AI compliance and governance. In one place.
Genyo Govern AI puts the control, governance and compliance of every AI system you run into a single platform — the EU AI Act, your sector's rules and every national regulator in the EU, with the evidence your supervisors will ask for.
Built for banks, insurers and asset managers. Made in Milan by Redo S.r.l.
Three ways to work with Genyo
Govern what you already run, build what you need next, and control the general-purpose and ML models underneath both.
Governance & Compliance
Inventory, classify and document every AI system. Map it to every obligation that applies, collect the evidence, and hand the supervisor a dossier.
Explore Govern AIBuild AIBuild AI
Design, develop and maintain AI models on a pipeline engineered for speed — with governance metadata generated as a by-product, not an afterthought.
Explore Build AIToolsAI Governance tools for GPAI and ML
Qualify general-purpose models, test training data, design human oversight, monitor post-market — and wire in your evaluation and red-team stack.
Explore the toolsEvery AI system, on one screen
Risk class, Annex III category, provider or deployer role, lifecycle, EU-database status, models in use and linked risks — one row per system, per entity. This is the register your supervisor will ask to see.

Fourteen frameworks, read together
An incident under the AI Act is usually also an incident under DORA and GDPR. Genyo maps every module to every article that binds it, so one action satisfies every regime — with the deadlines of each.
- Cross-cutting baselineEU AI Act, GDPR and Data Act apply to every system by default.
- Sector overlaysDORA, EBA guidelines, IVASS and Banca d'Italia communications, Solvency II, MiFID — switched on per entity.
- One questionnaire, several outputsA single FRIA + DPIA flow produces both assessments; a single incident report notifies AgID, Banca d'Italia and the Garante.
View the full screen →Local rules for every member state
The AI Act is European. Its enforcement is national — surveillance authorities, notification templates, sector circulars, labour law. Genyo models the regulators and the national law of all 27 member states, and generates the filings each one expects.
- Regulator map per countryWhich authority receives which notification, under which article, within which deadline.
- National overlaysItalian L. 132/2025, D.Lgs. 138/2024 and the 231 model today; further jurisdictions are added as their implementing law lands.
- Filings in the supervisor's formatThe Vigilanza Italia module produces the Banca d'Italia report from the platform's own evidence.
Connected to where your models already live
Read-only connectors pull model registries, run metrics, deployment metadata and security signals straight into the evidence base. Nothing is re-keyed.
Many companies, many countries, one dashboard
For groups, governance is a consolidation problem. Each legal entity keeps its own register, overlays and supervisors; the holding sees everything rolled up, with separation of duties enforced per entity.
- Entity-level scopeFrameworks, regulators and roles are set per company and per country.
- Group-level viewCROs and CCOs at the holding read a consolidated risk register and obligation status.
- Shared models, separate evidenceA model deployed in three subsidiaries appears once in the registry and three times in the obligations.
View the full screen →Post-market monitoring for every kind of model
Article 72 asks for a monitoring plan; it does not say what to measure. Genyo ships metric sets per model type, wired to your telemetry, with thresholds that open an incident when crossed.
- GPAI — LLM, Agent, RAGHallucination and toxicity rates for assistants; task completion and unsafe tool calls for agents; faithfulness and context precision for retrieval.
- ML — binary, multi-class, regressionAUC, PSI drift and approval-rate parity for binary models; macro-F1 and per-class recall for multi-class; MAE, RMSE and bias for regression.
- Breach to incidentA metric outside tolerance becomes an incident record with the Art. 73 clock already running — the drift on the credit model above is INC-2026-007.
View the full screen →Shadow AI, discovered and governed
Your security stack already sees the GenAI apps employees use. Genyo reads that inventory, correlates it with the AI service catalogue, scores the risk, and turns unsanctioned use into a governed procurement request — or a block.
- Five sources, one listPurview, Netskope, Zscaler, Harmonic Security and Reco feed discovered apps, OAuth grants and sensitive-data events.
- Risk, not just presenceUsers, grants and DLP events rank each app; the meeting-notes tool with mail and calendar access outranks the chatbot nobody logs into.
- Within labour lawDiscovery respects Art. 4 of the Italian Statuto dei Lavoratori — aggregate signals, no individual surveillance — and feeds Art. 4 AI-literacy evidence.
View the full screen →Human oversight, designed and evidenced
Article 14 requires that a person can understand, question, override and stop a high-risk system. Genyo records the five measures per system, who holds each, and what actually happened in operation.
- The five measures, (a) to (e)Capacities and anomalies, automation bias, interpretation, override, stop button — each with its design, owner and status.
- Competent, trained, assignedOverseers are named per system and their Genyo Academy training is current, as Art. 26(2) asks of deployers.
- Oversight you can showDecisions sampled, overrides, escalations and stop drills over the last 30 days, exported straight into Annex IV §2(e).
View the full screen →Genyo is what we build with Build AI
The platform you are looking at — twenty-five modules, fourteen frameworks, eighteen connectors — was designed, developed and is maintained on the Build AI pipeline. It is the fastest way we know to take an AI model from requirement to production, and it produces its own compliance metadata on the way.
Talk to the Build AI teamMade in Milan, for regulated Europe.
Redo S.r.l. is the company behind Genyo.ai. We build AI governance software for banks, insurers and asset managers, and we build AI models with the same pipeline.
Why we built Genyo
The AI Act arrived on top of DORA, GDPR, NIS2 and a decade of sector guidelines. Institutions were being asked to govern AI across five regimes with spreadsheets and email.
We had built credit-risk models under supervisory scrutiny and knew what an inspection asks for. Genyo is the register we wished we had had: every system, every obligation, every piece of evidence in one place, in the supervisor's order.
We built it on our own Build AI pipeline, which is why the platform can also produce its own compliance metadata — and why we offer the pipeline to clients.
Regulatory expertise
- EU AI Act, GDPR and Data Act
- DORA, EBA guidelines and the ECB/SSM supervisory expectations
- IVASS and Banca d'Italia communications, CONSOB rules
- Italian L. 132/2025, D.Lgs. 138/2024 (NIS2), D.Lgs. 231/2001
- National supervisors across the 27 member states
Certifications


