Citadel — the platform

Six questions
a board has to answer.
The paperwork that proves each one.

Citadel keeps one live record of every AI system, model, agent, vendor and use case in your organisation — governed, evidenced, valued and reported from the same record your risk sits on.

6
Board questions answered from one record
5
Role-based views, from Board to System Registry
6
Modules, from Command Centre to Board Reporting
0
Calls to AI model vendors — it governs AI, it does not consume it

The number the board is given

One score, four dimensions, snapshotted daily.

ROGS is a composite, not a rating we award. The weights are configurable per customer, the inputs are the same evidence held against each system, and a snapshot is taken every day so a board pack can show movement rather than a position.

Illustrative ROGS score: 74 out of 100 ROGS 74 of 100 · illustrative 0 100

Risk and Operational Governance Score

Four dimensions, each computed from the register rather than entered by hand. A dimension with no verified evidence behind it lowers the score rather than being omitted from it.

  • Regulatory alignment
  • Governance readiness
  • Automation delta
  • Compliance coverage

The figure above is illustrative. Citadel shows no score it cannot defend: a dimension with an unavailable feed is dashed rather than estimated, and coverage is reported as the number of controls not implemented, never as a percentage.

What it is

One register. Six answers. The proof attached.

Citadel is a managed platform that gives a regulated organisation one governed register of every AI system it runs — discovered as well as declared — and holds each one to a named owner, a risk tier, a recorded decision, and the controls and evidence that prove it. It scores the estate against your own governance framework and applicable regulation, tracks the obligations and incidents arising, values each system alongside its risk, and produces the board and regulatory reporting from the same record. Built for regulated industries, and it rolls up across a group or a portfolio.

Six board questions answered from one Citadel record Six questions—what do we have, who owns it, can we prove it, does it hold up, what is it worth, and what do we report—surround one live governed record. CITADELONE LIVERECORDrisk + value + evidence 01 · KNOW ITWhat AI do we have?Inventory, including what nobody registered. 02 · OWN ITWho answers for it?Named owner, risk tier and recorded decision. 03 · PROVE ITCan we evidence it?Controls, obligations and proof on demand. 04 · TEST ITDoes it hold up?Evals on the live endpoint; failures become findings. 05 · VALUE ITWhat is it worth?Cost, benefit and return on the same record as risk. 06 · REPORT ITWhat do we tell them?Board, auditor and regulator from one source.
The board conversation becomes accelerate or stop — not a worry list.

The spine of the product

Six questions. Each with the paperwork that proves the answer.

Know what you have

One register, including the ones nobody registered

“How much AI is running in this business, and who put it there?”

Systems arrive four ways: entered by an owner, pulled in by a connector, found by an external scan of what the organisation exposes publicly, or promoted from a Sentinel engagement. Anything unregistered is flagged as shadow AI, with the source and confidence of its discovery — so a challenge to “how do you know that’s there” has an answer.

Fix accountability

A named person, a risk tier, a recorded decision

“Who is answerable for this, and what did they actually decide?”

Nothing counts as governed until those three exist. Citadel runs the approval chains that get it there, tracks them against SLA, and escalates what breaches. Decisions carry conditions with expiry; exceptions are formal, time-boxed, and carry compensating controls rather than being a note in a spreadsheet. Every act is written to an audit log that cannot be edited or deleted.

Prove it

Evidence behind every obligation, expiry tracked

“Show me the evidence — for this system, for this obligation, today.”

Regulatory obligations and control frameworks mapped onto individual systems, evidence held behind each one, warning before it lapses. A per-system compliance passport assembles the full dossier on demand. Control coverage is reported as “N not implemented”, never as a reassuring percentage.

Test it

Evaluation runs against the live endpoint, failures become findings

“Is the governance real, or is it paperwork?”

Evaluation suites run against a system’s live endpoint and produce evidence from the result. Failures become risk findings. Incidents are tracked to a named owner with a due date — and the duty to notify a regulator is tracked separately from the incident’s own status, so an incident closed without notifying still surfaces.

Value it

Cost, benefit and return on the same record as the risk tier

“What is all this AI costing, and what is it returning?”

Every system carries a financial profile on the same record as its risk tier. Citadel aggregates estate-level spend, flags waste and duplication, identifies consolidation candidates, and surfaces the opportunities that have not been taken. The conversation becomes which systems to accelerate and which to stop — not a worry list.

Report it

ROGS — Risk and Operational Governance Score, snapshotted daily

“What do I tell the board, the regulator, and the group?”

