Compliance
Live compliance posture — per-framework control coverage and open findings by severity, derived from the control catalog and findings store (no fixtures).
Framework coverage
Findings by severity
No open findings. Open the findings queue →
Framework readiness
coverage detail →| Framework | Version | Mapped controls | Framework ID |
|---|---|---|---|
| NIST AI Risk Management Framework | 1.0 | nist_ai_rmf | |
| AICPA SOC 2 Trust Services Criteria | 2017 | soc_2 | |
| EU AI Act | 2024 | eu_ai_act | |
| NIST SP 800-53 Rev. 5 | Rev.5 | nist_800_53 | |
| ISO/IEC 42001 (AI Management System) | 2023 | iso_42001 | |
| CMMC 2.0 (Cybersecurity Maturity Model Certification) | 2.0 · 32 CFR 170 | cmmc_2_0 | |
| SR/MRM (US Banking Model Risk Management) | OCC 2026-13 | sr_mrm | |
| EU GDPR | 2016/679 | gdpr | |
| NAIC Model Bulletin on AI Use by Insurers | 2023-12 | naic_bulletin | |
| Colorado AI Act (SB 24-205) | 2024 | co_ai_act | |
| PCI DSS v4.0 | v4.0 | pci_dss | |
| Sarbanes-Oxley (SOX ITGC) | 2002 | sox | |
| ECOA / Regulation B | 12 CFR 1002 | ecoa_reg_b | |
| Texas TRAIGA (HB 149) | 2024 | tx_traiga | |
| HIPAA Security Rule | 45 CFR | hipaa | |
| CCPA / CPRA | 2023 | ccpa | |
| Fair Credit Reporting Act (FCRA) | 15 USC 1681 | fcra | |
| FINRA Rules | current | finra | |
| ISO/IEC 27001 | 2022 | iso_27001 | |
| NYDFS 23 NYCRR 500 | 2023 | nydfs | |
| SEC Marketing Rule (206(4)-1) | 206(4)-1 | sec_marketing_rule | |
| NIST AI 600-1 (Generative AI Profile) | 1.0 | nist_ai_600_1 |
Control catalog by category
45MDL
45PRM
40DAT
40EVL
40MON
35null
35SAF
30ACC
28DEP
28REG
25TPR
22BCM
6governance
2security
2fairness
1data
1observability