For information only. Not advice, and not to be relied on. What that means, in full
Frameworks

What the evidence has to satisfy

Each control is mapped to the GRI dimension whose evidence would satisfy it. That mapping is the working link between an abstract obligation and a document someone has to produce.

§164.312(b)audit controlsHIPAA Security RuleA clauseof a real instrumentYou assert itwith a reason, stored, never verified hereWe observe a signalchain verifies · triggers set · system on inventorynever mergedRecorded as your claimin the coverage tableRecomputed every readnever written to coverageCoveredPartly coveredNot startedNot applicableWhat an examiner getsthe two, still separate
What you say and what we can see are kept apart, permanently. A claim that a clause is covered is yours: recorded with your reason, never verified here, and never quietly upgraded. A signal is something this platform can actually observe — that your audit chain verifies, that a policy has human-review triggers, that a system is on the inventory. A signal is evidence a clause could be satisfied. It is never a claim that it is, and it is never written into your coverage.

Colorado AI Act — SB 24-205, repealed and replaced by SB 26-189

State of Colorado · US-CO · effective 2027-01-01 · CO_SB24_205

NOT IN FORCE. Enforcement of SB 24-205 was paused by a federal court on 2026-04-27 following a constitutional challenge by xAI in which the US Department of Justice intervened. SB 26-189, signed 2026-05-14, repeals it and re-enacts a narrower notice-and-disclosure regime for automated decision-making technology, effective 2027-01-01. The controls listed here describe the duties SB 24-205 imposed and are kept because organisations prepared against them; they are not current obligations, and no mapping to SB 26-189 has been done. Verified 2026-09-19.

ControlTitleRequirementSatisfied by
6-1-1702Developer duty of careDocumentation of known harms and reasonably foreseeable misuse supplied to deployers.D1 Documentation & Transparency
6-1-1702(2)Developer documentation to deployersDevelopers make available to deployers documentation describing intended and known harmful uses, training data summaries, known limitations, discrimination risks, and how the system should be used, not used, and monitored.D1 Documentation & Transparency
6-1-1702(3)Developer impact-assessment supportDevelopers make available to deployers, to the extent feasible, the artifacts (such as model cards or dataset cards) the deployer needs to complete its own impact assessment.D1 Documentation & Transparency
6-1-1703(4)(a)Consumer notice before a consequential decisionDeployers notify a consumer before a high-risk system is used to make, or substantially factor into, a consequential decision about them, in plain language and an accessible format.D1 Documentation & Transparency
6-1-1703(5)Deployer public risk-management statementDeployers publish, on their website, the types of high-risk systems they deploy, how they manage discrimination risk, and the nature, source and extent of information collected.D1 Documentation & Transparency
6-1-1704AI interaction disclosureDeployers ensure a consumer is told they are interacting with an AI system, unless that would already be obvious to a reasonable person.D1 Documentation & Transparency
6-1-1703(3)Deployer impact assessmentDeployers complete an impact assessment for each high-risk system at least annually and within 90 days of a substantial modification, covering purpose, discrimination-risk analysis, data categories, performance metrics, transparency measures and post-deployment monitoring.D2 Evaluation Evidence
6-1-1703(1)Deployer duty of reasonable careDeployers of a high-risk AI system use reasonable care to protect consumers from known or reasonably foreseeable algorithmic discrimination.D4 Fairness & Bias
6-1-1702(5)Developer discrimination disclosureA developer discloses to the Attorney General and to known deployers, without unreasonable delay, any known or reasonably foreseeable algorithmic discrimination risk it discovers or is credibly told about.D6 Accountability & Change Control
6-1-1703(2)Deployer risk management policy and programDeployers implement and iteratively review a risk management policy and program specifying the principles, processes and personnel used to identify, document and mitigate discrimination risk.D6 Accountability & Change Control
6-1-1703(4)(b)Adverse decision explanation, correction and appealWhere a consequential decision is adverse, deployers disclose the principal reasons and data sources, and give the consumer an opportunity to correct the data and appeal, with human review where technically feasible.D6 Accountability & Change Control

EU Artificial Intelligence Act (Reg. 2024/1689)

European Parliament & Council · EU · effective 2024-08-01 · EU_AI_ACT

High-risk obligations phase in through 2026-2027. Annex IV sets the technical documentation a provider must hold.

