Governance

Governance at RALIA

We believe transparency builds trust. This page outlines how we govern RALIA, manage our policies, and maintain compliance with international standards.

January 2026

1. Our Governance Commitment

RisqBase operates RALIA under a comprehensive governance framework designed to ensure security, compliance, and operational excellence. Our governance principles guide every aspect of how we build, operate, and improve our platform.

Key Principles

Security by Design

Security is built into every feature from the start

Accessibility by Default

WCAG 2.1 AA compliance for all users

Compliance First

GDPR, EU AI Act, and ISO standards embedded in operations

Transparency

Open about how we operate and protect your data

Continuous Improvement

Regular reviews and updates based on best practices

2. Our Framework

Our Operational Excellence Framework (OEF) establishes mandatory quality gates, security standards, and operational procedures for all RALIA development and operations.

OPERATIONAL EXCELLENCE FRAMEWORK (OEF)

Quality Gates

  • CI/CD Pipeline
  • Code Review
  • Automated Testing

Security Standards

  • Accessibility (WCAG 2.1 AA)
  • GDPR Compliance
  • AI Security

Policy Framework

14
Active Policies
2
Procedures
Quarterly
Reviews
Full
Version Control

Compliance Mapping

ISO 27001ISO 42001SOC 2GDPR

3. Our Policies

We maintain comprehensive policies covering security, privacy, AI governance, and platform use. The following policies are publicly available:

4. Compliance Framework

RALIA is designed to meet the requirements of major international standards and regulations.

4.1 Security Certifications & Standards

FrameworkDescription
ISO 27001 ReadyEnterprise-grade security and data protection
ISO 42001 ReadyAI management systems and responsible AI governance
SOC 2 Type II ReadyService organisation customer data management

4.2 Certification Roadmap

StandardTargetDescription
ISO 270012026Information Security Management System
ISO 420012026AI Management System
SOC 2 Type II2027Trust Services Criteria

4.3 Compliance Mapping

Our policies are mapped to control frameworks:

  • ISO 27001:2022 - All 10 control domains covered
  • ISO 42001:2023 - AI management system requirements
  • SOC 2 - Trust Services Criteria (CC1-CC9, A1, C1, PI1)
  • GDPR - Articles 5-35 mapped to policies
  • EU AI Act - Articles 6, 14, 26, 50 addressed

5. Transparency & Accountability

We are committed to operating with transparency and accountability. Our governance framework ensures that:

  • What we say matches what we do - Our public policies reflect our actual practices
  • We keep you informed - When our policies change, our public pages are updated
  • We welcome questions - Contact us anytime about our governance practices

We believe trust is earned through consistent, transparent action.

6. Get in Touch

For questions about our governance framework, policies, or compliance:

Enterprise Customers

Enterprise customers may request:

  • • Security questionnaire responses
  • • Compliance documentation
  • • Policy summaries

Contact your account manager or email legal@risqbase.com

Enterprise Governance Documentation

Request detailed governance documentation, including our complete policy register and compliance certifications.

Contact Sales

Governance at RALIA

Last updated: January 2026

RisqBase d.o.o. | Zagreb, Croatia