Cranium
AI risk management and governance platform
Overview
Cranium provides AI governance, risk management and compliance tooling — model registries, lineage tracking, regulator-ready documentation for the EU AI Act and US frameworks. Spun out of KPMG. Enterprise focus, large-regulated-industry adoption.
Use cases
What you can produce with Cranium
- Automatically discover AI and ML systems running across your environment and build a living inventory of models, datasets and pipelines.
- Generate an AI card — a bill-of-materials for a given AI system — that can be shared with customers, third parties or regulators as trust evidence.
- Map your AI systems against EU AI Act obligations and produce regulator-ready documentation for high-risk classifications.
- Track model lineage so you can show which data, base models and fine-tunes produced the system now in production.
- Assess AI supply-chain exposure by identifying third-party and vendor models embedded in your applications.
- Monitor AI systems for adversarial-threat exposure and get a prioritised view of which models carry the most risk.
- Give your compliance team a dashboard mapping AI usage to frameworks like the NIST AI RMF for board and audit reporting.
ASEAN Perspective
Cranium in Southeast Asia
ASEAN-region availability and pricing notes coming soon. Drop the editorial team a note via /contact/ if you can supply local context (Singapore/Malaysia/Indonesia/Thailand/Vietnam).
Cranium is an AI security and governance platform (spun out of KPMG's incubator) that helps enterprises inventory their AI/ML systems, assess risk, monitor for threats and demonstrate compliance with frameworks like the NIST AI RMF and the EU AI Act. As AI governance becomes a board-level concern, its focus on visibility into the AI supply chain and 'AI cards' for trust is timely and well-positioned.
It is firmly an enterprise product — pricing, deployment and value all assume a sizable AI footprint and a dedicated risk/security function. The AI-security category is young and fast-shifting, so buyers should validate maturity against specific needs. Limited public technical detail and no self-serve. For large ASEAN enterprises facing AI regulation it is relevant; SMBs will find it overkill.
What people say
Cranium is one of the more established names in the young AI security and governance category. Spun out of KPMG's startup studio in April 2023 and backed by a USD 25 million Series A, it sells enterprises a platform for discovering AI systems in use, building AI bills-of-materials ("AI cards"), tracking model lineage, and generating compliance documentation mapped to the EU AI Act, NIST AI RMF and similar frameworks. Through 2025 it collected notable analyst attention — inclusion in multiple Gartner Hype Cycle reports, a TAG Infosphere top-five AI security vendor nod, and spots on Fortune/Evolution Equity's Cyber 60-style list and CRN's Stellar Startups.
Grassroots review data is thin, which is itself worth knowing. Cranium's Gartner Peer Insights listing shows a strong 4.9/5, but across only around 20 ratings — a small sample typical of early enterprise security tooling. There is essentially no G2, Capterra or Reddit footprint of practitioner reviews, so most public signal comes from analysts, press and the vendor itself rather than from a broad user base.
What the available feedback and analyst commentary consistently highlight: the AI card concept is a practical answer to the "we don't actually know what AI we're running" problem, the compliance-mapping and regulator-ready documentation resonate with governance teams staring down the EU AI Act, and the KPMG pedigree gives risk-averse buyers comfort. The trade-offs are the usual enterprise ones — opaque pricing, a sales-led motion, and a platform whose value assumes you have a meaningful AI estate to govern. Smaller companies with two or three vendor LLM integrations will find it heavy.
Cranium fits large regulated enterprises — banks, insurers, healthcare, critical infrastructure — that need defensible AI inventories and audit-ready governance evidence. Startups or teams just wanting prompt-injection testing or basic model monitoring should look at lighter, more specialised tooling first.
Summary of public user & expert reviews, compiled by RECATOOLS.
About this listing
This entry was compiled from publicly available data including Cranium's official website, press releases, documentation, and reputable third-party publications. RECATOOLS is not affiliated with Cranium unless explicitly stated.
Third-party AI tools update their pricing, features, availability, and policies frequently. Information here may be outdated by the time you read this — we make reasonable efforts to keep listings current, but cannot guarantee absolute accuracy.
For the latest details, please refer to Cranium directly →
Spotted something out of date? Suggest an update →
Cranium in the news
ASEAN Tech
MAS's SAFR Framework Puts the Safeguard Where the Money Moves — At the Point an AI Agent A...
Finance
The FCA's Mills Review: No New AI Rulebook for Finance — but Targeted New Powers, Includin...
Privacy & Data
Three US State Privacy Changes Take Effect on 1 July 2026 — and Connecticut Reaches Into A...
More in Security & Safety