Skip to main content
Risk Meridian — AI Governance Platform

The AI Governance Platform Built for TRAIGA

Screen for TRAIGA's prohibited practices, build your NIST AI RMF safe-harbor defense, document intent — not impact — and stay cure-ready before the Attorney General ever asks. Enforcement is AG-only, with a 60-day cure period and no private right of action.

No credit card required · Built for TRAIGA — audit-ready in under an hour

app.riskmeridian.com/ai-systems
Risk Meridian AI Systems registry showing tracked AI systems with risk levels, owners, deployment type, and vendor for TRAIGA compliance
Jan 1, 2026
In force since
Up to $200K
Per uncurable violation
60 days
AG cure period
NIST AI RMF
Safe-harbor defense

By deployer type

Know exactly what you owe

Your obligations depend on who you are. For state agencies and local governments, SB 1964 and HB 3512 impose real mandates. For private companies, TRAIGA mostly means: don't do the prohibited things, disclose AI use in healthcare, and keep the documentation that gives you a defense. Risk Meridian maps the whole Texas AI stack to your organization type — with deep government and healthcare coverage.

SB 1964 and HB 3512 apply to governmental entities (state agencies and local governments); a hospital district may qualify — confirm applicability with counsel.

Built for alignment with leading AI governance frameworks

TRAIGA — Supported todayTexas SB 1964 & TAC 219 — Supported todayNo-PHI ArchitectureEncryption, RBAC & Tamper-Evident Audit LogSSO (Google & Microsoft) + TOTP MFAEU AI Act — On roadmapNIST AI RMF 1.0 — Supported todayMulti-Tenant SaaSHealthcare Specialists

The problem

AI now carries real legal exposure in Texas — and governance is how you manage it

The Texas Responsible AI Governance Act prohibits specific intentional, harmful uses of AI and is enforced by the Texas Attorney General. Because that liability is intent-based, a documented record of your AI systems, testing, and oversight is how you show good faith and qualify for the law's safe harbors. Comparable frameworks are emerging in other states and the EU.

Most organizations have no centralized AI inventory, no structured risk reviews, and no organized documentation. Building this from scratch with spreadsheets and word processors is slow, inconsistent, and fails at audit.

Your legal team is asking which AI systems you're running — and you can't answer.

If your AI is ever linked to a prohibited use, documentation is how you show good faith — and most organizations have none.

Clinical AI tools are proliferating across departments with no governance trail.

Auditors want a complete AI governance package. Building one manually takes months.

Risk Meridian's platform helps you get organized quickly and build a defensible governance record.

Platform capabilities

Everything you need to build your TRAIGA defense

Screen for prohibited practices, build your NIST AI RMF safe-harbor evidence, document intent — not impact — and stay cure-ready before the Attorney General asks. One platform for the full defense.

AI System Inventory

Register and document every AI system your organization uses or builds. Capture purpose, ownership, vendor, deployment type, and healthcare-specific fields in one structured registry.

Risk Scoring Engine

Deterministic risk classification — LOW, MODERATE, HIGH, or CRITICAL — driven by a structured questionnaire. Factors include consequential decisions, biometric data, patient-facing use, and more.

Control Auto-Creation

A rules engine maps every risk factor to the applicable compliance controls from a TRAIGA-aligned library. Controls are auto-generated the moment a risk review is completed.

Disclosure Generator

Auto-generate TRAIGA-aligned AI disclosure statements using merge-field templates. Export to PDF, copy to clipboard, or embed in your policy documentation package.

Policy Generator

Generate editable AI governance policies exportable to PDF. Templates cover data use, model oversight, human review, and incident response aligned to TRAIGA requirements.

Incident Log

Track AI incidents with severity classification (Critical / High / Medium / Low) and a structured resolution workflow. Full audit trail from detection to closure.

Executive Certifications

Formal attestation module for organizational leadership. Governance certifications are timestamped, signed, and stored as tamper-evident, append-only records as part of your governance documentation package.

Review Scheduling

Configurable review cadence — Annual, Semi-Annual, Quarterly, or Monthly — with automated email reminders when AI systems are due for re-assessment.

Governance Maturity Score

A normalized 0–100 score measuring overall AI governance program completeness. Track improvements over time and benchmark your organization against best practices.

Framework Readiness

Per-system readiness indicators across TRAIGA, California AI, EU AI Act, Colorado AI Act, and NIST AI RMF. Know exactly where gaps exist before a regulator asks.