Redo S.r.l. is ISO/IEC 27001 certified.
Genyo.ai is operated in compliance with DORA requirements for ICT third-party providers to financial entities.
Request a demo.
Tell us which entities, frameworks and countries are in scope. We reply within two working days with a proposed 45-minute walkthrough.
Thanks — your request has been sent.
We'll get back to you as soon as possible.
Incident reporting.
You may submit this form without providing your name or contact details. All responses are treated confidentially.
Thanks — your report has been sent.
We'll get back to you as soon as possible.
Eighteen connectors, all read-only.
Genyo never writes to your platforms. Each connector reads registries, runs, telemetry or security signals and files them as evidence against the obligations they satisfy.
ML platforms
Observability
Shadow AI and data security
Privacy
Guardrails
Red-team
Evaluation
Missing a connector?
Tell us which platform you run and what it should feed. Connectors are built on a read-only pattern, so most requests are a matter of weeks.
Request a connectorPrivacy and cookies
Why this notice?
Redo S.r.l. (hereinafter, the Company), P. IVA: 11601770966, with registered office in Corso Garibaldi, 49, Milano, acknowledges the central role of personal data in the socio-economic ecosystem in which it operates, as well as the critical issues related to their use in the provision of services that involve the non-incidental use of artificial intelligence systems. Accordingly, the Company is fully aware of the importance of clear and transparent communication in order to mitigate risks to the rights and freedoms of all natural persons whose personal data are processed. Furthermore, privacy legislation (in particular Regulation (EU) 2016/679, the "General Data Protection Regulation" — GDPR) requires us to provide you with the following information regarding the processing of your personal data, pursuant to Articles 13 and 14. For these reasons, Redo S.r.l., Corso Garibaldi, 49 — 20121, Milano (MI), as the "Data Controller," hereby provides this privacy notice to describe the modalities for processing your personal data in connection with its website.
The role of the Company
It is important to emphasize from the outset that the Company, in the course of its activities, operates both as a Data Controller and as a Data Processor. Since, pursuant to Articles 13 and 14 of the GDPR, the obligation to provide information on processing lies exclusively with the Data Controllers, this document will concern solely the processing activities for which the Company acts as Data Controller. These include activities related to service registration and the operation of the website, concerning the personal data of natural persons who access the site either as visitors or as operators with login credentials, for the purpose of accessing the services provided. However, in the interest of transparency and in the spirit of fair cooperation with the Data Controllers, the Company considers it useful to provide clients with information regarding processing activities carried out in its capacity as Data Processor. These include activities arising from the provision of its typical services (quality checks, enhancement, augmentation of training data, initial model training or re-training, processing and returning of inferences for the purposes chosen by the clients from those available, and retention of original database files for training). To this end, upon request by the client-Controllers, the Data Protection Impact Assessment (DPIA) prepared following the impact assessment pursuant to Article 35 GDPR is available. Extracts of the document may also be made available to third parties, upon request, in the interest of maximum transparency. It should be noted, however, that with regard to processing carried out as a Data Processor, the Company does not determine the specific purposes and categories of personal data used from time to time (which partly depend on the discretionary choices of the clients), the final retention periods of the data, the entities with whom the Controllers choose to share them, or numerous other relevant aspects of processing, except for those specifically related to the technical characteristics of the services provided. Furthermore, the Company cannot directly or autonomously respond to data subject requests, as it does not know the identity of the individuals involved, operating solely on information that is not attributable to specific natural persons (data pseudonymized at source and therefore anonymous from the Company's perspective, which does not possess, nor can it possess, legal or technical means to re-identify the data subjects). Nonetheless, the aforementioned DPIA contains information regarding technical "by design" measures adopted to facilitate the exercise of data subject rights by client-Controllers, in particular with respect to the explainability of AI model inferences and the human oversight of processes ("human-in-the-loop" supervision), in compliance with Article 22 GDPR as well as related regulations on Artificial Intelligence (Reg. (EU) 2025/1689 and sector-specific regulations, e.g., EBA). Finally, it should be noted that operations carried out by the Company for the purpose of developing additional AI models for its own interest are normally performed using synthetic data or data subjected to processes (embedding) that render them fully anonymous and not attributable to identified or identifiable natural persons, and therefore do not constitute processing of personal data within the meaning of Article 4(2) GDPR. Should personal data be used in the future for the purposes described in this paragraph, it will be the responsibility of the Data Controller (whether the Company, the client, or, in the case of joint controllership, the party designated under the agreements to assume the obligation) to inform the data subjects and to ensure the existence of the necessary legal bases.
Twenty-five modules, one register.
Every module carries the article that binds it. Together they cover the AI Act, GDPR, DORA, NIS2 and the sector and national overlays — from the first classification to the supervisor's dossier.
Getting started
AI inventory
Compliance and documentation
Risk and operations
Supervision (Italy)
Workspace, training and support
Products · Getting started
EU AI Act · L. 132/2025
AI compliance check
A guided questionnaire that positions the organisation against the EU AI Act, the Italian L. 132/2025 and the sector overlays that apply to it. The result is a gap list with owners, used to plan the first ninety days on the platform.
- Positions the organisation as provider, deployer or both
- Flags the frameworks and supervisors in scope
- Produces a prioritised gap list with owners

Related modules
Products · AI inventory
EU AI Act Art. 11 · Annex IV §2 · Art. 51–55
AI model registry
The technical record of each model behind a system: architecture, training purpose, parameters, compute, capability chips and lineage — synchronised from the ML platforms rather than typed in. Feeds Annex IV §2 and the GPAI qualification.
- Synced from MLflow, Databricks Unity Catalog, Azure ML, SageMaker, W&B
- Capability chips drive the GPAI assessment
- Linked to systems, data cards and monitoring plans

Related modules
Products · Risk and operations
EU AI Act Art. 26 · Art. 4
AI procurement
A governed channel for new AI demand: intake, function check, procurement assessment, decision, then classification into the registry. It is the structural mitigation for shadow AI — it moves demand from the unofficial channel to a governed one with a hash-chained audit trail.
- Every request becomes a registry entry or a documented refusal
- Linked to Vendor assessment and Role assessment
- Included in the AI use policy

Related modules
Products · Supervision (Italy)
EU AI Act + L. 132/2025 + DORA · NIS2 · MiFID · Solvency II
AI regulatory assessment
A single regulatory assessment that reads the AI Act together with the Italian L. 132/2025 and the sector law that applies to the entity — DORA, NIS2, MiFID, Solvency II — and produces the applicable obligation set for the catalogue.
- National and sector law layered on the AI Act
- Per entity, per country
- Output flows into the Obligation catalogue

Related modules
Products · Risk and operations
All 14 frameworks
AI risk governance
The AI risk register: 44 catalogued risks with KRI templates, sector overlays, owners and treatment plans, organised on the Banca d'Italia and IVASS risk-management communications. Every risk is linked to the obligations it threatens and the controls that mitigate it.
- 44 risks with KRI templates, extendable
- Sector overlay for financial services and utilities
- Consolidated at group level for the CRO

Related modules
Products · AI inventory
EU AI Act Art. 6 + Annex III
AI system classification
A three-step classification that assigns the risk class of each AI system under Art. 6 and Annex III, records the reasoning, and flags the NIS2 AI-component where the entity is in scope of D.Lgs. 138/2024. The classification drives which obligations apply downstream.
- Prohibited, high-risk, limited or minimal — with the Annex III use case
- Reasoning stored with the classification for the supervisor
- Re-run on substantial modification

Related modules
Products · AI inventory
EU AI Act Art. 49 · Fw 132/2025 §5.1
AI system registry
The single register of every AI system the organisation provides or deploys: owner, purpose, status, entity, classification and lifecycle events. It is the source that every other module reads from, and the record that goes to the EU database under Art. 49.
- One row per system, per entity, with owner and status
- Append-only lifecycle log
- Export for the EU database and for inspections

Related modules
Products · Compliance and documentation
EU AI Act Art. 11 · Annex IV
Annex IV generator
Generates the Annex IV technical documentation dossier required by Art. 11 for high-risk systems. Nine sections are pre-filled from system metadata and, for models built on Build AI, from the training pipeline itself. Version control and a review flow keep each dossier defensible.
- Nine-section template with automatic pre-fill
- Version history and author/reviewer workflow
- Sections populated from Human oversight, Training-data compliance and the Model registry

Related modules
Products · Compliance and documentation
EU AI Act Ch. I–XII
Article cockpit
Supervisors reason by article. The cockpit shows the full structure of the AI Act, Chapters I to XII, with status, maturity and evidence against each article across all systems — the cross view you need before an inspection.
- Every article of the AI Act with its status
- Drill from article to systems to evidence
- Used by the Inspection dossier and the Compliance checklist

Related modules
Products · Getting started
EU AI Act Art. 4 · Fw 132/2025
Company profile
The master record for each legal entity: sector, group position, applicable overlays, escalation thresholds, board competencies and AI training carried out or planned. Every assessment and every supervisory report reads from here, so it is filled once.
- One profile per legal entity, rolled up at group level
- Board competencies and training recorded as Art. 4 evidence
- Feeds the Vigilanza Italia report and the inspection dossier

Related modules
Products · Compliance and documentation
AI Act · GDPR · Data Act · DORA · NIS2
Compliance checklist
An operational checklist derived from the catalogue: the baseline that always applies, the NIS2 AI-component lens for in-scope entities, and the sector overlay — DORA and the EBA guidelines for financial services. Each item carries state, maturity and evidence.
- Generated per entity from its profile
- Items link back to the article and the module that fulfils them
- Exportable for internal audit

Related modules
Products · Compliance and documentation
EU AI Act Art. 43 + Art. 47
Conformity assessment
Routes each high-risk system to the right procedure — Annex VI internal control for most financial-services use cases, Annex VII notified body for biometric systems — and runs it: QMS readiness, evidence matrix, completeness check, then the EU declaration of conformity and CE marking. Nine roles across the three lines of defence sign with eIDAS.
- Decision tree from Art. 6 classification to Annex VI or VII
- Evidence linked to ISO 42001 QMS controls
- Append-only, hash-chained audit ledger for the whole procedure

