Assurance that
doesn't expire.
A certificate records a moment. Testamark records the state of a control, with the date attached, and keeps recording it. One standard, two modules: Supply for the risk you do not own, Model for the risk that will not sit still.
Two domains of risk. One evidence layer.
Testamark applies a single assurance standard across both domains, so third party risk and AI risk are stated in the same language, at the same depth, with the same dates.
Third and fourth party assurance, and your own posture.
A continuous view of your own controls and of the suppliers you depend on, evidenced against the frameworks you map.
- Your own posture, continuously stated
- Third and fourth party dependencies
- Aligned to CPS 230, CPS 234 and SOC 2
Assurance for the AI your institution runs.
Register every model, agent and vision system, then hold each one against ISO 42001 and the EU AI Act with evidence that keeps up with change. Do this at a project level, or at an organisational level
- Model inventory and lineage
- Aligned to ISO 42001, EU AI Act, NIST AI RMF
- Behavioural evidence, not annual sign off
Double the share of the prior year. Verizon 2025 Data Breach Investigations Report.
ISO 27001, ISO 42001, CPS 230, CPS 234, EU AI Act, SOC 2, NIST AI RMF.
Declared, Evidenced, Verified, Observed. Match the depth to the consequence.
From a framework on paper to a state you can see live.
Map your frameworks
Bring in your control library and obligations. Testamark reconciles ownership, criticality and the evidence you already hold.
Set the depth
Choose Declared, Evidenced, Verified or Observed for each control and each relationship, according to consequence.
Connect the sources
Read state from the systems that already know it. Attestation becomes the exception rather than the method.
Produce the record
Board papers, regulator packs and audit evidence, dated and defensible, drawn from the same record everyone reads.
For the office of the CISO, CRO and CTO.
GRC records that a question was answered. Testamark records the state of the control and the date that state was observed, then keeps it current. It works alongside the GRC or IRM platform you already run rather than replacing it.
ISO/IEC 27001, ISO/IEC 42001, APRA CPS 230, CPS 234, the EU AI Act, SOC 2 and the NIST AI Risk Management Framework are supported out of the box. Bespoke control libraries are supported as well.
No. Testamark uses direct API integration and takes signals rather than raw data out of your environment, which keeps the sharing protocol narrow and controllable. Where you already run a secure agent and prefer to use it, we can ingest through it.
Under your data residency and privacy constraints, with SSO, role based access control and an immutable record. Implementation is led by our own assurance engineers.
See your own controls stated as a live record.
A working session with our assurance engineers, mapped to your obligations and your own estate.
