AI speed. Governance discipline. Both.
The gap between AI capability and governance accountability. Closed. Azure-hosted and infrastructure-as-code governed, every decision is evidence-bound, human-reviewable, cryptographically signed, and independently verifiable.
Not an AI assistant. Not a document generator. Not a GRC checklist. A decision governance control layer — infrastructure for the decision process itself. Controlled confidence for organisations that need to move faster without giving up accountability.
The same deterministic path for every decision — both builds. Reproducible, replayable, and auditable.
The gap between AI capability and governance accountability. This is where DIIaC lives.
| Capability | Native LLM Tools | GRC Platforms | AI Governance Overlays | DIIaC™ IT Enterprise | DIIaC™ Pharma |
|---|---|---|---|---|---|
| Natural language intent capture | ✓ | ✗ | ✗ | ✓ | ✓ |
| Deterministic governed compilation | ✗ | ✗ | ✗ | ✓ | ✓ |
| Evidence binding and quality gates | ✗ | Partial | ✗ | ✓ | ✓ + GxP classes |
| Policy-pack enforcement | ✗ | ✓ | ✓ | ✓ EU AI Act + UK AI | ✓ + GMP/GCP/GVP |
| Cryptographically signed outputs | ✗ | ✗ | ✗ | ✓ | ✓ |
| Offline independent verification | ✗ | ✗ | ✗ | ✓ | ✓ |
| Multi-role accountability state | ✗ | Partial | ✗ | ✓ | ✓ pharma roles |
| Institutional Bayesian learning | ✗ | ✗ | ✗ | ✓ | ✓ |
| Board-ready report with evidence trace | Partial | ✗ | ✗ | ✓ | ✓ |
| AI output assurance / verification | ✗ | ✗ | Partial | ✓ | ✓ |
| Research advisory intelligence (PRIA) | ✗ | ✗ | ✗ | ✗ | ✓ |
| GxP / Annex 11+15 / ALCOA+ controls | ✗ | ✗ | ✗ | ✗ | ✓ |
| Pharmacovigilance governance | ✗ | ✗ | ✗ | ✗ | ✓ |
| UK Public Sector bid intelligence | ✗ | ✗ | ✗ | ✓ | ✗ |
| GxP validation baseline | ✗ | ✗ | ✗ | ✗ | ✓ |
Comparison based on published vendor documentation, March–May 2026. ChatGPT Enterprise / Microsoft Copilot: strong for general-purpose assistance, drafting and knowledge work. Not designed to emit deterministic signed decision artefacts or enforce policy-pack controls. GRC platforms (ServiceNow, IBM OpenPages, MetricStream): strong for controls management, risk registers, and audit workflows. Not decision-compilation engines. AI Governance Overlays (IBM watsonx.governance, Credo AI, OneTrust, ValidMind): strong for AI policy management and model risk monitoring. Sit around decisions, not inside the decision workflow.
From intent to signed board report. Governed end to end. The accountability infrastructure your technology strategy decisions have always needed — and never had.
19 controls enforced across every IT Enterprise compile. Hard gates — cannot be softened or bypassed.
Selected automatically based on decision intent. Procurement always retains the strictest gates.
| Model | Decision Type | Rigour |
|---|---|---|
| Procurement evaluation | Vendor selection, supplier shortlisting | Strictest |
| Vendor assessment | Technology comparison, platform review | Proportionate |
| Risk review | Risk assessment, threat analysis | Proportionate |
| Strategy assessment | Strategic planning, roadmaps | Proportionate |
| General | Default fallback | Baseline |
Governed decision assurance for regulated pharmaceutical organisations. Deterministic, evidence-bound, signed governance for research discovery, operational compliance, and supplier qualification — built for the regulated environment.
Policy rigour is not configurable at runtime. Controls are enforced as never-softened hard gates.
| Framework | Scope |
|---|---|
| EU AI Act (2024/1689) | Deployer responsibilities, human oversight (Art. 14), transparency |
| EU GMP Annex 11 | Computerised systems validation |
| EU GMP Annex 15 | Qualification and validation |
| MHRA GxP Data Integrity | ALCOA+ controls |
| ICH E6(R3) GCP | Good clinical practice for system selection |
| EMA GVP | Pharmacovigilance governance |
| EU CTR 536/2014 | Clinical trial governance |
| GDPR & UK GDPR | Clinical trial data protection |
| NIS2 Directive | Cybersecurity in regulated environments |
| UK AI Governance | UK-specific AI assurance baseline |
| Model | Decision Type | Notable |
|---|---|---|
| Pharma supplier qualification | Regulated supplier & system vendor evaluation | GxP gates required |
| Procurement evaluation | Explicit RFP & vendor selection | Strictest gates |
| Research evidence review | PRIA-backed discovery decisions | Advisory only |
| Risk review | Compliance, safety-system, change-risk | Proportionate |
| Strategy assessment | Portfolio, AI enablement, TOM | Proportionate |
| General | Default fallback | Baseline |
The builds have validated live baselines and signed verification evidence. DIIaC is Azure-hosted using infrastructure-as-code deployment patterns for repeatable environments, controlled release evidence, reduced configuration drift, and audit-ready operations. E20 AI Output Assurance is live in the production-grade IT build.
Both builds — IT Enterprise and Pharma & Medical Research — are being developed and validated. This site provides information about the platform, its architecture, and its governance capabilities. Access details will be published here when available.