Skip to content

A requirement needs a record behind it.

The business can show what was checked, who signed off and where evidence is still missing. Explore how those records support a framework review, with the limits kept in view.

Find the framework in front of you.

Six starting points. Two different kinds of support.

Selected framework mappings

Specific framework references are linked to types of product records. Evidence still depends on what happened within the review’s scope.

EU AI Act

Logging, oversight, and disclosure records for selected AI Act references.

NIST AI RMF

Selected Govern, Measure and Manage references, with the evidence gaps kept visible.

ISO 42001

Event, oversight, and documentation records for AI management reviews.

Security and privacy review topics

Relevant controls and data practices to examine. These frameworks do not have a control-by-control mapping in the current catalog.

SOC 2

Access and action records to support an independent assurance review.

ISO 27001

Access, protection, and accountability within security management.

GDPR

Scoped collection, temporary source processing, and deliberate data lifecycles.

A listed framework is not a certification, an endorsement or a finding of compliance.

A mapping still needs evidence.

To show an action was held for human approval, the record needs the check and the decision. Activity learned about afterward establishes something different.

Human oversight · EU AI Act Article 14Illustrative review

Who signed off on the $612 credit?

Compare alternative evidence sets for the same question. These are not a sequence of events.

Choose an evidence set
Company action history

$612 customer credit held for approval

Approval required above $500. Maya Okafor approved this credit at 4:12 PM on September 22, 2026.

Reference under reviewArticle 14 · Human oversight

Evidence of a check and approval

The record shows a hold and a named person’s decision before the credit could proceed.

What this does not establish

Approval is not proof that the credit was applied. This record does not establish every human-oversight duty under Article 14.

Give the reviewer a defined record to examine.

The evidence is recorded as work happens, ahead of the review. A packet brings the relevant history together for a customer’s procurement team, an auditor, an insurer or your board.

  1. Agree the scope.

    Name the company or agent, the period and the question being reviewed. One agent’s record does not cover the whole company.

  2. Keep the basis.

    Include the relevant decisions, evidence and mapping version. Keep checked actions, later observations and missing evidence distinct.

  3. Leave room for judgment.

    The reviewer decides whether the evidence is enough. A verified packet does not establish legal compliance or the effectiveness of every control.

Packet availability, supported records and sharing arrangements are confirmed for your deployment.

Receipts & verification

Before the assessment begins.

What the mappings mean, and what remains with your company and its reviewers.

Trust & security
Does a mapping mean a requirement has been met?

No. It links a type of record to a selected framework reference. The review may still have no qualifying evidence for that reference, and the reviewer decides whether the evidence is sufficient.

Why are the six frameworks in two groups?

EU AI Act, NIST AI RMF and ISO 42001 have selected references in the mapping catalog. SOC 2, ISO 27001 and GDPR have relevant security or privacy review topics, but no current control-by-control mapping in that catalog.

Does selecting a framework turn on company rules?

No. A framework mapping helps organize evidence for a review. Company policies and approvals determine which actions are checked and held; selecting a framework does not create those controls.

Can imported activity prove an action was held?

No. Imported activity can help establish what happened, but it cannot prove the action passed a check before it took effect. The review must keep that distinction visible.

What if a mapped reference has no evidence?

It stays marked as not evidenced for that review. A catalog entry is not a substitute for a record, and a missing record is not proof that the event never happened.

Is this certification or legal advice?

No. Mappings and packets support assessment; they do not establish certification, legal compliance or a regulator’s endorsement. No SOC 2 attestation or ISO 27001 certification is currently claimed for the service.

Start with the requirement you need to answer for.

Bring the review question. Establish the scope and the evidence it needs.

Discuss your review