Produce a CISO-ready governance readiness summary — overall posture, per-framework scores, gate status, unattested call exposure, and a prioritised action list. Use when the user asks for a readiness report, compliance status, board summary, or audit preparation overview.
Run the compliance copilot loop — observe posture, identify gaps, dry-run proposed evidence records where possible, present for human approval, then write approved records. Use when the user asks to close compliance gaps, improve their EU AI Act score, or fix failing governance gates.
Configure governance gates — thresholds, modes, and framework coverage. Use when the user asks how to set up gates, whether deployments should be blocked, what threshold to use, or wants to review their current gate configuration.
Run the quarterly evidence collection workflow — find the stalest controls by record type, collect completion details for each, dry-run to confirm controls earned, then write approved records. Use at the end of each quarter when a GRC manager has completed governance activities (risk assessments, model evaluations…
Run the Art. 9 intake workflow — find every AI system without an airiskassessment record, gather the required fields, and register each one. Use when the user asks to register systems, fix Art. 9 gaps, or prepare for the EU AI Act deadline.
AI governance evidence for EU AI Act, ISO 42001, SOC 2, and NIST AI RMF. Runs locally from the @mima-ai/governance-mcp npm package. Needs 2 environment variables to run.