Rhindon Cyber logo
    Support & Documentation
    Contact Support

    RAIC Platform Support & Documentation

    The Rhindon AI Risk & Integrity Cloud (RAIC) is a comprehensive governance platform for managing AI systems, use cases, controls, and compliance across your organization. Browse the documentation below to get started.

    Get Started

    (1/1)

    Guides

    (2/2)

    Courses

    (1/1)

    AI Risk Management Course

    External video course covering NIST AI RMF, ISO/IEC 42001, and the EU AI Act — tiered AI risk assessment, bias & fairness, vendor and LLM supply-chain exposure, and the four artifacts of an AI risk program (tiered inventory, bias-test plan, POA&M, board summary). Instructed by David Mosher, MS (Cybersecurity).

    What you'll learn
    • Design and defend a tiered AI risk assessment for a real system using NIST AI RMF, ISO/IEC 42001, and the EU AI Act as complementary references.
    • Distinguish AI-specific risks (bias, hallucination, prompt injection, model drift, supply-chain opacity) from traditional cyber risks and apply the right control set to each.
    • Evaluate vendor and LLM supply-chain exposures using structured criteria (data residency, model versioning, sub-processor visibility, right-to-audit).
    • Produce the four artifacts a functioning AI risk program requires: tiered inventory, bias-test plan, POA&M, and board-level summary.
    • Operate an AI Management System aligned to ISO/IEC 42001 that keeps pace with regulatory change as the AI portfolio grows.
    Course syllabus
    • Module 1 — Foundations of AI Risk
    • Module 2 — AI Governance and Regulation
    • Module 3 — Risk Identification and Tiering
    • Module 4 — Bias, Fairness and Explainability
    • Module 5 — Security, Adversarial ML, and Generative AI
    • Module 6 — Human Oversight and Accountability
    • Module 7 — Third-Party and LLM Supply-Chain Risk
    • Module 8 — Operationalizing an AI Management System
    • Module 9 — Capstone: AI System Risk Assessment Lab

    Videos

    (3/3)

    Modules

    (23/23)

    System Requirements

    ISO 42001 A.4.5 AI System Requirements Register: per-system functional, intended-use, and regulatory requirements with MoSCoW prioritization, sign-off, and versioning.

    AI Use Cases

    Learn how to register, submit, and manage AI use cases through the governance workflow.

    AI Systems

    Understand how to register AI systems, manage lifecycle stages, and track approvals.

    Controls

    Explore the controls framework including the 8-step wizard and 7-stage approval workflow.

    Risk Register

    The organization-wide risk register with dual inherent and residual scoring, an interactive 5x5 likelihood-by-impact heatmap, treatment plans, owners, review cadence, and linkage back to AI Systems, Use Cases, and Controls.

    AI Discovery & Catalog

    How RAIC finds AI in use across your estate: browser-extension telemetry, Microsoft Graph scans, the curated AI catalog of web, model, and API entries, unknown-signal triage with confidence-based auto-promotion, and promotion into the AI Systems register.

    AI Maturity Index

    The AI Maturity dashboard and its scoring engine: Governance Maturity Index (GMI), Cyber Governance Maturity Index (CGMI), and Total Governance Posture (TGP), what feeds each sub-metric, the daily snapshot job, and how to read the trend charts.

    Cyber Hygiene Program

    Configure and monitor the RAIC cyber hygiene program: baseline checks, review cadence, the remediation workflow, and how hygiene results roll into reporting.

    Operation Monitoring

    ISO 42001 A.6.2.6 operation monitoring: runtime metrics ingestion, thresholds and alerting, incident escalation paths, and the audit trail for monitored AI systems.

    Phishing Simulations

    Run phishing simulation campaigns from RAIC: pick templates, target audiences, track click and report rates, and drive awareness training follow-up for users who fall for a lure.

    Dataset Registry

    ISO 42001 Annex A.7 Dataset Registry: sensitivity tiers, PII flags, provenance, quality criteria, and AI System linkage.

