# XGRC® MAIA®

_Governed AI for GRC_

**The intelligence of governance, governed, audited, accountable.**

MAIA® is governed AI for GRC, embedded within XGRC® to help decision-makers interact with governance records, risks, policies, and compliance data. Faster insight. Better decisions. Full auditability, through controlled, audited AI integrations with a complete interaction audit trail.

## What it is

Governed AI for GRC is the controlled use of artificial intelligence to interrogate governance, risk, compliance, audit and policy data within defined permissions, security controls and audit trails.

## Overview

MAIA® is governed AI embedded within the XGRC® platform, using approved AI services through controlled, audited integrations, with permission alignment, data boundary controls, and full auditability of every AI interaction across risk, compliance, policy, and audit records.

## When organisations use it

Organisations typically adopt MAIA® when a board question about residual risk takes two days to answer because the risk manager has to compile data manually across systems, and generic AI tools may operate outside the governance, permission and audit controls required for regulated GRC decisions.

## What it is not

MAIA® is not a generic AI chatbot. It is governed AI designed for GRC contexts, operating within XGRC® Software permissions, records and auditability requirements, every interaction is logged, permissioned and auditable.

## Challenges it addresses

- **Answers take days, not minutes** — A board member asks about residual risk in a business unit. The risk manager spends two days compiling a response from multiple systems.
- **Governance records exist but are inaccessible** — Policies, risk registers, audit findings, and compliance records accumulated over years. Too dense, too fragmented for rapid insight generation.
- **AI tools that create new governance risk** — Generic AI tools may operate outside the governance, permission and audit controls required for regulated GRC decisions. Using them for governance decisions creates risk instead of reducing it.
- **Strategic decisions disconnected from operational risk data** — Leadership makes decisions without a live view of the risk and compliance posture. The data exists. Nobody can access it fast enough to matter.

## Modules

- **Governance Intelligence:** Natural Language Risk Queries, Policy & Procedure Q&A, Compliance Status Summaries, Regulatory Change Impact Analysis, ESG & SHERQ Insight Engine
- **DAVE: Data Integration:** API Data Connections, IoT Device Data, Microsoft Power BI, Microsoft Power Apps, Azure & PowerAutomate, XGRC Platform Data, Custom Data Requirements
- **LUCI: AI Interface:** DataViews & ML Dashboards, Predictive Maintenance AI, H&S Assistant Agent, Driver Fatigue Monitoring, Process Automation Bots, Voice Mode Interface
- **Governed AI Architecture:** Data Boundary Enforcement, AI Interaction Audit Trail, User Permission Alignment, Explainable AI Outputs, ChatGPT & Azure Integration

## Standards & frameworks

- ISO 42001 (targeted 2026)
- ISO 27001
- ISO 31000
- ISO 45001
- GDPR
- POPIA

## Frequently asked questions

### Does MAIA® send our data to ChatGPT or other AI providers?

MAIA® uses approved AI services through controlled, audited integrations, with permission alignment and data boundary controls, every AI interaction is logged in a complete audit trail.

### Can MAIA® answer questions across all our XGRC® data?

Yes. MAIA® can query risk registers, policies, audit findings and compliance records across every XGRC® solution your organisation uses.

### Is MAIA® certified to ISO/IEC 42001?

XGRC® is targeting ISO/IEC 42001 certification for September 2026. MAIA® is already built around governed AI principles, permission alignment, audit trails and explainable outputs, ahead of that certification.

### Who can access MAIA®'s answers?

MAIA® respects existing XGRC® user permissions. It only surfaces data a user is already authorised to see.

## Related solutions

- [Enterprise Risk Management](https://xgrcsoftware.com/erm)
- [Integrated Assurance](https://xgrcsoftware.com/integrated-assurance)
- [MSXCyber®](https://xgrcsoftware.com/msxcyber)

---

Source: https://xgrcsoftware.com/maia