Related modules
Products · Workspace, training and support
EU AI Act Art. 26
Deployer cockpit
Everything a deployer owes under Art. 26 in one workspace: use according to instructions, assignment of competent human oversight, relevance of input data, monitoring of operation, log retention, information to affected persons, cooperation with authorities and the FRIA.
- One checklist per deployed system
- Evidence linked from Human oversight and Post-market monitoring
- Supervisor-readable status

Related modules
Products · Compliance and documentation
EU AI Act Art. 27 + GDPR Art. 35
FRIA + DPIA
The fundamental-rights impact assessment (AI Act Art. 27) and the data-protection impact assessment (GDPR Art. 35) share most of their questions. Genyo asks them once, routes the case to FRIA-only, DPIA-only or combined, and generates both documents live as you answer.
- Five-step flow: scope, regime triage, affected persons, risks and mitigations, review
- DPO opinion and Garante prior-consultation (Art. 36) tracked
- Re-assessment triggered on substantial modification

Related modules
Products · Workspace, training and support
EU AI Act Art. 4 · Fw 132/2025 §9.1
Genyo Academy
The AI-literacy curriculum the AI Act requires under Art. 4, organised by role and level — from board members to model reviewers. Every completion is written to the audit register as evidence, and Academy status appears in the Vigilanza Italia report.
- Levels L1–L3 by role
- Curriculum on the AI Act, DORA, GDPR and the sector overlays
- Completions as automatic evidence

Related modules
Products · Compliance and documentation
EU AI Act Art. 51–55
GPAI assessment
Determines whether a model is a general-purpose AI model, whether it carries systemic risk under the 10²⁵ FLOP threshold, and which of the Art. 53–55 obligations follow for provider and deployer. Re-runs automatically when the vendor publishes a new version.
- Reads capability chips from the Model registry
- Vendor dossier per foundation model
- Obligations pushed into the catalogue

Related modules
Products · Risk and operations
EU AI Act Art. 14 · Art. 26(2)
Human oversight
Designs and records the human-oversight measures required by Art. 14(4)(a–e) for each high-risk system, and the deployer's assignment of competent oversight under Art. 26(2). The design auto-populates Annex IV §2(e).
- Five measures per system, with the person assigned
- Deployer and provider views
- Evidence for the Fw 132/2025 §6.2 requirement

Related modules
Products · Risk and operations
EU AI Act Art. 73 + DORA Art. 19 + GDPR Art. 33 + NIS2 Art. 23
Incident management
Report a serious incident once. Genyo classifies its severity, works out which other regimes it triggers, starts every clock, and pre-fills each authority's notification from the same record — AgID under the AI Act, Banca d'Italia under DORA, the Garante under GDPR, ACN under NIS2.
- Six steps: detection, classification, cross-regulation, containment, notifications, review
- Deadlines per regime: 2/10/15 days, 24h/72h/1 month, 72h
- Final report under Art. 73(7) and root-cause analysis tracked

Related modules
Products · Workspace, training and support
All supervisors
Inspection dossier
Assembles the package a supervisor asks for — registers, classifications, assessments, evidence, audit ledger — in the order they read it, and tracks their questions and your answers during the inspection. Covers financial-services supervisors, utilities regulators and NIS2 authorities.
- One dossier per supervisor, per entity
- Q&A tracker with deadlines
- Exports with chain-of-custody hashes

Related modules
Products · Getting started
Product configuration
Integration
A step-by-step wizard for each connector: what it feeds, which credentials it needs (always read-only), and what happens on the first sync. Model registries, run metrics, deployment metadata and security signals land in the evidence base without re-keying.
- 18 connectors across ML platforms, observability, Shadow AI, guardrails and evaluation
- Read-only service principals and tokens only
- Each connector is mapped to the modules it feeds

Related modules
Products · Workspace, training and support
Annex IV §2 · GDPR Art. 30 · Fw 132/2025 §6.1
Model & Data Cards
A transparency card per model that reviewers, auditors and — where required — affected persons can read: purpose, architecture, data, limitations, oversight, and the GDPR Art. 30 record of processing. Reviewers see the card before a decision.
- Generated from the Model registry and Training-data compliance
- Internal portal with role-based access
- Exportable for the Art. 13 transparency duty

Related modules
Products · Compliance and documentation
14 frameworks
Obligation catalogue
Where regulation becomes work. 135 obligations across 14 frameworks, each with an owner, a status, a maturity level and links to the evidence that satisfies it. The cross-cutting baseline (AI Act, GDPR, Data Act) applies always; sector and NIS2 overlays switch on per entity.
- Sector overlays for financial services, utilities, health, digital services, automotive, telecoms and more
- Obligations pre-fulfilled from Build AI metadata where available
- Per-system and per-entity completion scores

Related modules
Products · Risk and operations
EU AI Act Art. 72
Post-market monitoring
Builds the post-market monitoring plan required by Art. 72: metrics detected from the connected platforms, thresholds, reporting cadence and the triggers that open an incident. Drift beyond tolerance becomes an incident record automatically.
- Five-step plan setup per system
- Telemetry from Datadog, Dynatrace and the ML platforms
- Thresholds linked to Incident management

Related modules
Products · Compliance and documentation
EU AI Act Art. 25–27
Role assessment
Under Art. 3 and Art. 25, the role you hold for each model determines which obligations you carry. The wizard settles provider versus deployer per model and per service, lists the Art. 9–17 obligations that follow, and produces the contractual clauses and the Annex IV or Annex VIII registration that apply.
- A vendor may hold different roles in different services
- Clause set generated per role
- Feeds the Obligation catalogue and Vendor assessment

Related modules
Products · Risk and operations
EU AI Act Art. 4 · Art. 26 · L. 300/1970 Art. 4
Shadow AI monitor
Reads the inventory of GenAI applications discovered by your security stack — Purview, Netskope, Zscaler, Harmonic Security, Reco — with risk scores, OAuth grants and sensitive-data exposure events, and correlates them with the AI service catalogue. Relevant tools are promoted to the registry; DLP events can open incidents.
- Whitelist management with CSV upload
- Italian labour-law constraints (Art. 4 L. 300/1970) built in
- Discovery to registry to procurement in one flow

Related modules
Products · Risk and operations
EU AI Act Art. 10
Training-data compliance
Tests whether a dataset meets the Art. 10 requirements on data governance, relevance, representativeness and bias examination before training starts. The verdict and quality band are stored with the model and reused in Annex IV.
- Run before training, not after
- Data-quality report shared with business functions
- Linked to the Model registry and the Annex IV generator

Related modules
Products · Risk and operations
DORA Art. 28 · EBA GL/2022/05 · AI Act Art. 11 · GDPR Art. 28
Vendor assessment
Assesses each critical ICT and AI third party against DORA Art. 28, the EBA outsourcing guidelines, AI Act Art. 11, GDPR Art. 28 and NIS2 Art. 21(2)(d): documentation, SLAs, exit strategy, concentration, replacement time and AI Act role. One green assessment per critical provider.
- Register of critical third parties per entity
- GPAI dossier per foundation-model vendor
- Feeds the Vigilanza Italia FEI register

Related modules
Products · Supervision (Italy)
Banca d'Italia template v3 · DORA
Vigilanza Italia
Produces the Relazione per la Vigilanza in the Banca d'Italia template (v3, September 2026 revision) from the platform's own evidence: company profile, board competencies, AI register, shadow-AI whitelist, DPIA measures, resilience testing with RTO/RPO, and the FEI register of critical ICT providers with exposure anchoring.
- Sections filled from the modules, not re-typed
- Pre-transmission check with blocking and non-blocking findings
- First of the national country packs

