IQWorks AI Governance & Privacy Risk controls how AI touches personal data. AIQ, the middleware behind all IQWorks AI, can run offline, air-gapped or on your own LLM API; ChatIQ asks a person to confirm every change it makes; and ComplyIQ flags profiling in the RoPA and assesses AI-driven applications like any other system.
AI Governance Challenges
AI tools now read contracts, answer customer questions and summarize records, and many of them send personal data to a third-party model to do it. Privacy teams are asked to approve these tools without a clear view of where the data goes or what the AI is allowed to change.
The questions are familiar ones: what personal data is processed, on what grounds, by which system, and with which safeguards. AI adds new systems and new processing faster than a manual review keeps up with them.
Data sent to third-party models
Prompts and documents that contain personal data go to external LLMs by default.
AI acting unchecked
Assistants that can write to records make changes nobody approved.
Profiling not recorded
Processing that profiles individuals is missing from the record of processing.
AI tools outside review
New AI-driven applications go live without an assessment or an approval.
AI Governance with IQWorks
Your team today
Personal data sent to external models
With IQWorks
AI that runs where your data lives
AIQ can run offline and air-gapped models or connect to your own LLM API, so your data need not pass through third-party models.
Your team today
AI assistants change records unchecked
With IQWorks
A person confirms every change
ChatIQ asks for explicit confirmation before every write, logs every action and applies permission scoping automatically.
Your team today
Profiling hidden inside processing
With IQWorks
Profiling flagged in the RoPA
Each data activity in ComplyIQ records whether it involves profiling and analytics.
Your team today
AI tools approved over email
With IQWorks
AI applications assessed and approved
Register AI-driven applications in ComplyIQ with assessments, an approval workflow and version history, and request a custom assessment template for your AI use cases.
See it working on your own data
A live walkthrough against your regulations and your systems.
Request DemoProducts for AI Governance
All IQWorks AI runs through AIQ, which can use offline and air-gapped models or connect to your own LLM API.
AI Governance Workflow
Choose where AI runs
Run AIQ with offline or air-gapped models, or connect it to your own LLM API.
Choose where AI runs
Run AIQ with offline or air-gapped models, or connect it to your own LLM API.
Record the processing
Flag profiling and analytics on each data activity in the ComplyIQ RoPA.
Record the processing
Flag profiling and analytics on each data activity in the ComplyIQ RoPA.
Register and assess AI applications
Add AI-driven applications to the ComplyIQ register and run assessments through the approval workflow.
Register and assess AI applications
Add AI-driven applications to the ComplyIQ register and run assessments through the approval workflow.
Draft the documentation
Use ConsultIQ to draft DPIAs, legitimate interest assessments and risk registers for AI use cases.
Draft the documentation
Use ConsultIQ to draft DPIAs, legitimate interest assessments and risk registers for AI use cases.
Keep a person in charge
ChatIQ confirms before every write and logs every action.
Keep a person in charge
ChatIQ confirms before every write and logs every action.
Key Takeaways
- AI that can run offline, air-gapped or on your own LLM API
- A person confirms every change ChatIQ makes to records
- Profiling and analytics visible in the record of processing
- AI-driven applications assessed and approved like any other system
- DPIAs and legitimate interest assessments drafted with ConsultIQ
AI Governance FAQ
It does not have to. AIQ, the middleware behind all IQWorks AI, can run offline and air-gapped models or connect to your own LLM API, so your data need not pass through third-party models.
No. ChatIQ asks for explicit confirmation before every write, logs every action and applies permission scoping automatically.
Register it in the ComplyIQ applications register, run an assessment through the approval workflow, and generate a one-click DPIA from your RoPA. Custom assessment templates can be requested for AI use cases.
Each data activity in the ComplyIQ RoPA records whether it involves profiling and analytics, alongside its purpose, grounds and Data Principals.
AI Governance Resources
Regulations
Glossary
Data Protection Impact Assessment (DPIA)
A Data Protection Impact Assessment is a systematic process for evaluating the potential impact of a data processing activity on individuals' privacy, required under the GDPR for processing likely to result in high risk to data subjects.
Privacy by Design
Privacy by Design is a proactive approach that embeds data protection safeguards into the design and architecture of IT systems, business practices, and products from the earliest stages of development.
Data Governance
Data governance is the overall management of data availability, usability, integrity, and security within an organization, establishing policies, procedures, and accountability for data management.
