USE CASES / GRC

Prove control to an assessor, not to a dashboard.

Your job is not to have controls. It is to evidence them — to hand a reviewer a record they can examine, a mapping that says what it proves, and an honest statement of where a person still has to attest. GovernorAI records governance actions in a hash-chained, tamper-evident audit ledger and maps that evidence to named controls. Mapping evidence to controls is not certification, and this page keeps that line visible throughout.

Hash-chained audit ledger Evidence mapped to named controls Coverage stated per control Pre-deployment gate
TWO FRAMEWORK PACKS, COVERAGE AS SHIPPED ISO/IEC 42001 · automatic 0 ISO/IEC 42001 · partial 6 ISO/IEC 42001 · attested 29 NIST AI RMF · automatic 0 NIST AI RMF · partial 15 NIST AI RMF · attested 38 35 clauses and 53 subcategories — and zero automatic between them.

The two AI standards a board is most likely to ask about seed zero automatic controls between them. That is the honest starting position, and it is on the page rather than behind it.

ISO/IEC 42001 · 35NIST AI RMF · 530 automatic

WHAT YOUR JOB ACTUALLY IS HERE

Three problems that arrive together the moment an agent takes an action.

The AI-governance question your business hands you is usually framed as a policy question. In practice it resolves into an evidence question, a control-mapping question and a timing question — and the timing one is the one that catches teams out.

Evidence Show me what the control did, not that it exists.

A screenshot of a policy page proves configuration. An assessor wants the record of the control operating: which action, decided by which policy version, under whose approval, on what date — and some reason to believe the record was not edited afterwards.

Mapping Which clause does this actually satisfy?

Evidence with no control reference is a log file. The work is the mapping — and the honest part of the mapping is admitting which clauses a platform signal can never answer, because they are organisational rather than technical.

Timing It went to production in March. We are asking in November.

Retrospective evidence collection is the expensive failure mode. If nothing was recorded at the moment the agent was approved for deployment, no amount of effort in November reconstructs it.

THE ASSESSOR'S QUESTIONS

Five questions, and the artefact each one is answered with.

These are the questions a reviewer asks about an agent that took a consequential action. The right-hand side is a shipped surface, not a promise — and where the honest answer is "a person attests to this", it says so.

What did this agent actually do, and when?

Governance actions are written to the audit store with a sequence number and the SHA-256 hash of the entry before them. Verification walks the chain from an empty genesis hash and stops at the first row it cannot reconcile, naming that row.

The answer carries its own scope: a pass also reports how many rows predate the tenant-binding hash format, and refuses to assert tenant binding when it cannot. Evidence & Compliance shows the entry shape and the verification response.

Who allowed it, and against which rule?

Every governed action resolves to a verdict carrying the matched policies, an explain code, a reason and — where the action was escalated — the approver and the decision latency. Call arguments are recorded as SHA-256 digests rather than raw values.

Change management runs with separation of duties: the author of a policy is not its approver, and the approval is attributable to a named person. /governance-timeline replays who approved, assigned, deferred, escalated or revoked.

Was it fit to go to production in the first place?

Assurance evaluates an immutable snapshot of the agent — model provider, name and version, a hash over the prompt manifest, a hash over the tool manifest, the artifact digest and the runtime-config digest — against acceptance bars registered before the run.

A verdict expires when the ground moves. A configuration change mints a new snapshot; a namespace move or an assigned-policy edit stales every prior run for that agent, and the gate treats a stale run as a block rather than a warning.

Which control does this evidence support?

A standard evidence catalogue populates per account and derives its payload from real signals — audit-event volume, active policy count, enabled alert rules, registered agents. Items no signal can produce are marked as document or screenshot uploads rather than filled in.

Every control in a framework pack carries a coverage status, and a control is never returned as automatic if any part of it still needs a person to attest.

Can I take it away and read it myself?

Template-driven exports per framework in PDF, JSON, CSV or HTML across a date range, with a preview of the sections and the evidence each one carries before the job runs. The AI-BOM exports as JSON or PDF with a SHA-256 content hash over the inventory, so a post-hoc edit is detectable.

Signed evidence bundles — Ed25519 with Merkle batch manifests — are available per deployment. They are off unless an operator turns evidence signing on, and they additionally require a dedicated gateway and a persistent key store or the gateway refuses to start rather than sign unverifiably.

Stated precisely Control mapping and evidence for governed actions, recorded in a hash-chained, tamper-evident audit ledger.

The ledger is live wherever GovernorAI runs — no flag, no separate plane. What it holds is governance actions: policy decisions, approvals, session lifecycle, kill-switch activations, policy changes. It is deliberately not described as a record of every decision your AI estate makes, because coverage follows the enforcement points that are actually integrated.

Honesty note — mapping evidence to controls is not certification

Naming a regulation here means GovernorAI has a workspace, a control library, or an evidence mapping for it. It does not mean that running GovernorAI makes you compliant with it, and no framework named here is automatically or fully covered.

A certification is issued by an auditor, a certification body or a notified body, against their own opinion. GovernorAI is none of those and produces no audit opinion. What it produces is a record, and a mapping an assessor can examine.

A valid chain is also a narrower claim than it sounds. It proves the entries the ledger holds still reconcile and names the first row that does not. It cannot tell you the record is complete — that depends on which enforcement points are integrated and what the deployment actually routes through them.

THE FOUR BUCKETS

Every control resolves to one of four values, and two of them are admissions.