Related modules
Models built to be governed.
Build AI is Redo's pipeline for designing, developing and maintaining AI models — engineered for speed, and engineered so that every artefact the AI Act asks for is produced as the model is built. Genyo Govern AI is our proof: we built it this way.
Governance inherited, not added
A model that leaves Build AI arrives in Govern AI with its obligations already partly met. The Annex IV generator reads the pipeline's metadata; the training-data check is already on file; monitoring thresholds are already set.
- Where it comes fromThe pipeline was first built for credit-risk modelling at a large Italian utility, and then used to build Genyo itself.
- How we engageA scoped delivery with your data team, or the full build of a specific model, with governance artefacts as part of the deliverable. Engagement terms on request.
Genyo is the proof
Twenty-five modules, fourteen frameworks and eighteen connectors, designed, developed and maintained on Build AI. When we say the pipeline is fast and produces its own compliance metadata, the platform you are evaluating is the evidence.
See the modulesFrom inventory to inspection, without leaving the platform.
Classify every AI system, map it to the 135 obligations that may apply, collect evidence from the systems that produce it, and hand your supervisor a dossier that reads the way they read.
Built for the people who sign
Every workflow is assigned across the three lines of defence and signed with eIDAS. The platform enforces separation of duties; the audit log proves it.
Chief Risk Officer
Consolidated AI risk register, 44 catalogued risks with KRI templates, sector overlays.
Compliance Officer
Obligation status by article, inspection dossier, supervisor Q&A tracker.
DPO
DPIA generated with the FRIA, Garante notifications, Art. 36 prior consultation.
Internal Audit
Append-only ledger, evidence matrix, completeness verifier, chain integrity check.
How coverage works
Regulation becomes work through the obligation catalogue: 135 obligations across 14 frameworks, each tied to an article, an owner and the evidence that satisfies it. The baseline applies always; sector, NIS2 and national overlays switch on per entity.
- Classify once, inherit everythingThe Art. 6 risk class of a system decides which obligations follow. Change the class and the catalogue updates.
- Evidence from the sourceModel registries, run metrics and telemetry arrive through read-only connectors and attach to the obligation they satisfy.
- Hash-chained ledgerEvery action, actor and timestamp in an append-only log with SHA-256 chaining — exportable for the supervisor.
The modules of Govern AI
Grouped as they appear in the product.
AI inventory
Compliance and documentation
Risk and operations
Supervision (Italy)
Workspace, training and support
Ready for the supervisor
The Inspection dossier assembles what AgID, Banca d'Italia, CONSOB, IVASS, the Garante, ACN or the EU AI Office ask for, in the order they read it, and tracks their questions. For Italian institutions, Vigilanza Italia produces the Banca d'Italia report in the authority's own template.
Controls for the models underneath.
General-purpose models and in-house ML need their own instruments: GPAI qualification and systemic-risk checks, training-data tests, oversight design, post-market telemetry — and a place for your evaluation and red-team results to become evidence.
GPAI assessment
Art. 51–55 qualification, 10²⁵ FLOP systemic-risk test, re-run on vendor updates.
Training-data compliance
Test a dataset against Art. 10 before training; verdict and quality band on file.
Human oversight design
The five Art. 14(4) measures, recorded per system and auto-populated into Annex IV.
Post-market monitoring
Metrics, thresholds and incident triggers under Art. 72, fed from your telemetry.
ML lifecycle, article by article
For models you train yourself, the tools follow the lifecycle the AI Act describes: data governance before training, oversight design before deployment, monitoring after.
- Before trainingTraining-data compliance tests the dataset against Art. 10 and files the data-quality report with the model.
- Before deploymentHuman oversight records the Art. 14(4) measures; the Model & Data Card is generated for reviewers.
- In productionPost-market monitoring reads telemetry from Datadog, Dynatrace and the ML platforms; drift beyond tolerance opens an incident.
Your evaluation stack becomes evidence
Results from Garak, PyRIT, DeepEval and RAGAS, guardrail policies from NeMo, PII findings from Presidio — each lands against the article it supports.
Conformità e governance dell'IA. In un unico posto.
Genyo Govern AI riunisce in un'unica piattaforma il controllo, la governance e la conformità di ogni sistema di IA che usi — l'AI Act, le regole del tuo settore e ogni autorità nazionale dell'Unione, con le evidenze che la vigilanza ti chiederà.
Progettato per banche, assicurazioni e gestori. Realizzato a Milano da Redo S.r.l.
Tre modi di lavorare con Genyo
Governa ciò che già usi, costruisci ciò che ti serve, controlla i modelli generali e di ML sotto a entrambi.
Governance e Conformità
Inventaria, classifica e documenta ogni sistema di IA. Collegalo a ogni obbligo applicabile, raccogli le evidenze e consegna alla vigilanza un dossier.
Scopri Govern AIBuild AIBuild AI
Progetta, sviluppa e mantieni modelli di IA su una pipeline costruita per la velocità — con i metadati di governance generati lungo la strada, non a posteriori.
Scopri Build AIStrumentiStrumenti di AI Governance per GPAI e ML
Qualifica i modelli per finalità generali, verifica i dati di addestramento, progetta la sorveglianza umana, monitora post-market — e collega il tuo stack di valutazione e red-team.
Scopri gli strumentiOgni sistema di IA, in una schermata
Classe di rischio, categoria Allegato III, ruolo di fornitore o deployer, ciclo di vita, stato nella banca dati UE, modelli in uso e rischi collegati — una riga per sistema, per entità. È il registro che la vigilanza chiederà di vedere.

