Audit, risk and assurance

AuditMap.ai

Turn scattered policies and controls into a clause-mapped audit trail

AuditMap.ai helps organizations operationalize risk management by mapping real artifacts (policies, procedures, reports, datasets, approvals) to controls and requirements, producing a living, searchable evidence base built for internal audits and external assessments.

Principal capabilities

Control and clause mapping

Map evidence to risk frameworks, with ISO/IEC 42001 readiness and NIST AI RMF alignment.

Evidence collection

Evidence requests and status, role-based access, and exportable audit packages.

Model and system inventory

A live, versioned inventory of AI systems with a risk register, mitigations, monitoring, and alerting.

Coverage analysis and QA

Consolidate critical findings to expose coverage gaps and misalignments with second-line functions.

Built for audit teams

Control owners and due dates, clear pass / partial / fail status, and repeatable audit playbooks.

Private by design

On-prem or isolated network, role-based approvals, immutable audit logs.

The detail buyers ask for

Problem, deployment model, licensing, and how this relates to our consulting work, stated plainly.

Buyer problem

Audit readiness fails on evidence-chasing. The controls are documented, the artifacts exist somewhere, and connecting the two consumes weeks of senior time every cycle. Worse, the mapping is rebuilt from scratch each time, so nobody can answer how coverage changed since the last assessment.

What it does

A living evidence base where every control links to concrete, reviewable artifacts, and coverage gaps are visible in days rather than months.

Deployment model

On-prem or isolated-network support, with role-based access, approvals, and immutable audit logs. Designed for sensitive and compliance-heavy environments.

Typical users

Internal audit teams; second-line risk and compliance functions; control owners; organizations preparing for ISO/IEC 42001 or NIST AI RMF assessment.

Relationship to Lemay.ai consulting

AuditMap is the evidence layer beneath our ISO 42001 work. A gap assessment tells you where you stand; AuditMap is how the evidence stays current after the consultants leave. Our team includes consultants certified as lead auditors, so the two fit together by design.

Licensing model

Licensed separately from consulting engagements. Available as a standalone platform or as part of an ISO 42001 readiness programme.

Proof and deployment examples

Spun out of Lemay.ai as a dedicated audit-technology company and presented at the Institute of Internal Auditors International Conference. See our press page for the record.

Ownership and licensing

Custom engagements. Clients own project-specific code, models, and documentation as defined in the applicable agreement. That is the default for consulting work and it does not change because a project touches one of our products.

Lemay.ai products. Pre-existing Lemay.ai platforms and intellectual property are licensed separately where selected. A licence covers the platform; it does not claim anything you build on top of it.

Request an AuditMap demo

Tell us what you are trying to accomplish and we will tell you whether this is the right fit, including when it is not.

By submitting this form, you agree to be contacted about your enquiry. See our Privacy Policy.

What happens next

  1. We reply to confirm fit and what we’d need to know.
  2. A 30-minute call to see the product against your own material.
  3. A pilot scope and licence terms in writing.

Prefer to book a time directly? Email [email protected] and we’ll send options.