
AI governance and risk tools help you inventory AI systems, assess model risk, and evidence controls against frameworks like ISO 42001 and the NIST AI RMF. The free tools below give startups and small teams a way to start governing AI use long before the budget for a full platform exists.
You cannot govern AI you cannot see. Arize Phoenix is an open-source platform for tracing and evaluating AI applications and agents, so you can observe how they behave, annotate issues and measure quality over time. It is free to self-host on a laptop, in Docker or on Kubernetes.
Put policy controls around what goes into and comes out of your LLMs. Guardrails AI is an open-source (Apache 2.0) Python framework that adds input and output guards to AI applications, using pre-built validators from Guardrails Hub to detect and reduce specific types of risk and to extract structured, reliable data from language models.
Stop the trial-and-error approach to AI quality and security. Promptfoo is an open-source (MIT) CLI and library for evaluating and red-teaming LLM applications, letting you run automated tests against your prompts, models and agents before they reach production. Now part of OpenAI, the open-source project continues to be developed.
Before you ship a generative AI feature, find out how it can be misused. PyRIT (Python Risk Identification Tool) is Microsoft's open-source framework that helps security teams and engineers red-team generative AI systems and proactively identify risks, so issues are found and fixed before your customers find them.
The AI Governance Playbook is a free tool that builds a tailored AI governance framework for a small business adopting AI-powered apps, agentic systems or agentic workflows, with findings, recommendations and a 90-day plan aligned to the NIST AI RMF, ISO/IEC 42001 and the EU AI Act.
Open-source toolkit with 70+ metrics to detect and mitigate bias in ML models throughout the AI lifecycle
Kirin secures AI coding assistants from prompt injections, rogue behavior, and unsafe execution, so you can code faster and safer.
Every gap in AI compliance is a product you can't ship, a customer you can't serve, or a market you can't enter. VerifyWise provides the tools to automate compliance, manage risk, and build trust—from development to production.
Experience a frictionless and user-friendly interface designed for everyone. Simply drag and drop your files and get a deepfake media verification within seconds.
Scan & Detect Deepfake Videos Scan a suspicious video to find out if it's synthetically manipulated
AI governance and risk tools give you an inventory of the AI systems your business builds or buys, a way to assess each one for risk and impact, and a place to record the policies and controls that apply to it. They are the tooling layer beneath frameworks such as ISO/IEC 42001 and the NIST AI Risk Management Framework, which describe what to govern but leave you to decide how.
For a startup or SMB the starting point is rarely a platform. It is a register of AI tools in use (including the ones staff adopted on their own), an acceptable use policy, a risk assessment on the two or three systems that touch customer data, and evidence that someone reviews them. The free tools listed on this page cover exactly that: model cards, bias and robustness testing, policy generators, and lightweight inventories.
Need help with AI Governance & Risk?
IRM builds and certifies AI Management Systems for SaaS and AI-first companies.
AI Governance ServicesCheck your readiness first
Free, no signup, runs in your browser. Score your gaps and download a remediation roadmap.
Free AI Governance PlaybookAn AI governance tool helps an organization inventory its AI systems, assess their risks and impacts, assign ownership, and keep evidence of the policies and controls that apply to them. Enterprise platforms bundle all of this; the free tools on this page each cover one part, such as model documentation, bias testing, or policy generation.
If staff use generative AI with customer or company data, or the product ships an AI feature, yes at a basic level: an inventory, an acceptable use policy, and a risk assessment of the systems that matter. That can be done with free tools and a spreadsheet; a paid platform becomes worthwhile when customers start asking for ISO 42001 or NIST AI RMF evidence.
Most reference ISO/IEC 42001 (the certifiable AI management system standard), the NIST AI Risk Management Framework, and increasingly the EU AI Act. IRM's free ISO 42001 Gap Assessment covers all 38 Annex A controls if you want to see where you stand before choosing tooling.
Our diverse industry experience and expertise in AI, Cybersecurity & Information Risk Management, Data Governance, Privacy and Data Protection Regulatory Compliance is endorsed by leading educational and industry certifications for the quality, value and cost-effective products and services we deliver to our clients.