Quattordici framework, letti insieme
Un incidente ai sensi dell'AI Act è quasi sempre anche un incidente DORA e GDPR. Genyo collega ogni modulo a ogni articolo che lo vincola: un'azione sola soddisfa ogni regime, con le scadenze di ciascuno.
- Baseline trasversaleAI Act, GDPR e Data Act si applicano a ogni sistema di default.
- Overlay di settoreDORA, linee guida EBA, comunicazioni IVASS e Banca d'Italia, Solvency II, MiFID — attivati per entità.
- Un questionario, più outputUn unico flusso FRIA + DPIA produce entrambe le valutazioni; una sola segnalazione di incidente notifica AgID, Banca d'Italia e Garante.
Vedi la schermata completa →Regole locali per ogni Stato membro
L'AI Act è europeo. La sua applicazione è nazionale — autorità di vigilanza, template di notifica, circolari di settore, diritto del lavoro. Genyo modella le autorità e la normativa nazionale di tutti i 27 Stati membri e genera gli adempimenti che ciascuna si aspetta.
- Mappa delle autorità per PaeseQuale autorità riceve quale notifica, ai sensi di quale articolo, entro quale scadenza.
- Overlay nazionaliL. 132/2025, D.Lgs. 138/2024 e Modello 231 oggi; altre giurisdizioni si aggiungono man mano che arriva la normativa attuativa.
- Adempimenti nel formato della vigilanzaIl modulo Vigilanza Italia produce la Relazione per Banca d'Italia dalle evidenze della piattaforma.
Collegato a dove i tuoi modelli già vivono
Connettori in sola lettura portano registri dei modelli, metriche, metadati di deployment e segnali di sicurezza direttamente nella base delle evidenze. Nulla viene ribattuto a mano.
Più società, più Paesi, una sola dashboard
Per i gruppi la governance è un problema di consolidamento. Ogni entità giuridica mantiene registro, overlay e autorità proprie; la capogruppo vede tutto consolidato, con la separazione dei compiti garantita per entità.
- Perimetro per entitàFramework, autorità e ruoli sono definiti per società e per Paese.
- Vista di gruppoCRO e CCO della capogruppo leggono un registro dei rischi e uno stato degli obblighi consolidati.
- Modelli condivisi, evidenze separateUn modello usato in tre controllate compare una volta nel registro e tre volte negli obblighi.
Vedi la schermata completa →Monitoraggio post-market per ogni tipo di modello
L'Art. 72 richiede un piano di monitoraggio; non dice cosa misurare. Genyo fornisce set di metriche per tipo di modello, collegati alla vostra telemetria, con soglie che aprono un incidente quando vengono superate.
- GPAI — LLM, Agent, RAGTassi di allucinazione e tossicità per gli assistenti; completamento dei task e chiamate non sicure per gli agenti; fedeltà e precisione del contesto per la retrieval.
- ML — binario, multi-classe, regressioneAUC, drift PSI e parità dei tassi di approvazione per i modelli binari; macro-F1 e recall per classe per i multi-classe; MAE, RMSE e bias per la regressione.
- Dalla violazione all'incidenteUna metrica fuori tolleranza diventa un record di incidente con la scadenza Art. 73 già in corso — il drift sul modello di credito qui sopra è INC-2026-007.
Vedi la schermata completa →Shadow AI, scoperto e governato
Il vostro stack di sicurezza vede già le app GenAI che i dipendenti usano. Genyo legge quell'inventario, lo correla con il catalogo dei servizi IA, ne valuta il rischio e trasforma l'uso non autorizzato in una richiesta di procurement governata — o in un blocco.
- Cinque fonti, una listaPurview, Netskope, Zscaler, Harmonic Security e Reco alimentano app scoperte, grant OAuth ed eventi su dati sensibili.
- Rischio, non solo presenzaUtenti, grant ed eventi DLP ordinano ogni app; lo strumento per i verbali con accesso a posta e calendario pesa più del chatbot a cui nessuno accede.
- Nel rispetto dello StatutoLa discovery rispetta l'Art. 4 dello Statuto dei Lavoratori — segnali aggregati, nessun controllo individuale — e alimenta le evidenze di alfabetizzazione Art. 4.
Vedi la schermata completa →Sorveglianza umana, progettata e documentata
L'Art. 14 richiede che una persona possa comprendere, mettere in discussione, annullare e fermare un sistema ad alto rischio. Genyo registra le cinque misure per sistema, chi ne è responsabile e cosa è accaduto davvero in esercizio.
- Le cinque misure, da (a) a (e)Capacità e anomalie, bias di automazione, interpretazione, override, pulsante di arresto — ciascuna con design, responsabile e stato.
- Competenti, formati, assegnatiI supervisori sono nominati per sistema e la loro formazione Genyo Academy è aggiornata, come l'Art. 26(2) chiede ai deployer.
- Una sorveglianza dimostrabileDecisioni campionate, override, escalation ed esercitazioni di arresto degli ultimi 30 giorni, esportati direttamente nell'Allegato IV §2(e).
Vedi la schermata completa →Genyo è ciò che costruiamo con Build AI
La piattaforma che stai guardando — venticinque moduli, quattordici framework, diciotto connettori — è stata progettata, sviluppata ed è mantenuta sulla pipeline Build AI. È il modo più rapido che conosciamo per portare un modello dal requisito alla produzione, e genera lungo la strada i propri metadati di conformità.
Parla con il team Build AINata a Milano, per l'Europa regolamentata.
Redo S.r.l. è la società dietro Genyo.ai. Costruiamo software di AI governance per banche, assicurazioni e gestori, e costruiamo modelli di IA con la stessa pipeline.
Perché abbiamo costruito Genyo
L'AI Act è arrivato sopra DORA, GDPR, NIS2 e dieci anni di linee guida di settore. Alle istituzioni veniva chiesto di governare l'IA su cinque regimi con fogli di calcolo ed email.
Avevamo costruito modelli di rischio di credito sotto il controllo della vigilanza e sapevamo cosa chiede un'ispezione. Genyo è il registro che avremmo voluto avere: ogni sistema, ogni obbligo, ogni evidenza in un unico posto, nell'ordine della vigilanza.
L'abbiamo costruito sulla nostra pipeline Build AI: per questo la piattaforma produce da sé i propri metadati di conformità, e per questo offriamo la pipeline ai clienti.
Competenza regolamentare
- AI Act, GDPR e Data Act
- DORA, linee guida EBA e aspettative di vigilanza BCE/SSM
- Comunicazioni IVASS e Banca d'Italia, regole CONSOB
- L. 132/2025, D.Lgs. 138/2024 (NIS2), D.Lgs. 231/2001
- Autorità nazionali nei 27 Stati membri
Certificazioni


Redo S.r.l. è certificata ISO/IEC 27001.
Genyo.ai opera in conformità ai requisiti DORA per i fornitori ICT terzi delle entità finanziarie.
Richiedi una demo.
Diteci quali entità, framework e Paesi sono in perimetro. Rispondiamo entro due giorni lavorativi con una proposta di walkthrough di 45 minuti.
Grazie — la richiesta è stata inviata.
Vi risponderemo il prima possibile.
Segnalazione di un incidente.
Potete inviare questo modulo senza fornire nome o dati di contatto. Tutte le risposte sono trattate in modo confidenziale.
Grazie — la segnalazione è stata inviata.
Vi risponderemo il prima possibile.
Diciotto connettori, tutti in sola lettura.
Genyo non scrive mai sulle vostre piattaforme. Ogni connettore legge registri, run, telemetria o segnali di sicurezza e li archivia come evidenze rispetto agli obblighi che soddisfano.
Piattaforme ML
Osservabilità
Shadow AI e sicurezza dei dati
Privacy
Guardrail
Red-team
Valutazione
Manca un connettore?
Diteci quale piattaforma usate e cosa dovrebbe alimentare. I connettori seguono uno schema in sola lettura, quindi la maggior parte delle richieste si risolve in settimane.
Richiedi un connettorePrivacy e cookie
Perché questa informativa?
Redo S.r.l. (di seguito, la Società), P. IVA: 11601770966, con sede legale in Corso Garibaldi, 49, Milano, riconosce il ruolo centrale dei dati personali nell'ecosistema socio-economico in cui opera, nonché le criticità legate al loro utilizzo nella fornitura di servizi che comportano l'uso non occasionale di sistemi di intelligenza artificiale. La Società è pertanto pienamente consapevole dell'importanza di una comunicazione chiara e trasparente al fine di mitigare i rischi per i diritti e le libertà di tutte le persone fisiche i cui dati personali sono trattati. Inoltre, la normativa in materia di protezione dei dati (in particolare il Regolamento (UE) 2016/679, "Regolamento generale sulla protezione dei dati" — GDPR) ci impone di fornire le seguenti informazioni relative al trattamento dei vostri dati personali, ai sensi degli articoli 13 e 14. Per questi motivi, Redo S.r.l., Corso Garibaldi, 49 — 20121, Milano (MI), in qualità di "Titolare del trattamento", fornisce con la presente informativa le modalità di trattamento dei vostri dati personali in relazione al proprio sito web.
Il ruolo della Società
È importante sottolineare fin da subito che la Società, nello svolgimento delle proprie attività, opera sia come Titolare del trattamento sia come Responsabile del trattamento. Poiché, ai sensi degli articoli 13 e 14 del GDPR, l'obbligo di fornire informazioni sul trattamento spetta esclusivamente ai Titolari del trattamento, il presente documento riguarda esclusivamente le attività di trattamento per le quali la Società agisce in qualità di Titolare. Tra queste rientrano le attività legate alla registrazione al servizio e al funzionamento del sito web, relative ai dati personali delle persone fisiche che vi accedono sia come visitatori sia come operatori muniti di credenziali di accesso, ai fini della fruizione dei servizi offerti. Tuttavia, nell'interesse della trasparenza e nello spirito di leale collaborazione con i Titolari del trattamento, la Società ritiene utile fornire ai propri clienti informazioni relative alle attività di trattamento svolte in qualità di Responsabile del trattamento. Tra queste rientrano le attività derivanti dalla fornitura dei propri servizi tipici (controlli di qualità, arricchimento e ampliamento dei dati di addestramento, addestramento iniziale o ri-addestramento dei modelli, elaborazione e restituzione delle inferenze per le finalità scelte dai clienti tra quelle disponibili, e conservazione dei file originali del database per l'addestramento). A tal fine, su richiesta dei clienti-Titolari, è disponibile la Valutazione d'Impatto sulla Protezione dei Dati (DPIA) predisposta a seguito della valutazione d'impatto ai sensi dell'articolo 35 del GDPR. Estratti del documento possono inoltre essere messi a disposizione di terzi, su richiesta, nell'interesse della massima trasparenza. Va tuttavia precisato che, per quanto riguarda i trattamenti svolti in qualità di Responsabile del trattamento, la Società non determina le specifiche finalità e categorie di dati personali utilizzati di volta in volta (che dipendono in parte dalle scelte discrezionali dei clienti), i termini finali di conservazione dei dati, i soggetti a cui i Titolari scelgono di comunicarli, né numerosi altri aspetti rilevanti del trattamento, ad eccezione di quelli specificamente legati alle caratteristiche tecniche dei servizi forniti. Inoltre, la Società non è in grado di rispondere direttamente e autonomamente alle richieste degli interessati, non conoscendo l'identità delle persone coinvolte, operando esclusivamente su informazioni non riconducibili a specifiche persone fisiche (dati pseudonimizzati all'origine e pertanto anonimi dal punto di vista della Società, che non possiede, né può possedere, mezzi legali o tecnici per re-identificare gli interessati). Ciò nonostante, la DPIA sopra citata contiene informazioni relative alle misure tecniche "by design" adottate per agevolare l'esercizio dei diritti degli interessati da parte dei clienti-Titolari, in particolare con riferimento alla spiegabilità delle inferenze dei modelli di IA e alla supervisione umana dei processi (supervisione "human-in-the-loop"), in conformità all'articolo 22 del GDPR nonché alla normativa correlata in materia di Intelligenza Artificiale (Reg. (UE) 2025/1689 e normative settoriali, ad es. EBA). Infine, si precisa che le operazioni svolte dalla Società ai fini dello sviluppo di ulteriori modelli di IA per proprio interesse sono normalmente effettuate utilizzando dati sintetici o dati sottoposti a processi (embedding) che li rendono completamente anonimi e non riconducibili a persone fisiche identificate o identificabili, e che pertanto non costituiscono trattamento di dati personali ai sensi dell'articolo 4, paragrafo 2, del GDPR. Qualora in futuro venissero utilizzati dati personali per le finalità descritte nel presente paragrafo, sarà responsabilità del Titolare del trattamento (che sia la Società, il cliente o, in caso di contitolarità, il soggetto designato secondo gli accordi ad assumere tale obbligo) informare gli interessati e garantire l'esistenza delle basi giuridiche necessarie.
Venticinque moduli, un solo registro.
Ogni modulo porta con sé l'articolo che lo vincola. Insieme coprono AI Act, GDPR, DORA, NIS2 e gli overlay di settore e nazionali — dalla prima classificazione al dossier per la vigilanza.
Per iniziare
Inventario IA
Compliance e documentazione
Rischio e operatività
Vigilanza Italia
Workspace, formazione e supporto
Prodotti · Per iniziare
EU AI Act · L. 132/2025
Verifica di conformità IA
Un questionario guidato che posiziona l'organizzazione rispetto all'AI Act, alla L. 132/2025 e agli overlay di settore applicabili. Il risultato è una lista di gap con responsabili, usata per pianificare i primi novanta giorni sulla piattaforma.
- Posiziona l'organizzazione come fornitore, deployer o entrambi
- Segnala i framework e le autorità in perimetro
- Produce una lista di gap prioritizzata con responsabili