A single 0–100 composite across four dimensions — regulatory alignment, governance readiness, automation delta, compliance coverage — with weights configurable per customer. From it, a period-over-period board pack that flags material change on its own, and group or portfolio roll-up with anonymised benchmarking.

What makes it different

Three things a procurement team will check, answered.

Risk and value live on the same record

GRC tools tell a board what to be frightened of. Citadel puts the exposure and the return on the same object, so the conversation becomes “which of these do we accelerate and which do we stop” rather than a list of things to worry about. That is the difference between a compliance purchase and a strategy one.

It never shows a number it cannot defend

The main screen distinguishes three states, not two: a light lit on a verified count, dark on a verified zero, dashed when the feed is unavailable. A reassuring zero Citadel cannot prove displays as unknown, not as good news. Simulated evaluations are labelled and cannot be approved.

Citadel governs AI; it does not consume it

The platform makes no calls to any AI model vendor, and the build fails if one is reintroduced. Legal determinations — an EU AI Act classification, a fundamental-rights impact assessment — are made by the accountable person, never auto-filled. In procurement it shortens the sub-processor list and removes a class of security-review question.

Role views

Five seats at the table, five views of the same record.

  • Board / CEO — the Command Centre: estate posture, ROGS, material change
  • CFO — the AI Portfolio P&L: spend, benefit, return, duplication, consolidation
  • Governance lead — workflows: approvals, exceptions, expiries, escalations
  • Audit committee / NED — Executive Intelligence: evidence, findings, audit trail
  • Operations — the System Registry & Use Cases: the day-to-day register of record

Six modules

Command Centre · System Registry & Use Case Register · Exposure Engine · Evidence Vault & Decision Ledger · AI Portfolio P&L · Board Reporting.

What Citadel is not

Not a BI dashboard — it holds the record, it does not visualise someone else’s. Not a one-off audit — the register is live. Not a policy library — policies here are attached to systems and tracked to evidence. It does not assume your inventory exists — populating it is the first job, by Sentinel or guided self-onboarding.

Assurance

Security, stated plainly.

  • Role-based access enforced at row level, MFA for admin roles
  • Encryption at rest and in transit
  • OIDC single sign-on — Azure AD, Okta, Auth0, Google Workspace
  • UK data residency
  • No AI vendor calls from the platform, and the build fails if one is reintroduced

Framework alignment, honestly named

Citadel maps to EU AI Act, ISO 42001, FCA/SM&CR and NIST AI RMF. It aligns; it does not certify. We claim no certification and no compliance outcome — the paperwork it produces is what your auditor and regulator see.

Commercials

Priced on the estate, billed annually.

Pricing follows the size of the estate and the modules you run, quoted in writing before anything is signed. Populated by Sentinel at engagement close, or by guided self-onboarding where you would rather walk the estate yourself. As an illustration of the reporting: an estate of 41 systems carrying a ROGS of 74, with a portfolio return of +359.4% — illustrative demonstration figures, not a customer’s.

AutoDiscover runs continuously

Weekly scans keep the register honest after day one: new systems surface, shadow AI is flagged with its source and confidence, and the count the board sees is the count that was verified — not the count someone remembered to enter.

Before you commit

The five questions a procurement team asks first.

Does Citadel call any AI model vendor?

No. It governs AI and consumes none — the platform makes no calls to any model vendor, and the build fails if one is reintroduced. That shortens the sub-processor list and removes a class of security-review question.

Where does our data live, and who can reach it?

UK data residency, encrypted at rest and in transit, role-based access enforced at row level, multi-factor authentication on admin roles, and OIDC single sign-on via Azure AD, Okta, Auth0 or Google Workspace.

What happens to a number when a feed goes down?

It goes dashed rather than stale. A light is lit on a verified count, dark on a verified zero, and dashed when the feed cannot be reached. Simulated evaluations are labelled as simulated and cannot be approved.

Do we need a Sentinel engagement first?

No. Citadel is populated either by a Sentinel engagement or by guided self-onboarding. Sentinel is the faster route when nobody can currently name everything that is running.

Who makes the legal classifications?

The accountable person, never the platform. An EU AI Act classification is a legal determination and is never auto-filled. We claim no certification for any framework Citadel aligns to.

One record your board, your auditors and your regulator can share.

Thirty minutes with a founder to walk the six questions against your estate. NDA available before the detail.

Priced on estate size, billed annually · UK data residency · NDA available