Governance Report Pack

Complete documentation export for regulators, auditors, and executives — one-click generation of a full compliance package including risk reviews, controls, disclosures, and certifications.

Board AI Governance Report

A concise, non-technical governance summary designed specifically for hospital and enterprise boards. Meets emerging board-level AI oversight reporting requirements.

Tamper-Evident Audit Trail

Append-only audit log capturing every data change, partitioned by quarter for performance. Full traceability for every risk review, control update, disclosure, and policy change.

Vendor AI Register

Track third-party AI systems and vendor compliance documentation. Know which vendors have governance programs in place and which need follow-up.

See it in action

Your entire TRAIGA posture in one place

A live compliance health score, a full inventory of every AI system, and a documented control for every requirement — the evidence trail you need before the Attorney General ever asks. Preview it in light or dark mode.

app.riskmeridian.com/dashboard
Risk Meridian compliance dashboard showing a Grade A health score with prohibited-use clearance, NIST AI RMF alignment, controls completion, and incident posture

A real-time compliance health score across prohibited-use clearance, NIST AI RMF alignment, controls completion, and incident posture.

app.riskmeridian.com/controls
Risk Meridian controls page listing compliance controls mapped to each AI system, with control code, category, risk level, and status

Every control mapped to every system — code, category, owner, and status in one auditable view.

app.riskmeridian.com/ai-systems
Risk Meridian AI systems inventory listing systems with owners, risk levels, deployment type, and vendor

The full AI inventory — owners, risk levels, deployment type, and vendor for every system.

How it works

Get your AI governance organized in four steps

  1. 01

    Register your AI systems

    Add every AI system your organization uses to the registry. Capture system purpose, ownership, vendor, deployment type, and risk indicators in a structured form. Takes less than 2 minutes per system.

  2. 02

    Run risk reviews

    Complete the structured risk questionnaire for each system. Risk Meridian's scoring engine automatically classifies risk (LOW / MODERATE / HIGH) based on your answers and applicable regulatory factors.

  3. 03

    Track controls & generate documents

    Controls are auto-created from your risk profile. Track completion progress, generate TRAIGA-aligned disclosures and policies, log incidents, and collect executive certifications.

  4. 04

    Produce board-ready reports

    Generate a complete Governance Report Pack for regulators, auditors, or your board at any time. One click exports your full evidence package as a structured PDF bundle.

Solutions by industry

AI governance for every sector with AI governance obligations

Healthcare

AI governance built for hospitals and health systems

Clinical AI — decision support, diagnostics, treatment planning, and patient-facing tools — carries the highest governance scrutiny. Risk Meridian's platform includes dedicated healthcare fields, board-ready reports, and controls designed so no PHI is required — only governance metadata about your AI systems — to help hospitals demonstrate responsible AI use to regulators and their boards.

Learn more

HR & Hiring

Govern AI used in hiring and workforce decisions

AI systems that influence hiring, promotion, or termination decisions carry real legal exposure under employment law and emerging AI rules. Document your AI tools, run risk reviews, and generate disclosure statements that support your compliance with Texas and federal requirements for employment AI.

Learn more

Finance

AI compliance for financial eligibility decisions

Credit scoring, loan origination, fraud detection, and financial planning AI are consequential by definition. Risk Meridian's platform helps financial organizations maintain a complete governance trail across their AI portfolio — from model inventory to board reporting.

Learn more

Enterprise

Enterprise-grade AI governance at scale

Multi-tenant architecture supports large organizations with hundreds of AI systems across business units. Role-based access control, org-level team management, unlimited AI systems on the Enterprise plan, and a Governance Maturity Score to track program progress over time.

Learn more

Small & Medium Business

AI governance that fits your team and budget

Small and medium-sized businesses using AI in customer-facing, HR, or operational decisions face the same TRAIGA obligations as large enterprises — without the dedicated compliance teams. Risk Meridian's platform is designed to be set up and managed by a single person in an afternoon, with affordable plans that grow with your business.

Learn more

Multi-framework coverage

One platform for every AI governance framework you need to address

Risk Meridian's platform is purpose-built for the Texas Responsible AI Governance Act, and maps your controls to the NIST AI RMF today. The platform also provides a road map to other overlapping frameworks including the EU AI Act, Colorado AI Act, and ISO 42001 (on the roadmap).

When new frameworks land, your AI system inventory, risk reviews, and governance controls carry over. You don't start over — you extend.

TRAIGA

Supported today

EU AI Act

On roadmap

Colorado AI Act

Monitoring — law in flux

NIST AI RMF

On roadmap

ISO 42001

On roadmap

Pricing

Plans that grow with your AI governance program

Run your first risk assessment now.