Moduli collegati
Prodotti · Inventario IA
EU AI Act Art. 11 · Annex IV §2 · Art. 51–55
Registro dei modelli di IA
La scheda tecnica di ogni modello dietro un sistema: architettura, finalità di addestramento, parametri, compute, capacità e lineage — sincronizzati dalle piattaforme ML invece che inseriti a mano. Alimenta l'Allegato IV §2 e la qualificazione GPAI.
- Sincronizzato da MLflow, Databricks Unity Catalog, Azure ML, SageMaker, W&B
- Le capacità guidano la Valutazione GPAI
- Collegato a sistemi, data card e piani di monitoraggio

Moduli collegati
Prodotti · Rischio e operatività
EU AI Act Art. 26 · Art. 4
Procurement IA
Un canale governato per la nuova domanda di IA: intake, verifica delle funzioni, valutazione di procurement, decisione, poi classificazione nel registro. È la mitigazione strutturale dello shadow AI: sposta la domanda dal canale ombra a uno governato con audit trail hash-chained.
- Ogni richiesta diventa una voce del registro o un rifiuto documentato
- Collegato a Valutazione fornitori e Valutazione del ruolo
- Incluso nella policy sull'uso dell'IA

Moduli collegati
Prodotti · Vigilanza Italia
EU AI Act + L. 132/2025 + DORA · NIS2 · MiFID · Solvency II
Valutazione regolamentare IA
Un'unica valutazione regolamentare che legge l'AI Act insieme alla L. 132/2025 e alla normativa di settore applicabile all'entità — DORA, NIS2, MiFID, Solvency II — e produce l'insieme degli obblighi applicabili per il catalogo.
- Normativa nazionale e di settore stratificata sull'AI Act
- Per entità, per Paese
- L'output confluisce nel Catalogo degli obblighi

Moduli collegati
Prodotti · Rischio e operatività
All 14 frameworks
Governance dei rischi IA
Il registro dei rischi IA: 44 rischi a catalogo con template KRI, overlay settoriali, responsabili e piani di trattamento, organizzati secondo le comunicazioni di Banca d'Italia e IVASS sulla gestione dei rischi. Ogni rischio è collegato agli obblighi che minaccia e ai controlli che lo mitigano.
- 44 rischi con template KRI, estensibili
- Overlay settoriale per servizi finanziari e utilities
- Consolidato a livello di gruppo per il CRO

Moduli collegati
Prodotti · Inventario IA
EU AI Act Art. 6 + Annex III
Classificazione dei sistemi di IA
Una classificazione in tre passi che assegna la classe di rischio di ogni sistema ai sensi dell'Art. 6 e dell'Allegato III, registra la motivazione e segnala la componente IA NIS2 dove l'entità rientra nel D.Lgs. 138/2024. La classificazione determina quali obblighi si applicano a valle.
- Vietato, alto rischio, limitato o minimo — con il caso d'uso dell'Allegato III
- Motivazione conservata insieme alla classificazione, per la vigilanza
- Rieseguita in caso di modifica sostanziale

Moduli collegati
Prodotti · Inventario IA
EU AI Act Art. 49 · Fw 132/2025 §5.1
Registro dei sistemi di IA
Il registro unico di ogni sistema di IA fornito o utilizzato: responsabile, finalità, stato, entità, classificazione ed eventi del ciclo di vita. È la fonte da cui leggono tutti gli altri moduli e il record che va nella banca dati UE ai sensi dell'Art. 49.
- Una riga per sistema, per entità, con responsabile e stato
- Log del ciclo di vita append-only
- Esportazione per la banca dati UE e per le ispezioni

Moduli collegati
Prodotti · Compliance e documentazione
EU AI Act Art. 11 · Annex IV
Generatore Allegato IV
Genera il dossier di documentazione tecnica dell'Allegato IV richiesto dall'Art. 11 per i sistemi ad alto rischio. Nove sezioni precompilate dai metadati di sistema e, per i modelli costruiti con Build AI, direttamente dalla pipeline di addestramento. Controllo di versione e flusso di revisione rendono ogni dossier difendibile.
- Template in nove sezioni con precompilazione automatica
- Storico delle versioni e flusso autore/revisore
- Sezioni popolate da Sorveglianza umana, Conformità dei dati e Registro dei modelli

Moduli collegati
Prodotti · Compliance e documentazione
EU AI Act Ch. I–XII
Cockpit Articoli
Le autorità ragionano per articolo. Il cockpit mostra l'intera struttura dell'AI Act, Capi I–XII, con stato, maturità ed evidenze per ogni articolo su tutti i sistemi: la vista incrociata che serve prima di un'ispezione.
- Ogni articolo dell'AI Act con il suo stato
- Dall'articolo ai sistemi alle evidenze
- Usato dal Dossier ispettivo e dalla Checklist di conformità

Moduli collegati
Prodotti · Per iniziare
EU AI Act Art. 4 · Fw 132/2025
Dati aziendali
L'anagrafica di ogni entità giuridica: settore, posizione nel gruppo, overlay applicabili, soglie di escalation, competenze del Consiglio e formazione svolta o pianificata. Ogni valutazione e ogni relazione di vigilanza legge da qui: si compila una volta sola.
- Un profilo per entità giuridica, consolidato a livello di gruppo
- Competenze e formazione dell'organo registrate come evidenza Art. 4
- Alimenta la Relazione per la Vigilanza e il dossier ispettivo