ControlTitleRequirementSatisfied by
Art.11 / Annex IVTechnical documentationProvider holds documentation describing the system, its intended purpose, and its design choices.D1 Documentation & Transparency
Art.13Transparency to deployersInstructions for use sufficient for the deployer to interpret output.D1 Documentation & Transparency
Art.14Human oversightDesigned so a natural person can effectively oversee it during use.D3 Safety & Robustness
Art.15Accuracy, robustness, cybersecurityAppropriate accuracy declared; resilience to error and adversarial manipulation.D3 Safety & Robustness
Art.10Data governanceTraining, validation and test sets examined for bias; gaps addressed.D4 Fairness & Bias
Art.12Record-keeping / loggingAutomatic recording of events over the system lifetime, enabling traceability.D6 Accountability & Change Control

FFIEC BSA/AML Examination Manual

FFIEC · US · effective 2021-06-21 · FFIEC_BSA

Independent testing pillar. Requires the tester not be involved in other BSA functions at that institution.

ControlTitleRequirementSatisfied by
31 CFR 1020.210(a)(2)(iv)BSA trainingAppropriate personnel receive training on the BSA/AML obligations relevant to their roles.D1 Documentation & Transparency
IND-TESTIndependent testingTesting performed by parties not involved in other BSA functions at the institution.D2 Evaluation Evidence
31 CFR 1010.230Beneficial ownership identificationBeneficial owners of legal entity customers are identified and verified at account opening, under both the ownership and control prongs.D5 Privacy & Data Handling
31 CFR 1020.210(a)(2)(v)Risk-based customer due diligenceRisk-based procedures identify and verify customers, understand the nature and purpose of customer relationships, and conduct ongoing monitoring to support suspicious activity reporting.D5 Privacy & Data Handling
31 CFR 1020.210(a)(2)(i)Internal controlsA system of internal controls assures ongoing compliance with the Bank Secrecy Act and its implementing regulations.D6 Accountability & Change Control
31 CFR 1020.210(a)(2)(iii)Designated BSA compliance officerAn individual is designated as responsible for coordinating and monitoring day-to-day BSA compliance.D6 Accountability & Change Control

GDPR Article 22 — Automated individual decision-making

European Data Protection Board · EU · effective 2018-05-25 · GDPR_A22

A person has the right not to be subject to a solely automated decision with legal or similarly significant effect, and to obtain human intervention and contest it.

ControlTitleRequirementSatisfied by
Art. 13(2)(f) / 14(2)(g)Notice of automated decision-making at collectionWhen personal data is collected, the data subject is told that Article 22(1)/(4) automated decision-making occurs, and given meaningful information about the logic, significance and envisaged consequences.D1 Documentation & Transparency
Art. 15(1)(h)Right of access to the logic involvedOn request, a data subject can obtain meaningful information about the logic, significance and envisaged consequences of automated decision-making concerning them.D1 Documentation & Transparency
Art. 35DPIA for high-risk automated decisionsA data protection impact assessment is carried out before processing that includes systematic, extensive, automated evaluation of personal aspects producing legal or similarly significant effects.D2 Evaluation Evidence
Art. 22(4)Special-category data restrictionA solely automated decision made under the contract or consent exceptions may not be based on special-category data unless explicit consent or substantial public interest applies, with suitable safeguards.D5 Privacy & Data Handling
Art. 22(1)Right not to be subject to a solely automated decisionA person is not subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects, unless an Article 22(2) exception applies.D6 Accountability & Change Control
Art. 22(3)Human intervention, expression of view, contestWhere the contract or consent exception applies, the controller provides at least the right to obtain human intervention, express a view, and contest the decision.D6 Accountability & Change Control
Art. 22(2)Permitted exceptionsA solely automated decision with such effects is lawful only where necessary for a contract with the data subject, authorised by Union or Member State law, or based on the data subject's explicit consent.D7 Regulatory Mappability

Good Machine Learning Practice for Medical Device Development

FDA / Health Canada / MHRA · US-UK-CA · effective 2021-10-27 · GMLP

Ten guiding principles for AI/ML in medical devices: representative datasets, performance on the intended population, and monitoring of deployed models.

