RAIC Platform Support & Documentation
The Rhindon AI Risk & Integrity Cloud (RAIC) is a comprehensive governance platform for managing AI systems, use cases, controls, and compliance across your organization. Browse the documentation below to get started.
Get Started
(1/1)Guides
(2/2)Submit a Use Case (Portal)
For business owners and technical leads submitting a new AI use case via the public intake portal. Walks through the five on-screen sections and includes a downloadable branded DOCX guide.
Assessment Wizard
Walkthrough of the RAIC AI risk assessment wizard: scoping, control mapping, evidence capture, and reviewer sign-off.
Courses
(1/1)AI Risk Management Course
External video course covering NIST AI RMF, ISO/IEC 42001, and the EU AI Act — tiered AI risk assessment, bias & fairness, vendor and LLM supply-chain exposure, and the four artifacts of an AI risk program (tiered inventory, bias-test plan, POA&M, board summary). Instructed by David Mosher, MS (Cybersecurity).
What you'll learn
- Design and defend a tiered AI risk assessment for a real system using NIST AI RMF, ISO/IEC 42001, and the EU AI Act as complementary references.
- Distinguish AI-specific risks (bias, hallucination, prompt injection, model drift, supply-chain opacity) from traditional cyber risks and apply the right control set to each.
- Evaluate vendor and LLM supply-chain exposures using structured criteria (data residency, model versioning, sub-processor visibility, right-to-audit).
- Produce the four artifacts a functioning AI risk program requires: tiered inventory, bias-test plan, POA&M, and board-level summary.
- Operate an AI Management System aligned to ISO/IEC 42001 that keeps pace with regulatory change as the AI portfolio grows.
Course syllabus
- Module 1 — Foundations of AI Risk
- Module 2 — AI Governance and Regulation
- Module 3 — Risk Identification and Tiering
- Module 4 — Bias, Fairness and Explainability
- Module 5 — Security, Adversarial ML, and Generative AI
- Module 6 — Human Oversight and Accountability
- Module 7 — Third-Party and LLM Supply-Chain Risk
- Module 8 — Operationalizing an AI Management System
- Module 9 — Capstone: AI System Risk Assessment Lab
Videos
(3/3)Partner / MSP Videos
Walkthroughs for managed service providers — the MSP Partner Portal demo and the end-to-end partner onboarding video.
Client Onboarding Videos
Walkthroughs for onboarding a client organization — the general RAIC tour plus Starter and Professional tier onboarding.
How-To Videos
Task tutorials — how to complete a specific RAIC form or workflow, field by field, including use case intake and approvals.
Modules
(23/23)System Requirements
ISO 42001 A.4.5 AI System Requirements Register: per-system functional, intended-use, and regulatory requirements with MoSCoW prioritization, sign-off, and versioning.
AI Use Cases
Learn how to register, submit, and manage AI use cases through the governance workflow.
AI Systems
Understand how to register AI systems, manage lifecycle stages, and track approvals.
Controls
Explore the controls framework including the 8-step wizard and 7-stage approval workflow.
Risk Register
The organization-wide risk register with dual inherent and residual scoring, an interactive 5x5 likelihood-by-impact heatmap, treatment plans, owners, review cadence, and linkage back to AI Systems, Use Cases, and Controls.
AI Discovery & Catalog
How RAIC finds AI in use across your estate: browser-extension telemetry, Microsoft Graph scans, the curated AI catalog of web, model, and API entries, unknown-signal triage with confidence-based auto-promotion, and promotion into the AI Systems register.
AI Maturity Index
The AI Maturity dashboard and its scoring engine: Governance Maturity Index (GMI), Cyber Governance Maturity Index (CGMI), and Total Governance Posture (TGP), what feeds each sub-metric, the daily snapshot job, and how to read the trend charts.
Cyber Hygiene Program
Configure and monitor the RAIC cyber hygiene program: baseline checks, review cadence, the remediation workflow, and how hygiene results roll into reporting.
Operation Monitoring
ISO 42001 A.6.2.6 operation monitoring: runtime metrics ingestion, thresholds and alerting, incident escalation paths, and the audit trail for monitored AI systems.
Phishing Simulations
Run phishing simulation campaigns from RAIC: pick templates, target audiences, track click and report rates, and drive awareness training follow-up for users who fall for a lure.
Dataset Registry
ISO 42001 Annex A.7 Dataset Registry: sensitivity tiers, PII flags, provenance, quality criteria, and AI System linkage.
Training & Competence
ISO 42001 Clause 7.2 / Annex A.4.6 Training & Competence: course catalog, per-user assignments, completion evidence, and validity expiry tracking.
Data Lineage
ISO 42001 Annex A.7.6 Data Lineage: directed edges, interactive graph view, and cycle detection across datasets, AI systems, and use cases.
AI Data Governance
The AI Data Governance control plane inspects content flowing into AI tools, classifies sensitive data with patterns and Named Entity Recognition, and applies allow, mask, or block policy inline or after the fact.
Autonomous Governance Agents
Governance agents that watch continuously and bring you decisions, not alerts: Shadow AI triage, evidence freshness, supplier document intelligence, and compliance drift — each with configurable autonomy and a human-reviewed proposal inbox.
Transparency Register
ISO 42001 Annex A.10.4 Customer Transparency Register: customer, regulator, and public disclosures with supersede and withdraw actions plus expiry watch.
