FAQ
Frequently Asked Questions
What does Navigate Compliance actually do?
We give regulated organisations one platform to design, govern and operate AI, regulatory compliance and fair conduct. Instead of separate tools for model risk, obligations and customer outcomes, everything runs off one governed record.
Which frameworks do you govern against?
ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, POPIA and GDPR, alongside your own internal AI policies. Controls are mapped once and reused, so a single control test can satisfy obligations across several frameworks.
What is KY-A (Know Your Agent)?
Know Your Agent is a live register of every AI system, model and agent in the business, with its purpose, owner, risk classification and control status. It carries each system through approval gates and into runtime monitoring.
What is AURA?
AURA is the regulatory operating system: an automated regulatory universe, impact assessments, policy governance, an enterprise control library, regulatory reporting and a change management workstation.
What is Fair Conduct?
Fair Conduct monitors customer outcomes continuously — that customers understand products, receive appropriate advice, are treated fairly and are protected from foreseeable harm. It includes the Consumer Trust Wallet, the consumer-facing trust layer.
Who is the platform built for?
Financial Services Providers, Accountable Institutions and other regulated organisations that must evidence how they govern AI, data and customer outcomes.
Can we host it in our own environment?
Yes. Deployment options are customer-hosted, Azure native, or multi-tenant SaaS. The platform is cloud agnostic and can run on Azure, AWS, Google Cloud or private cloud infrastructure.
Do we have to replace our existing RegTech tools?
No. AURA is built on a plug-and-play architecture that integrates with your existing RegTech ecosystem. You adopt further capabilities only as your governance needs evolve.
How do you keep regulatory content current?
Trusted Regulatory Data maintains the underlying obligations and reference data as canonical, versioned datasets, so regulatory change flows through to your policies and controls rather than being tracked by hand.
Is this software only, or do you run it with us?
Both. You can license the platform and run it yourself, or take it as GRC-as-a-Service, where our GRC Operational Centre operates the governance function alongside your team.
How does Cerebro fit in?
Cerebro builds the workforce capability to run governance. When regulation changes, it identifies capability gaps, assigns the required training and tracks organisational readiness.
How do we get started?
With an AI and obligations inventory. From there we agree the control set, evidence model and reporting cadence: a structured path from inventory to continuous, evidenced compliance.
- Answer questions about our services
- Recommend the best next step
- Explore your automation or AI use case
- Discuss timelines, scope, and fit