ControlTitleRequirementSatisfied by
GMLP-9Clear, essential information for usersUsers have ready access to the device's intended use, subgroup performance, training/test data characteristics, known limitations and how to report concerns.D1 Documentation & Transparency
GMLP-4Training data independent of test dataTraining and test data sets are selected and maintained to be independent of one another, addressing patient, acquisition and site sources of dependence.D2 Evaluation Evidence
GMLP-5Reference data sets based on best available methodsReference standards used in development and testing are built with accepted, best-available methods, with the reference's limitations understood.D2 Evaluation Evidence
GMLP-8Testing under clinically relevant conditionsStatistically sound test plans generate performance evidence independent of the training data, covering the intended population, subgroups and clinical use conditions.D2 Evaluation Evidence
GMLP-2Good software engineering and security practicesModel design follows sound software engineering, data quality assurance, data management and cybersecurity practices, with decisions and rationale documented.D3 Safety & Robustness
GMLP-6Model design tailored to the data and intended useModel design is suited to the available data, mitigates known risks such as overfitting and performance degradation, and supports the device's intended use.D3 Safety & Robustness
GMLP-7Focus on the performance of the human-AI teamWhere a human is in the loop, human factors and interpretability of outputs are addressed with emphasis on the combined human-AI team's performance, not the model in isolation.D3 Safety & Robustness
GMLP-3Representative clinical study participants and data setsClinical study participants and training/test data sufficiently represent the intended patient population's relevant characteristics, so results generalize and bias can be managed.D4 Fairness & Bias
GMLP-1Multi-disciplinary expertise throughout the life cycleClinical, statistical, engineering and human-factors expertise is applied across the device's whole life cycle, not only at initial design.D6 Accountability & Change Control
GMLP-10Monitoring and management of re-training riskDeployed models are monitored for real-world performance, and where periodic or continual re-training occurs, controls manage overfitting, unintended bias and drift.D6 Accountability & Change Control

HIPAA Security Rule

US HHS Office for Civil Rights · US · effective 2005-04-20 · HIPAA_SEC

Administrative, physical and technical safeguards for electronic protected health information, including audit controls and access management.

ControlTitleRequirementSatisfied by
§164.308(a)(5)Security awareness and trainingAll workforce members, including management, receive a security awareness and training program.D1 Documentation & Transparency
§164.308(a)(7)Contingency planA contingency plan covers data backup, disaster recovery and emergency-mode operation for systems that hold electronic PHI.D3 Safety & Robustness
§164.310(a)(1)Facility access controlsPhysical access to the facilities and systems that hold electronic PHI is limited to authorized individuals.D5 Privacy & Data Handling
§164.310(d)(1)Device and media controlsPolicies govern the receipt, removal, reuse and disposal of hardware and electronic media that contain electronic PHI.D5 Privacy & Data Handling
§164.312(a)(1)Access controlTechnical policies restrict access to electronic PHI to the persons or software granted access rights, such as through unique user identification.D5 Privacy & Data Handling
§164.312(c)(1)IntegrityPolicies and procedures protect electronic PHI from improper alteration or destruction.D5 Privacy & Data Handling
§164.312(e)(1)Transmission securityTechnical measures guard against unauthorized access to electronic PHI while it is transmitted over a network.D5 Privacy & Data Handling
§164.308(a)(1)Security management processPolicies and procedures prevent, detect, contain and correct security violations against electronic PHI, built on a documented risk analysis.D6 Accountability & Change Control
§164.308(a)(6)Security incident proceduresPolicies and procedures identify, respond to, and document security incidents involving electronic PHI.D6 Accountability & Change Control
§164.312(b)Audit controlsHardware, software or procedural mechanisms record and examine activity in systems that contain or use electronic PHI.D6 Accountability & Change Control
§164.316(b)(1)Documentation retentionSecurity policies, procedures and required actions are documented in writing and retained for six years from creation or last effective date, whichever is later.D6 Accountability & Change Control

ISO/IEC 23894:2023 — AI Risk Management

ISO/IEC · International · effective 2023-02-01 · ISO_23894

Risk management guidance specific to AI, complementing ISO 31000. Process guidance rather than a conformity bar.

ControlTitleRequirementSatisfied by
Clause 6ProcessAn AI risk management process is applied: establishing scope, context and criteria; identifying, analysing and evaluating risk; treating risk; and continually communicating, monitoring, reviewing, recording and reporting.D2 Evaluation Evidence
Clause 4PrinciplesAI-adapted risk management principles, based on ISO 31000, are established as the basis for the organization's approach.D6 Accountability & Change Control
Clause 5FrameworkA risk management framework is established covering leadership and commitment, integration into organizational processes, design, implementation, evaluation and improvement.D6 Accountability & Change Control

ISO/IEC 42001:2023 — AI Management Systems

ISO/IEC · International · effective 2023-12-01 · ISO_42001

Certifiable management-system standard. Certification evidences process, not model quality.