Anonymous Concerns
ISO 42001 A.3.3 anonymous concerns channel: hCaptcha-protected public form, per-IP rate limiting, rotatable submission token, OrgAdmin triage queue, and full audit trail.
Impact Assessments
ISO 42001 A.5.5 AI System Impact Assessments: societal, environmental, economic, and human-rights impact register with a staged workflow and branded DOCX exports.
Documented Info (7.5)
ISO 42001 Clause 7.5 Documented Information INDEX register: 11 doc types, 5-state lifecycle, 15 linked-module backfill targets, branded CSV + DOCX exports.
Resources (7.1)
ISO 42001 Clause 7.1 AIMS Resources & Infrastructure register: people, infra, tooling, data, budget, and external services with adequacy review, scheduling, and AI-Systems / Suppliers backfill.
Suppliers (A.10.3)
ISO 42001 A.10.3 Suppliers & Third-Party Risk register: sub-processors (GDPR Art. 28), DPA evidence, AI System linkage, and Mark-Reviewed scheduling.
Concepts
(1/1)Reference
(3/3)ISO 42001 Statements
Reusable ISO/IEC 42001 platform control statements shipped with RAIC and how to tailor them for your Statement of Applicability.
CIS Controls Statements
Reusable CIS Controls v8 platform statements shipped with RAIC and how to tailor them for cybersecurity assessments.
User Roles
Discover the role-based access control model and what each role can do in RAIC.
Admin
(4/4)MSP Partner Portal
The MSP Partner Portal: the multi-tenant client launcher, demo sandboxes for prospects, quarterly business review reporting, Shadow AI discovery engagements, and the partner-level role model.
White-Label Add-On
Partner-facing guide to the $99/mo White-Label add-on: branded Partner Portal shell, transactional emails, DOCX/XLSX/CSV exports, per-client overrides, Stripe checkout, renewal behavior, and audit trail.
MSP Shadow AI Discovery
How partners run Shadow AI discovery engagements for prospects and clients: scoping the engagement, rolling out the browser extension, working the findings workspace, and producing the client-ready discovery report.
Partner Template Library
Install canonical RAIC document templates — discovery packages, onboarding guides, report templates — straight into your firm's Partner Docs library, then version and rebrand them for client delivery.
Security and Compliance
(7/7)External Auditor
Isolated workspace for external ISO 42001 auditors: engagement scope, checklist, evidence review, findings capture, branded DOCX report, and the promote-to-nonconformity workflow.
EU AI Act Workbench
The EU AI Act compliance workbench: declare your actor role (provider, deployer, importer, distributor), classify systems against the prohibited / high-risk / limited / minimal tiers, work the Annex III triggers, and track each obligation to evidence.
NIST CSF 2.0
NIST Cybersecurity Framework 2.0 coverage in RAIC: the six functions (Govern, Identify, Protect, Detect, Respond, Recover), category and subcategory scoring, crosswalks to CIS and ISO controls, and gap reporting.
Cybersecurity Mode
Enable RAIC Cybersecurity Mode: NIST CSF 2.0 and CIS Controls v8 workflows, the unified risk register, and cyber reporting overlays alongside AI governance.
HIPAA Module
The HIPAA module available on Professional and Enterprise tiers: administrative, physical, and technical Security Rule safeguards, Business Associate Agreement tracking, PHI data mapping against the Dataset Registry, and per-safeguard evidence.
Hedge Fund / FINRA WSP
The financial-services overlay for hedge funds and RIAs: FINRA Written Supervisory Procedures mapped to AI usage, SEC marketing-rule checks, supervisory review workflows, and the additional control set the overlay activates.
SOC 2 Type 2 Evidence
Pro/Enterprise module tracking the AICPA Trust Services Criteria across your SOC 2 Type 2 audit period. 61-row TSC catalog, per-control evidence uploads, one-click backfill from existing RAIC artifacts, branded auditor evidence pack ZIP, and CSV + DOCX exports.
API & Integrations
(7/7)REST API Reference
Public reference for the raic-api/v1 surface: base URL, authentication, scopes, rate limits, webhooks, error envelope, and a downloadable branded DOCX.
API Tokens
How RAIC API tokens work: org-scoped rai_ keys minted by Org Admins versus SuperAdmin-only platform tokens, scope selection, rate-limit behavior, one-time secret display, rotation, revocation, and the audit trail every token action writes.
MCP Server
Connect AI assistants to RAIC over the Model Context Protocol: the OAuth 2.1 authorization flow, client registration, the read-only tool surface exposed to models, scope enforcement, and how every MCP call is audit-logged.
Browser Extension
How the Shadow AI browser extension detects AI tool usage, what it captures, and its privacy posture.
Extension via Intune
Force-install the RAIC Shadow AI extension via Microsoft Intune or Chrome ADMX MDM: hosted CRX, ADMX policy configuration, and staged rollout steps.
Integrations Marketplace
Browse and configure RAIC marketplace integrations: available connectors, install steps, permission scopes, and troubleshooting.
ConnectWise PSA
Connect RAIC to ConnectWise PSA: credential setup, the outbound risk-event push, ticket and board mapping, retry behavior, and how delivery failures surface.
Release Notes
(1/1)Submit a Request
Need help? Submit a support request directly to the Rhindon Cyber support team.
Need Additional Help?
Contact our support team at [email protected] for assistance with platform configuration, onboarding, or technical issues.
