EvidentAI — Audit & Compliance

Compliance

Live compliance posture — per-framework control coverage and open findings by severity, derived from the control catalog and findings store (no fixtures).

Framework coverage

Findings by severity

No open findings. Open the findings queue →

Framework readiness

coverage detail →
FrameworkVersionMapped controlsFramework ID
NIST AI Risk Management Framework1.0
150
nist_ai_rmf
AICPA SOC 2 Trust Services Criteria2017
77
soc_2
EU AI Act2024
55
eu_ai_act
NIST SP 800-53 Rev. 5Rev.5
45
nist_800_53
ISO/IEC 42001 (AI Management System)2023
44
iso_42001
CMMC 2.0 (Cybersecurity Maturity Model Certification)2.0 · 32 CFR 170
40
cmmc_2_0
SR/MRM (US Banking Model Risk Management)OCC 2026-13
38
sr_mrm
EU GDPR2016/679
34
gdpr
NAIC Model Bulletin on AI Use by Insurers2023-12
13
naic_bulletin
Colorado AI Act (SB 24-205)2024
12
co_ai_act
PCI DSS v4.0v4.0
12
pci_dss
Sarbanes-Oxley (SOX ITGC)2002
10
sox
ECOA / Regulation B12 CFR 1002
8
ecoa_reg_b
Texas TRAIGA (HB 149)2024
8
tx_traiga
HIPAA Security Rule45 CFR
6
hipaa
CCPA / CPRA2023
5
ccpa
Fair Credit Reporting Act (FCRA)15 USC 1681
4
fcra
FINRA Rulescurrent
3
finra
ISO/IEC 270012022
3
iso_27001
NYDFS 23 NYCRR 5002023
1
nydfs
SEC Marketing Rule (206(4)-1)206(4)-1
1
sec_marketing_rule
NIST AI 600-1 (Generative AI Profile)1.0
0
nist_ai_600_1

Control catalog by category

45MDL
45PRM
40DAT
40EVL
40MON
35null
35SAF
30ACC
28DEP
28REG
25TPR
22BCM
6governance
2security
2fairness
1data
1observability