AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance
Kertos
European compliance automation platform with an ISO 42001 and EU AI Act AI management system
What Kertos does
Kertos is a Munich-based compliance automation platform that helps European companies operationalize data protection, information security, and AI governance from a single system. Founded in November 2021 by Kilian Schmidt, Johannes Hussak, and Alexander Prams, Kertos positions itself as an all-in-one, audit-ready platform that combines AI-powered automation with certified expert support, and it claims to automate a large share of certification and documentation workflows. Its foundations are privacy management (GDPR RoPA, TOMs, DPIAs, DSAR automation, and shadow-IT discovery) and a certifiable information-security management system aligned with ISO 27001, TISAX, and C5. For AI governance specifically, Kertos offers an AI Management System (AIMS) targeting ISO/IEC 42001 and EU AI Act readiness, letting organizations inventory AI systems and address AI-specific risks within the same tooling they use for privacy and security, supported by KAIA, an AI compliance assistant. The platform emphasizes 100+ integrations, a Trust Center for displaying certifications, and optional certified DPO support. Kertos is best suited to European startups, scale-ups, and SMEs in sectors like fintech, healthtech, and SaaS that want to consolidate GDPR, ISO 27001, NIS2, DORA, and emerging AI Act obligations rather than run separate tools for each.
Key capabilities
- Privacy Management System for GDPR
- DSAR / deletion automation
- Automated RoPA, TOM and DPIA documentation
- Shadow-IT discovery
- Certifiable ISMS (ISO 27001, TISAX, C5)
- AI Management System (AIMS) for ISO 42001 and EU AI Act
- KAIA AI compliance assistant
- Trust Center and certified DPO support
Best for
European SMEs and scale-ups consolidating GDPR and ISO 27001 automation while adding ISO 42001 / EU AI Act AI governance
Limitations
AI governance is one module within a broader privacy and security automation suite rather than a dedicated, model-level AI platform; European-focused; a relatively young vendor with pricing available only on request.
Framework coverage
Kertos alternatives
Other tools solving a similar problem in Policy, Compliance & GRC.
Security compliance automation vendor with ISO 42001 and real-time AI agent governance
AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act
Compliance automation platform that extended into ISO 42001 and EU AI Act governance
Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates
Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine
AI Governance Tool Selection Kit
A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.
Free. No spam — unsubscribe anytime.