Skip to main content
    Why ReignFor Chief Risk Officers
    For Chief Risk Officers

    Govern AI use with evidence.

    Reign Gateway applies approved identity, access, policy and spend controls to AI calls sent through it and creates an evidence record for each governed call. Reign Assurance is in co-design development to connect requirements, checks, results, exceptions and evidence for review.

    Reign Gateway · Available today Reign Assurance · Co-design development
    From policy to evidence

    Make the operating decisions explicit.

    Your teams decide which AI uses, models, tools and identities are approved. Reign Gateway applies those decisions to traffic sent through it and records the result.

    01Approved use

    Name the application or agent, its owner and purpose, the models and tools it may reach, and the access and spend limits that apply.

    02Governed traffic

    Gateway checks identity and access, applies policy and spend limits, and sends permitted requests to an approved model or tool.

    03Evidence record

    Each governed call creates an evidence record showing the caller, policy decision, destination, outcome, time and cost, subject to approved capture settings.

    Two distinct disciplines

    Controls and assurance serve different purposes.

    Reign Gateway · Available today
    Embedded controls

    Gateway applies identity, access, policy and spend controls while calls sent through it are in progress. The evidence record shows what policy decided and what happened on that governed path.

    Reign Assurance · Co-design development
    Assurance review

    Reign Assurance is designed to connect a named workflow’s requirements to checks, results, exceptions and evidence. Your business, risk, compliance and audit experts assess what the evidence supports. Reign Assurance does not issue an audit opinion or certification.

    Independent assurance requires appropriate functional and organizational independence from the activity being reviewed. Embedded controls and independent assurance are complementary parts of the customer’s governance approach.

    Clear responsibility

    Your decisions remain visible in the operating record.

    WhoWhat they decide or do
    Business and risk ownersDefine the approved purpose, risk appetite, accountable owner and response to exceptions.
    Security and engineering teamsDefine identities, access, approved models and tools, technical policy, spend limits, capture and retention settings.
    iTmethodsOperates Reign Gateway and applies the approved configuration to traffic sent through it.
    Risk, compliance and audit expertsAssess the evidence against the organization’s objectives and obligations. Auditors are responsible for any audit opinion or certification.
    Across jurisdictions

    Use the evidence in the framework your organization operates.

    AI and model-risk expectations differ across Canada, the United States and the European Union. Our regulatory pages explain the scope, dates and practical implications of the instruments they cover. Specific mappings are established with your compliance function and counsel.

    Next step

    Discuss one AI traffic path or workflow.

    We can discuss who owns it, which policies apply and what evidence your teams can use today.