ControlTitleRequirementSatisfied by
A.4Resources for AI systemsThe resources the AI system depends on — data, tooling, compute, human competence — are identified and documented.D1 Documentation & Transparency
A.8Information for interested parties of AI systemsInformation needed by users, affected parties and other interested parties is determined and provided.D1 Documentation & Transparency
A.7Data for AI systemsData used by the AI system is managed: its sources, provenance, quality and preparation are recorded.D5 Privacy & Data Handling
A.2Policies related to AIAn AI policy is established, approved, communicated and reviewed.D6 Accountability & Change Control
A.3Internal organizationRoles, responsibilities and reporting lines for the AI management system are defined and allocated.D6 Accountability & Change Control
A.6AI system life cycleThe AI system is developed, deployed, changed and retired under a defined and documented life cycle.D6 Accountability & Change Control
A.9Use of AI systemsResponsible use of the AI system is defined, including intended use and what use is not permitted.D6 Accountability & Change Control
A.10Third-party and customer relationshipsResponsibilities are allocated and understood across suppliers, partners and customers in the AI supply chain.D7 Regulatory Mappability
A.5Assessing impacts of AI systemsImpacts of the AI system on individuals, groups and society are assessed and documented.D7 Regulatory Mappability

AI Risk Management Framework 1.0

NIST · US · effective 2023-01-26 · NIST_AI_RMF

Voluntary. Four functions: Govern, Map, Measure, Manage. Widely used as the scaffolding US examiners expect to see.

ControlTitleRequirementSatisfied by
MAP-2.3Scientific integrity and TEVVTest, evaluation, verification and validation defined and documented.D2 Evaluation Evidence
MEASURE-2.7Security and resilience evaluatedRed-team and adversarial results recorded.D3 Safety & Robustness
MEASURE-2.11Fairness and bias evaluatedBias measured across relevant demographic groups.D4 Fairness & Bias
MANAGE-4.1Post-deployment monitoringPerformance monitored in production with defined thresholds.D6 Accountability & Change Control
GOVERN-1.1Legal and regulatory requirements understoodRequirements applying to the system are inventoried and tracked.D7 Regulatory Mappability

NYC Local Law 144 — Automated Employment Decision Tools

NYC Dept of Consumer and Worker Protection · US-NY · effective 2023-07-05 · NYC_LL144

Requires an independent bias audit within the prior year, published results, and notice to candidates. One of the few regimes that mandates a third-party audit by statute.

ControlTitleRequirementSatisfied by
6 RCNY §5-303Published results content and durationPublished results include the data source used, the count of individuals in an unknown category, and per-category counts, rates and impact ratios, and stay posted at least 6 months after the AEDT's last use.D1 Documentation & Transparency
§20-871(a)(2)Bias audit results published before useA summary of the most recent bias audit's results and the tool's distribution date is published on the employer's or employment agency's website before the tool is used.D1 Documentation & Transparency
§20-871(b)(1)Advance notice of AEDT useCandidates and employees residing in the city are notified at least 10 business days before an AEDT is used on them, with the right to request an alternative selection process or accommodation.D1 Documentation & Transparency
§20-871(b)(2)Notice of qualifications assessedCandidates and employees are told, at least 10 business days before use, the job qualifications and characteristics the AEDT will use in its assessment.D1 Documentation & Transparency
6 RCNY §5-301Bias audit calculation methodThe bias audit calculates selection or scoring rate and the resulting impact ratio separately for sex, race/ethnicity, and intersectional categories, using the EEOC's Component 1 categories.D4 Fairness & Bias
§20-871(a)(1)Bias audit within one yearAn AEDT may not be used to screen a candidate or employee unless it was the subject of an independent bias audit conducted no more than one year before that use.D4 Fairness & Bias
§20-871(b)(3)Data type, source and retention disclosed on requestThe type of data collected for the AEDT, its source, and the employer's or agency's retention policy are disclosed on written request within 30 days, unless already published.D5 Privacy & Data Handling

SR 26-2 — Model Risk Management

Federal Reserve / OCC · US · effective 2026-04-17 · SR_26_2

Replaced SR 11-7. Explicitly excludes generative and agentic AI as novel and rapidly evolving — the exclusion is the gap this registry addresses. VERIFY the citation before external use.

ControlTitleRequirementSatisfied by
III.BEffective challengeIndependent, informed, incentivised challenge of model design and outcomes.D2 Evaluation Evidence
V.AValidation independenceValidation carried out with rigour and free of misaligned commercial incentive.D2 Evaluation Evidence
II.AModel definition and inventoryModel inventory covers every model in use, with owner and version.D6 Accountability & Change Control
IV.COngoing monitoringPerformance tracked against benchmarks with escalation thresholds.D6 Accountability & Change Control

Talk to the person who built this

If you advise clients against these instruments, the gap between what they assert and what anyone can observe is probably familiar. There is no sales team and no company yet — the LLC is filed and not yet approved, so this reaches one person directly. Nothing is for sale today: what is on offer is a conversation, and free early access to the method, the corpus and the router if it is useful to you. If it is not a fit, saying so costs you one reply.

Start a conversation

What are you trying to show, and to whom — an auditor, a client, a regulator, your own board?

Your address is used to reply and nothing else. It is not published, not sold, and not added to a mailing list.

GovernanceHub — the governance registry and policy router for AI systems