This is the mechanism that keeps the mapping honest. A framework pack does not produce a score; it produces a status per control, and where GovernorAI cannot prove something it names the fields you have to attest to yourself instead of scoring it.

ISO/IEC 42001:2023

clauses
35
automatic
0
partial
6
manual attestation
29

Seeded coverage for the AI management system. This is a management-system standard, and most of it is organisational evidence no tool can produce for you.

NIST AI RMF 1.0

subcategories
53
automatic
0
partial
15
manual attestation
38

Across GOVERN, MAP, MEASURE and MANAGE. The partial ones are the subcategories a live signal contributes to — audit log, kill switch, policy engine, approval workflow, anomaly detection, RBAC.

Attestation, tracked

campaigns
recurring
per task
owner · due date
decisions
four
history
per policy

Each policy owner gets a task with a due date and a decision — still relevant, needs update, should retire, needs review — plus reject and escalate paths and overdue tracking.

Honesty note — for the AI-governance standards, most controls are manual, and we publish that

The two AI standards a board is most likely to ask about seed zero automatic controls between them. That is not a gap in the packs; it is what those standards are. Anyone offering automatic or continuous coverage of ISO/IEC 42001 or the NIST AI RMF is describing something other than what those documents require. GovernorAI's contribution is the subset a running platform can genuinely evidence, stated as partial, with the rest routed to a named human attestation and chased on a due date.

NAMED REGULATORY PROGRAMMES

The regulations we will name, and the narrow thing naming them buys you.

Each of these is a surface that exists in the product. The full table — including where each one lives, what it covers, and the row that is honestly marked API-only — is on Evidence & Compliance; this is the short version for deciding whether the conversation is worth having.

Programme workspace

EU AI Act

Register an AI system, get a risk tier from a scored classifier, and track obligations against a requirement library naming Articles 6, 9–16, 26, 50 and 52. Human-oversight configuration and transparency records attach to the same record.

triage for counsel, not a legal determination
Programme workspace

Colorado SB 24-205

High-risk system records across the seven consequential-decision domains, plus documented impact assessments covering bias risk, mitigation, human oversight, consumer notice and appeal. Each obligation can link to a specific audit event as its evidence.

obligation → audit event
Data-subject operations

GDPR

Right-of-access exports, erasure with an explicit confirm step and a retry path, consent grant and withdrawal, retention policies and data-residency configuration. Erasure is gated by the legal-hold registry and fails closed.

no proof of no-hold means no erasure
Framework pack

ISO/IEC 42001 · NIST AI RMF

Every clause and subcategory with its coverage status and, where GovernorAI cannot prove it, the named fields you must attest to by hand. Assessment runs, findings and per-control attestation work the same way across packs.

coverage status on every control
Live control assessment

SOC 2 · HIPAA · PCI DSS

Controls scored from real system state rather than a questionnaire, resolving to pass, fail, partial or not_assessed. The EU AI Act is deliberately excluded from this assessor, because platform signals do not answer its questions.

an exclusion stated on purpose
Cross-framework

Control references

A seeded map of equivalent and overlapping controls between SOC 2, GDPR, HIPAA and PCI DSS, each with a stated relationship and rationale, so evidence gathered once can be pointed at its counterpart.

a stated mapping, not a proof of equivalence

Two things this list does not say. It does not say a regulation is satisfied — see the honesty note above. And it does not say every surface has a screen: the legal-hold registry is API-driven today, and Evidence & Compliance marks it that way rather than letting a reader assume a console exists.

THE TIMING PROBLEM

The cheapest evidence is the evidence recorded before deployment.

Assurance is a design-time control that sits in your pipeline. It decides whether a candidate agent may be deployed at all, and it produces the artefact you would otherwise be reconstructing eight months later.

PREREGISTERED

The bar is set before the run

Every measured domain reports its raw numerator and denominator, sample size, a confidence interval, and a bar chosen before the result was seen. A domain that could not be measured still carries its bar, so what it would have been held to stays visible.

measurement, never projection
NOT A PASS

not_assessed is the absence of evidence

It is neither a failure nor a pass. It appears when a domain's prerequisite is missing in your environment, with an operator-readable reason naming what is missing. A critical unit reporting it blocks the gate rather than clearing it.

named prerequisite
EXIT CODES

Unreachable never exits zero

Pass, blocked, malformed input, control plane unreachable and authentication failure are five distinct exit codes. A control plane that read no evidence cannot produce a green gate, and auth failure stays separate from a network blip.

a CI/CD step, not a dashboard
BUNDLE

The result leaves as a re-verifiable artifact

A run exports as a self-describing evidence bundle whose staleness statement is made as of the moment it was generated. A separate operator client retains captured bundles and re-verifies them, reporting the retention condition honestly — including when it is not met.

re-verified, not just archived
Honesty note — a passing gate is a narrow statement, and some sections of the inventory ship empty

A passing assurance gate does not assert that an agent is safe in general. It asserts that the units your deployment could measure cleared bars preregistered before the run, on the exact configuration named in the snapshot, at that time. It stops a pipeline, not a running agent — that is the runtime enforcement point, and a separate control.

The AI-BOM ships three sections empty with a written explanation rather than a plausible guess: there is no per-tenant agent-to-tool or agent-to-data-source binding recorded today, and ownership is empty because GovernorAI knows who registered an agent and who approved a model — that is provenance, and a registrant is not an owner. Policy coverage is read from a projection that can lag live assignments, so the export carries its as-of timestamp and reports an agent missing from the projection as coverage-unknown, which is a different thing from ungoverned.

Continue