AIAI Governance StackFree kit

Kertos

European compliance automation platform with an ISO 42001 and EU AI Act AI management system

Visit website ↗

What Kertos does

Kertos is a Munich-based compliance automation platform that helps European companies operationalize data protection, information security, and AI governance from a single system. Founded in November 2021 by Kilian Schmidt, Johannes Hussak, and Alexander Prams, Kertos positions itself as an all-in-one, audit-ready platform that combines AI-powered automation with certified expert support, and it claims to automate a large share of certification and documentation workflows. Its foundations are privacy management (GDPR RoPA, TOMs, DPIAs, DSAR automation, and shadow-IT discovery) and a certifiable information-security management system aligned with ISO 27001, TISAX, and C5. For AI governance specifically, Kertos offers an AI Management System (AIMS) targeting ISO/IEC 42001 and EU AI Act readiness, letting organizations inventory AI systems and address AI-specific risks within the same tooling they use for privacy and security, supported by KAIA, an AI compliance assistant. The platform emphasizes 100+ integrations, a Trust Center for displaying certifications, and optional certified DPO support. Kertos is best suited to European startups, scale-ups, and SMEs in sectors like fintech, healthtech, and SaaS that want to consolidate GDPR, ISO 27001, NIS2, DORA, and emerging AI Act obligations rather than run separate tools for each.

Key capabilities

  • Privacy Management System for GDPR
  • DSAR / deletion automation
  • Automated RoPA, TOM and DPIA documentation
  • Shadow-IT discovery
  • Certifiable ISMS (ISO 27001, TISAX, C5)
  • AI Management System (AIMS) for ISO 42001 and EU AI Act
  • KAIA AI compliance assistant
  • Trust Center and certified DPO support

Best for

European SMEs and scale-ups consolidating GDPR and ISO 27001 automation while adding ISO 42001 / EU AI Act AI governance

Limitations

AI governance is one module within a broader privacy and security automation suite rather than a dedicated, model-level AI platform; European-focused; a relatively young vendor with pricing available only on request.

Framework coverage

FrameworkTypeSupported
EU AI ActRegulationYes
ISO/IEC 42001Certifiable standardYes
GDPRRegulationYes
SOC 2Control frameworkYes
DORARegulationYes
NIS2RegulationYes

Kertos alternatives

Other tools solving a similar problem in Policy, Compliance & GRC.

AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance

EU AI ActNIST AI RMFISO/IEC 42001

Security compliance automation vendor with ISO 42001 and real-time AI agent governance

ISO/IEC 42001EU AI ActSOC 2

AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act

ISO/IEC 42001EU AI ActNIST AI RMF

Compliance automation platform that extended into ISO 42001 and EU AI Act governance

ISO/IEC 42001EU AI ActNIST AI RMF

Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates

NIST AI RMFISO/IEC 42001EU AI Act

Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine

EU AI ActNIST AI RMFISO/IEC 42001
See the full Kertos alternatives guide →

AI Governance Tool Selection Kit

A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.

Free. No spam — unsubscribe anytime.