    Training & Competence

    ISO 42001 Clause 7.2 / Annex A.4.6 Training & Competence: course catalog, per-user assignments, completion evidence, and validity expiry tracking.

    Data Lineage

    ISO 42001 Annex A.7.6 Data Lineage: directed edges, interactive graph view, and cycle detection across datasets, AI systems, and use cases.

    AI Data Governance

    The AI Data Governance control plane inspects content flowing into AI tools, classifies sensitive data with patterns and Named Entity Recognition, and applies allow, mask, or block policy inline or after the fact.

    Autonomous Governance Agents

    Governance agents that watch continuously and bring you decisions, not alerts: Shadow AI triage, evidence freshness, supplier document intelligence, and compliance drift — each with configurable autonomy and a human-reviewed proposal inbox.

    Transparency Register

    ISO 42001 Annex A.10.4 Customer Transparency Register: customer, regulator, and public disclosures with supersede and withdraw actions plus expiry watch.

    Anonymous Concerns

    ISO 42001 A.3.3 anonymous concerns channel: hCaptcha-protected public form, per-IP rate limiting, rotatable submission token, OrgAdmin triage queue, and full audit trail.

    Impact Assessments

    ISO 42001 A.5.5 AI System Impact Assessments: societal, environmental, economic, and human-rights impact register with a staged workflow and branded DOCX exports.

    Documented Info (7.5)

    ISO 42001 Clause 7.5 Documented Information INDEX register: 11 doc types, 5-state lifecycle, 15 linked-module backfill targets, branded CSV + DOCX exports.

    Resources (7.1)

    ISO 42001 Clause 7.1 AIMS Resources & Infrastructure register: people, infra, tooling, data, budget, and external services with adequacy review, scheduling, and AI-Systems / Suppliers backfill.

    Suppliers (A.10.3)

    ISO 42001 A.10.3 Suppliers & Third-Party Risk register: sub-processors (GDPR Art. 28), DPA evidence, AI System linkage, and Mark-Reviewed scheduling.

    Concepts

    (1/1)

    Reference

    (3/3)

    Admin

    (4/4)

    Security and Compliance

    (7/7)

    External Auditor

    Isolated workspace for external ISO 42001 auditors: engagement scope, checklist, evidence review, findings capture, branded DOCX report, and the promote-to-nonconformity workflow.

    EU AI Act Workbench

    The EU AI Act compliance workbench: declare your actor role (provider, deployer, importer, distributor), classify systems against the prohibited / high-risk / limited / minimal tiers, work the Annex III triggers, and track each obligation to evidence.

    NIST CSF 2.0

    NIST Cybersecurity Framework 2.0 coverage in RAIC: the six functions (Govern, Identify, Protect, Detect, Respond, Recover), category and subcategory scoring, crosswalks to CIS and ISO controls, and gap reporting.

    Cybersecurity Mode

    Enable RAIC Cybersecurity Mode: NIST CSF 2.0 and CIS Controls v8 workflows, the unified risk register, and cyber reporting overlays alongside AI governance.

    HIPAA Module

    The HIPAA module available on Professional and Enterprise tiers: administrative, physical, and technical Security Rule safeguards, Business Associate Agreement tracking, PHI data mapping against the Dataset Registry, and per-safeguard evidence.

    Hedge Fund / FINRA WSP

    The financial-services overlay for hedge funds and RIAs: FINRA Written Supervisory Procedures mapped to AI usage, SEC marketing-rule checks, supervisory review workflows, and the additional control set the overlay activates.

    SOC 2 Type 2 Evidence

    Pro/Enterprise module tracking the AICPA Trust Services Criteria across your SOC 2 Type 2 audit period. 61-row TSC catalog, per-control evidence uploads, one-click backfill from existing RAIC artifacts, branded auditor evidence pack ZIP, and CSV + DOCX exports.

    API & Integrations

    (7/7)

    Release Notes

    (1/1)

    Submit a Request

    Need help? Submit a support request directly to the Rhindon Cyber support team.

    Need Additional Help?

    Contact our support team at [email protected] for assistance with platform configuration, onboarding, or technical issues.