Your team is already using AI. Find out if you’re managing it properly.
A 15-minute ISO/IEC 42001 readiness check, in plain language. Get a score, a red-amber-green report and a prioritised list of what to fix first. No consultants, no calls.
No card needed. Full Pro access for 14 days.
Start with AI, add security when you’re ready
Each assessment is a short, guided questionnaire written for business owners, not auditors. Most people start with ISO/IEC 42001, because AI is already in the building.
ISO/IEC 42001 readiness
Check whether your business uses and builds AI tools in a responsible, well-managed way.
36 questions · 9 areas
About ISO 42001Start nowISO/IEC 27001 readiness
See how close you are to the international standard for keeping business information safe.
33 questions · 8 areas
About ISO 27001Start nowBuilt for businesses in the gap
Regulation is arriving faster than most businesses can build governance. KhutsoGRC is for the ones stuck in between.
You're using AI in a regulated business
Fintech, lending, insurance or anything with automated decisions. Investors and regulators are starting to ask how you govern it, and “we'll get to it” is no longer an answer.
You build AI for other people
Agencies and SaaS teams shipping agents, chatbots and automations. Your clients' risk questionnaires are coming, and they'll ask what you have in writing.
A client or tender is asking
Supplying a bank, a multinational or government means answering security and AI questions before you sign. Find out what you'd score before someone else scores you.
You're too small for enterprise GRC
Enterprise platforms start in the hundreds of thousands of rand a year and are sold through demos and quotes. You need to know where you stand first.
1. Answer yes, no or partly
One topic per screen. Your progress saves as you go, so you can stop any time.
2. See your score
A score for each area and overall, with a clear red, amber or green status.
3. Fix what matters first
Download a PDF with every gap, why it matters and a realistic first step to fix it.
Why Khutso
Khutso is a Sepedi word for peace. Not the peace of ignoring risk, but the calm that comes from facing it clearly and knowing exactly where you stand.
Most compliance tools sell fear: fines, failed audits, damaged reputations. We're after the opposite feeling. The quiet confidence of a business that has looked honestly at its gaps, understood them, and knows what to fix next. Not the absence of risk, but the clarity to manage it.
Where this fits, honestly
KhutsoGRC is the step before you spend money. You find out where you stand, fix the basics yourself using the report, and only bring in a consultant or a certification body once you've outgrown a self-assessment.
- It isn't a certification. Only an accredited body can certify you.
- It isn't legal advice, and it doesn't make you compliant on its own.
- It isn't an evidence-collection platform. That comes later, if you decide to certify.
What it does is answer “are we ready?” in about 15 minutes, for the price of a couple of hours of consulting.