Moduli collegati
Prodotti · Compliance e documentazione
AI Act · GDPR · Data Act · DORA · NIS2
Checklist di conformità
Una checklist operativa derivata dal catalogo: la baseline sempre applicabile, la lente NIS2 componente IA per le entità in perimetro e l'overlay di settore — DORA e linee guida EBA per i servizi finanziari. Ogni voce ha stato, maturità ed evidenze.
- Generata per entità dal suo profilo
- Le voci rimandano all'articolo e al modulo che le adempie
- Esportabile per l'internal audit

Moduli collegati
Prodotti · Compliance e documentazione
EU AI Act Art. 43 + Art. 47
Valutazione di conformità
Instrada ogni sistema ad alto rischio verso la procedura corretta — controllo interno Annex VI per la maggior parte dei casi d'uso finanziari, organismo notificato Annex VII per i sistemi biometrici — e la esegue: prontezza QMS, matrice delle evidenze, verifica di completezza, poi Dichiarazione UE di conformità e marcatura CE. Nove ruoli sulle tre linee di difesa firmano con eIDAS.
- Albero decisionale dalla classificazione Art. 6 ad Annex VI o VII
- Evidenze collegate ai controlli QMS ISO 42001
- Registro di audit append-only con hash concatenati per l'intera procedura

Moduli collegati
Prodotti · Workspace, formazione e supporto
EU AI Act Art. 26
Cockpit Deployer
Tutto ciò che un deployer deve ai sensi dell'Art. 26 in un unico workspace: uso secondo le istruzioni, assegnazione di sorveglianza umana competente, pertinenza dei dati di input, monitoraggio del funzionamento, conservazione dei log, informazione delle persone interessate, cooperazione con le autorità e FRIA.
- Una checklist per ogni sistema utilizzato
- Evidenze collegate da Sorveglianza umana e Monitoraggio post-market
- Stato leggibile dalla vigilanza

Moduli collegati
Prodotti · Compliance e documentazione
EU AI Act Art. 27 + GDPR Art. 35
FRIA + DPIA
La valutazione d'impatto sui diritti fondamentali (AI Act Art. 27) e quella sulla protezione dei dati (GDPR Art. 35) condividono gran parte delle domande. Genyo le pone una volta sola, instrada il caso verso solo FRIA, solo DPIA o combinata, e genera entrambi i documenti in tempo reale.
- Flusso in cinque fasi: ambito, triage del regime, persone interessate, rischi e mitigazioni, riesame
- Parere del DPO e consultazione preventiva al Garante (Art. 36) tracciati
- Rivalutazione attivata in caso di modifica sostanziale

Moduli collegati
Prodotti · Workspace, formazione e supporto
EU AI Act Art. 4 · Fw 132/2025 §9.1
Genyo Academy
Il percorso di alfabetizzazione IA richiesto dall'Art. 4, organizzato per ruolo e livello — dai consiglieri di amministrazione ai revisori dei modelli. Ogni completamento è scritto nel registro di audit come evidenza e lo stato Academy compare nella Relazione per la Vigilanza.
- Livelli L1–L3 per ruolo
- Curriculum su AI Act, DORA, GDPR e overlay di settore
- Completamenti come evidenza automatica

Moduli collegati
Prodotti · Compliance e documentazione
EU AI Act Art. 51–55
Valutazione GPAI
Stabilisce se un modello è un modello di IA per finalità generali, se comporta rischio sistemico rispetto alla soglia di 10²⁵ FLOP e quali obblighi degli Artt. 53–55 ne derivano per fornitore e deployer. Si riesegue automaticamente quando il vendor pubblica una nuova versione.
- Legge le capacità dal Registro dei modelli
- Dossier vendor per ogni foundation model
- Obblighi inseriti nel catalogo

Moduli collegati
Prodotti · Rischio e operatività
EU AI Act Art. 14 · Art. 26(2)
Sorveglianza umana
Progetta e registra le misure di sorveglianza umana richieste dall'Art. 14(4)(a–e) per ogni sistema ad alto rischio, e l'assegnazione di sorveglianza competente da parte del deployer ai sensi dell'Art. 26(2). Il design popola automaticamente l'Allegato IV §2(e).
- Cinque misure per sistema, con la persona assegnata
- Viste deployer e fornitore
- Evidenza per il requisito Fw 132/2025 §6.2

Moduli collegati
Prodotti · Rischio e operatività
EU AI Act Art. 73 + DORA Art. 19 + GDPR Art. 33 + NIS2 Art. 23
Gestione incidenti
Segnala un incidente grave una volta sola. Genyo ne classifica la gravità, individua gli altri regimi che attiva, avvia ogni scadenza e precompila la notifica di ciascuna autorità dallo stesso record: AgID per l'AI Act, Banca d'Italia per DORA, il Garante per il GDPR, ACN per NIS2.
- Sei passi: rilevazione, classificazione, cross-normativa, contenimento, notifiche, riesame
- Scadenze per regime: 2/10/15 giorni, 24h/72h/1 mese, 72h
- Report finale Art. 73(7) e analisi delle cause tracciati

Moduli collegati
Prodotti · Workspace, formazione e supporto
All supervisors
Dossier ispettivo
Assembla il pacchetto che l'autorità richiede — registri, classificazioni, valutazioni, evidenze, registro di audit — nell'ordine in cui lo legge, e traccia domande e risposte durante l'ispezione. Copre le autorità dei servizi finanziari, i regolatori delle utilities e le autorità NIS2.
- Un dossier per autorità, per entità
- Tracker Q&A con scadenze
- Esportazioni con hash di custodia

Moduli collegati
Prodotti · Per iniziare
Product configuration
Integrazione
Una procedura guidata per ogni connettore: cosa alimenta, quali credenziali servono (sempre in sola lettura) e cosa succede alla prima sincronizzazione. Registri dei modelli, metriche, metadati di deployment e segnali di sicurezza arrivano nella base delle evidenze senza ribattitura.
- 18 connettori tra piattaforme ML, osservabilità, Shadow AI, guardrail e valutazione
- Solo service principal e token in sola lettura
- Ogni connettore è mappato sui moduli che alimenta

Moduli collegati
Prodotti · Workspace, formazione e supporto
Annex IV §2 · GDPR Art. 30 · Fw 132/2025 §6.1
Model & Data Card
Una scheda di trasparenza per modello leggibile da revisori, auditor e — dove richiesto — persone interessate: finalità, architettura, dati, limiti, sorveglianza e registro dei trattamenti GDPR Art. 30. I revisori vedono la scheda prima della decisione.
- Generata dal Registro dei modelli e dalla Conformità dei dati
- Portale interno con accessi per ruolo
- Esportabile per l'obbligo di trasparenza Art. 13

Moduli collegati
Prodotti · Compliance e documentazione
14 frameworks
Catalogo degli obblighi
Dove la regolamentazione diventa lavoro. 135 obblighi su 14 framework, ciascuno con responsabile, stato, livello di maturità e collegamenti alle evidenze che lo soddisfano. La baseline trasversale (AI Act, GDPR, Data Act) si applica sempre; gli overlay di settore e NIS2 si attivano per entità.
- Overlay settoriali per servizi finanziari, utilities, sanità, servizi digitali, automotive, telecomunicazioni e altri
- Obblighi già adempiuti dai metadati Build AI dove disponibili
- Punteggi di completamento per sistema e per entità

Moduli collegati
Prodotti · Rischio e operatività
EU AI Act Art. 72
Monitoraggio post-market
Costruisce il piano di monitoraggio post-market richiesto dall'Art. 72: metriche rilevate dalle piattaforme collegate, soglie, cadenza di reporting e trigger che aprono un incidente. Un drift oltre la tolleranza diventa automaticamente un record di incidente.
- Configurazione del piano in cinque passi per sistema
- Telemetria da Datadog, Dynatrace e dalle piattaforme ML
- Soglie collegate alla Gestione incidenti

Moduli collegati
Prodotti · Compliance e documentazione
EU AI Act Art. 25–27
Valutazione del ruolo
Ai sensi degli Artt. 3 e 25, il ruolo ricoperto per ciascun modello determina gli obblighi. Il wizard stabilisce fornitore o deployer per modello e per servizio, elenca gli obblighi Artt. 9–17 che ne conseguono e produce le clausole contrattuali e la registrazione Allegato IV o VIII applicabili.
- Un vendor può ricoprire ruoli diversi in servizi diversi
- Set di clausole generato per ruolo
- Alimenta il Catalogo degli obblighi e la Valutazione fornitori

