| EU AI Act | /compliance/programs/eu-ai-act | Register an AI system, get a risk tier — unacceptable, high, limited or minimal — from a scored classifier, and track obligations against a requirement library that names Articles 6, 9–16, 26, 50 and 52. Human-oversight configuration, transparency records, and per-system bias reports attach to the same record. The classifier scores category, purpose and deployment region: first-pass triage for counsel to confirm, not a legal determination. |
| Colorado SB 24-205 (Colorado AI Act) | /compliance/programs/colorado-ai-act | High-risk system records across the seven consequential-decision domains — employment, education, financial, government, healthcare, housing, legal — plus documented impact assessments covering bias risk, mitigation steps, human oversight, consumer notice and appeal mechanism. Each obligation can be linked to a specific audit event as its evidence. |
| GDPR — data-subject operations | /privacy | Right-of-access exports, erasure requests with an explicit confirm step and a retry path, consent grant and withdrawal, retention policies, and data-residency configuration. Erasure is gated by the legal-hold registry and fails closed: if the gate cannot prove there is no hold, the erasure is blocked rather than allowed. |
| SOC 2, GDPR, HIPAA, PCI DSS — live control assessment | /compliance | Controls scored from real system state — audit-event volume, active policies, enabled alert rules, registered agents — rather than from a questionnaire. Controls resolve to pass, fail, partial or not_assessed. The EU AI Act is deliberately excluded from this assessor and handled as a programme workspace instead, because platform signals do not answer its questions. |
| ISO/IEC 42001:2023 | /compliance/programs/frameworks/iso_42001 | All 35 clauses of the AI management system, each with a coverage status and, where GovernorAI cannot prove it, the named fields you must attest to by hand. Seeded coverage is 0 automatic, 6 partial, 29 manual attestation — this is a management-system standard, and most of it is organisational evidence no tool can produce for you. |
| NIST AI RMF 1.0 | /compliance/programs/frameworks/nist_ai_rmf | All 53 subcategories across GOVERN, MAP, MEASURE and MANAGE. Seeded coverage is 0 automatic, 15 partial, 38 manual attestation. The partial ones are the subcategories a live GovernorAI signal genuinely contributes to — audit log, kill switch, policy engine, approval workflow, anomaly detection, RBAC. |
| NIST SP 800-53 Rev 5 | /compliance/programs/frameworks/nist_800_53 | A control pack with the same coverage classification, assessment runs, findings and per-control attestation as the others. Useful where an agent programme has to answer to an existing federal control catalogue rather than a new AI-specific one. |
| Cross-framework control references | /compliance/scorecards | A seeded map of equivalent and overlapping controls between SOC 2, GDPR, HIPAA and PCI DSS, each with a stated relationship and rationale, so evidence gathered for one control can be pointed at its counterpart instead of collected twice. It is a stated mapping with its reasoning attached, not a proof of equivalence. |
| Legal hold and records preservation | API only — /api/v1/legal-holds | Place an account-, subject- or resource-scoped preservation hold that blocks erasure of the covered records until it is explicitly released. There is no legal-hold console: today the registry is driven through the API, and the only place a hold surfaces in the interface is as a legal-hold flag on a retention policy in the Privacy Center. |