Keep the mapping version.
Conformance packets record the catalog version used to associate their evidence with framework references.
Bring governance evidence into AI, security, and privacy reviews, with a clear view of what is mapped and what still needs assessment.
Selected catalog mappings and architecture alignment, with scope made explicit.
Each page explains the relevant product records, the limits of coverage, and the work that remains with your organization and reviewers.
Product records are associated with selected framework references.
Catalog 2026.09.2Logging, oversight, and disclosure records for selected AI Act references.
Explore EU AI Act Voluntary AI risk frameworkSelected Govern, Measure, and Manage references with evidence gaps visible.
Explore NIST AI RMF AI management system standardEvent, oversight, and documentation records for AI management reviews.
Explore ISO 42001Relevant controls and data practices, without a current receipt-catalog crosswalk.
Access and action records to support an independent assurance review.
Explore SOC 2 Information security management standardAccess, protection, and accountability within security management.
Explore ISO 27001 Data protection regulationScoped collection, temporary source processing, and deliberate data lifecycles.
Explore GDPRA useful review connects the event, the control reference, and the scope of what was captured.
Actor, verdict, policy, and basis
Version 2026.09.2
Evidence, integrity, and coverage
Conformance packets record the catalog version used to associate their evidence with framework references.
Enforced, observed, and not-evidenced records remain distinct. A catalog reference alone does not establish evidence.
Reviewers determine whether the record is sufficient for the requirement and scope under examination.
Where Attest is available, conformance packets bring together scoped history, integrity checks, selected control references, and evidence coverage.
Explore reconstruction and auditPacket availability and evidence scope are confirmed for the deployment.
It identifies the product records associated with selected framework references. A mapping can exist even when no qualifying activity appears in the packet’s scope or review window. It is an advisory reference rather than a compliance finding.
It describes relevant product mechanisms, such as scoped access, audit history, and temporary source processing. SOC 2, ISO 27001, and GDPR are not currently mapped in the receipt catalog.
Where Attest is available, a packet brings together scoped records, integrity checks, selected control references, and evidence coverage. The reviewer must assess whether the material is sufficient for the specific requirement.
No. Verification checks the integrity of the recorded history. It does not establish the correctness of a decision, the adequacy of a control, or compliance with a framework.
Walk through the evidence your team needs and where the product can contribute.