Moduli collegati
Prodotti · Rischio e operatività
EU AI Act Art. 4 · Art. 26 · L. 300/1970 Art. 4
Monitor Shadow AI
Legge l'inventario delle applicazioni GenAI scoperte dallo stack di sicurezza — Purview, Netskope, Zscaler, Harmonic Security, Reco — con scoring di rischio, grant OAuth ed eventi di esposizione di dati sensibili, e li correla con il catalogo dei servizi IA. Gli strumenti rilevanti sono promossi nel registro; gli eventi DLP possono aprire incidenti.
- Gestione della whitelist con caricamento CSV
- Vincoli giuslavoristici (Art. 4 L. 300/1970) integrati
- Dalla discovery al registro al procurement in un unico flusso

Moduli collegati
Prodotti · Rischio e operatività
EU AI Act Art. 10
Conformità dei dati di addestramento
Verifica se un dataset soddisfa i requisiti dell'Art. 10 su governo dei dati, pertinenza, rappresentatività ed esame dei bias prima che l'addestramento inizi. Verdetto e fascia di qualità sono conservati con il modello e riutilizzati nell'Allegato IV.
- Eseguita prima dell'addestramento, non dopo
- Report di Data Quality condivisibile con le funzioni aziendali
- Collegata al Registro dei modelli e al Generatore Allegato IV

Moduli collegati
Prodotti · Rischio e operatività
DORA Art. 28 · EBA GL/2022/05 · AI Act Art. 11 · GDPR Art. 28
Valutazione fornitori
Valuta ogni terza parte ICT e IA critica rispetto a DORA Art. 28, linee guida EBA sull'outsourcing, AI Act Art. 11, GDPR Art. 28 e NIS2 Art. 21(2)(d): documentazione, SLA, exit strategy, concentrazione, tempo di sostituzione e ruolo AI Act. Una valutazione verde per ogni fornitore critico.
- Registro delle terze parti critiche per entità
- Dossier GPAI per ogni vendor di foundation model
- Alimenta il registro FEI di Vigilanza Italia

Moduli collegati
Prodotti · Vigilanza Italia
Banca d'Italia template v3 · DORA
Vigilanza Italia
Produce la Relazione per la Vigilanza nel template di Banca d'Italia (v3, revisione settembre 2026) dalle evidenze della piattaforma: dati aziendali, competenze dell'organo, registro IA, whitelist shadow AI, misure DPIA, test di resilienza con RTO/RPO e registro FEI dei fornitori ICT critici con ancoraggio delle esposizioni.
- Sezioni compilate dai moduli, non ribattute
- Verifica pre-trasmissione con rilievi bloccanti e non bloccanti
- Il primo dei pacchetti Paese

Moduli collegati
Modelli costruiti per essere governati.
Build AI è la pipeline di Redo per progettare, sviluppare e mantenere modelli di IA — costruita per la velocità, e costruita perché ogni artefatto richiesto dall'AI Act venga prodotto mentre il modello nasce. Genyo Govern AI è la nostra prova: l'abbiamo costruito così.
Governance ereditata, non aggiunta
Un modello che esce da Build AI arriva in Govern AI con gli obblighi già in parte adempiuti. Il Generatore Allegato IV legge i metadati della pipeline; la verifica dei dati è già agli atti; le soglie di monitoraggio sono già impostate.
- Da dove vieneLa pipeline è nata per la modellazione del rischio di credito in una grande utility italiana, poi è stata usata per costruire Genyo stesso.
- Come lavoriamoUna consegna con perimetro definito insieme al vostro team dati, oppure la costruzione completa di un modello specifico, con gli artefatti di governance come parte della consegna. Condizioni su richiesta.
Genyo è la prova
Venticinque moduli, quattordici framework e diciotto connettori, progettati, sviluppati e mantenuti su Build AI. Quando diciamo che la pipeline è veloce e produce da sé i metadati di conformità, la piattaforma che state valutando è l'evidenza.
Scopri i moduliDall'inventario all'ispezione, senza uscire dalla piattaforma.
Classifica ogni sistema di IA, collegalo ai 135 obblighi potenzialmente applicabili, raccogli le evidenze dai sistemi che le producono e consegna alla vigilanza un dossier scritto come lo legge.
Costruito per chi firma
Ogni flusso è assegnato sulle tre linee di difesa e firmato con eIDAS. La piattaforma applica la separazione dei compiti; il registro di audit lo dimostra.
Chief Risk Officer
Registro dei rischi IA consolidato, 44 rischi a catalogo con template KRI, overlay di settore.
Compliance Officer
Stato degli obblighi per articolo, dossier ispettivo, tracker delle richieste della vigilanza.
DPO
DPIA generata con la FRIA, notifiche al Garante, consultazione preventiva Art. 36.
Internal Audit
Registro append-only, matrice delle evidenze, verificatore di completezza, controllo di integrità della catena.
Come funziona la copertura
La regolamentazione diventa lavoro attraverso il catalogo degli obblighi: 135 obblighi su 14 framework, ciascuno legato a un articolo, a un responsabile e alle evidenze che lo soddisfano. La baseline si applica sempre; overlay di settore, NIS2 e nazionali si attivano per entità.
- Classifica una volta, eredita tuttoLa classe di rischio Art. 6 di un sistema decide quali obblighi seguono. Cambia la classe e il catalogo si aggiorna.
- Evidenze dalla fonteRegistri dei modelli, metriche e telemetria arrivano tramite connettori in sola lettura e si agganciano all'obbligo che soddisfano.
- Registro con hash concatenatiOgni azione, attore e timestamp in un log append-only con catena SHA-256 — esportabile per la vigilanza.
I moduli di Govern AI
Raggruppati come compaiono nel prodotto.
Inventario IA
Compliance e documentazione
Rischio e operatività
Vigilanza Italia
Workspace, formazione e supporto
Pronti per la vigilanza
Il Dossier ispettivo assembla ciò che AgID, Banca d'Italia, CONSOB, IVASS, Garante, ACN o l'AI Office UE richiedono, nell'ordine in cui lo leggono, e traccia le loro domande. Per le istituzioni italiane, Vigilanza Italia produce la Relazione per Banca d'Italia nel template dell'autorità.
Controlli per i modelli che stanno sotto.
I modelli per finalità generali e il ML interno hanno bisogno di strumenti propri: qualificazione GPAI e verifiche di rischio sistemico, test sui dati di addestramento, progettazione della sorveglianza, telemetria post-market — e un posto dove i risultati di valutazione e red-team diventano evidenze.
Valutazione GPAI
Qualificazione Artt. 51–55, verifica di rischio sistemico 10²⁵ FLOP, riesecuzione agli aggiornamenti del vendor.
Conformità dei dati di addestramento
Verifica un dataset rispetto all'Art. 10 prima dell'addestramento; verdetto e fascia di qualità agli atti.
Progettazione della sorveglianza umana
Le cinque misure Art. 14(4), registrate per sistema e riportate automaticamente nell'Allegato IV.
Monitoraggio post-market
Metriche, soglie e trigger degli incidenti ai sensi dell'Art. 72, alimentati dalla tua telemetria.
Ciclo di vita ML, articolo per articolo
Per i modelli che addestrate voi, gli strumenti seguono il ciclo di vita descritto dall'AI Act: governo dei dati prima dell'addestramento, sorveglianza prima del deployment, monitoraggio dopo.
- Prima dell'addestramentoLa Conformità dei dati verifica il dataset rispetto all'Art. 10 e archivia il report di qualità con il modello.
- Prima del deploymentLa Sorveglianza umana registra le misure Art. 14(4); la Model & Data Card è generata per i revisori.
- In produzioneIl Monitoraggio post-market legge la telemetria da Datadog, Dynatrace e dalle piattaforme ML; un drift oltre la tolleranza apre un incidente.
Il tuo stack di valutazione diventa evidenza
Risultati di Garak, PyRIT, DeepEval e RAGAS, policy dei guardrail NeMo, rilevazioni PII di Presidio — ciascuno si aggancia all'articolo che supporta.


