

If a complete supplied evidence set cannot be converted into an approved evidence pack within 30 days, the launch fee is refunded. A complete set means you and your client supplied the scoped request, its source material, the existing records, named gap owners, and timely approvals; missing cooperation extends the period and triggers no refund. The launch guarantees no legal compliance, certification, or acceptance by any insurer, buyer, or regulator.

Keep reading, or use your provisioned account

The example evidence pack and the methodology page show what your client receives and where the limits are. Docs explains the terms and user journeys. Sign-in is for people whose access has already been provisioned.