Inventory

Get started — inventory your first AI systems.

Up to 10 active AI systems
See pricing
Most popular

Compliance

Core AI governance workflow for growing teams.

Up to 25 active AI systems
See pricing

Governance

Enterprise governance with board reporting.

Up to 35 active AI systems
See pricing

Enterprise

Unlimited systems and users for large orgs.

Unlimited AI systems
See pricing

All plans include: AI system inventory · risk scoring · control tracking · disclosure generator · Audit trail included on Governance and Enterprise plans

FAQ

Frequently asked questions about AI governance compliance

What is the Texas Responsible AI Governance Act (TRAIGA)?
The Texas Responsible AI Governance Act (TRAIGA) is Texas state legislation, effective January 1, 2026, that primarily prohibits specific intentional, harmful uses of AI — such as using AI to incite self-harm or criminal activity, to intentionally and unlawfully discriminate against a protected class, or to produce unlawful content. Its affirmative disclosure duties apply mainly to government entities, with a narrower disclosure duty for healthcare providers. TRAIGA is enforced exclusively by the Texas Attorney General, after a 60-day cure period, and there is no private right of action. Risk Meridian is designed to help you build and maintain the documentation that supports a defensible AI governance program.
Is Risk Meridian only for Texas organizations?
No — it also applies to businesses outside the state that do business in Texas. TRAIGA's obligations attach to any organization that deploys AI to make or assist in consequential decisions affecting Texas residents, regardless of where that organization is headquartered. Risk Meridian also maps your controls to the NIST AI RMF today (Govern, Map, Measure, Manage) to support TRAIGA's NIST safe-harbor defense, and provides a roadmap to other overlapping frameworks including the EU AI Act, Colorado AI Act, and ISO 42001.
How long does it take to get started?
Most organizations complete their first AI system registration and risk review in under 10 minutes. The platform walks you through a structured questionnaire, auto-generates applicable controls, and produces your first disclosure statement — all in the same session. No configuration or IT setup is required.
Is Risk Meridian designed specifically for healthcare organizations?
The platform is industry-agnostic, but built with Healthcare as a primary vertical. It includes dedicated fields for clinical AI systems (patient-facing, clinical decision support, diagnosis, treatment planning), board-level AI governance reports designed for hospital boards, and controls aligned to healthcare AI oversight requirements. Any organization using AI in clinical workflows can use Risk Meridian to demonstrate responsible AI governance to regulators.
What AI governance documents does the platform generate?
Risk Meridian generates: AI disclosure statements (public-facing), AI governance policies (editable, exportable to PDF), a complete Governance Report Pack (for auditors and regulators), a Board AI Governance Report (for hospital and enterprise boards), and executive certification attestations. All documents are generated from your system registry and risk review data — no manual writing required.
What is an AI Risk Register and does Risk Meridian have one?
An AI risk register is a structured inventory of AI systems that documents their purpose, risk classification, applicable controls, and governance status. Risk Meridian's AI Systems Registry is a full AI risk register — every system has a risk score (Low / Moderate / High), control completion tracking, review history, and incident log. The register is always current and exportable for audit.
How does multi-tenancy work? Can multiple departments use one account?
Risk Meridian uses a multi-tenant architecture with role-based access control. A single organization account can have multiple users with different roles: org_admin (full access + billing), compliance_user (create and edit systems and reviews), viewer (read-only), and auditor (read-only + full audit log access). The Governance and Enterprise plans support team-based access for larger organizations.
How is Risk Meridian different from a general compliance platform?
General compliance platforms are framework-agnostic and require extensive configuration. Risk Meridian is purpose-built for AI governance — the risk scoring engine, control library, disclosure templates, and report formats are all pre-configured for AI-specific regulatory requirements. You get a working AI governance program out of the box, not a blank compliance canvas.

More questions? Email our team →

Start your AI governance program today — before your regulators ask

Risk Meridian takes the guesswork out of AI governance. Whether you need to address the Texas Responsible AI Governance Act, prepare for the EU AI Act, or simply get your clinical AI under proper governance — Risk Meridian is the fastest way to get organized and build a defensible governance program.

No credit card required.

  • First AI system registered in under 2 minutes
  • Auto-generated TRAIGA-aligned disclosure statements
  • Risk scoring and control tracking out of the box
  • Governance reports on demand, ready when you need them
  • Healthcare, HR, finance, enterprise and Small/Medium business plans
  • No credit card required to start