Compliance

Frameworks, controls and evidence that survives an audit

Assurance and compliance ask for the same evidence. AICAP generates it once, doing the assurance work, then maps it to the frameworks you report against.

01

Obligations you have to meet

Someone else checks these: a regulator, a certification body or an auditor. There is a formal route and a formal outcome.

EU AI Act

Legislation. High-risk obligations: record-keeping, technical documentation, retention and serious incident reporting.

ISO/IEC 42001

A certifiable management system for AI: risk actions, lifecycle data governance, monitoring and measurement, and logging.

SOC 2 Type II

An audit opinion. Logical access, access removal, security event monitoring and incident evaluation.

02

Assurance you have to be able to show

No certificate to hold up. These expect you to do the assurance work and to be able to evidence it on demand.

JSP 936

Dependable AI in Defence expects AI-enabled systems to be justified across their whole life, not signed off once.

UK Software Security Code of Practice

Secure development and supply-chain expectations, applied to code AI wrote as much as code a person wrote.

NIST AI RMF

Voluntary by design, and the crosswalk the others are commonly mapped against: govern, measure, manage.

03

Controls mapped to evidence you already generate

Each control names the evidence that satisfies it and where that evidence comes from. Status runs from not started through to attested, so the gap between what you claim and what you can show stays visible.

It is not another register to keep by hand. The four pillars produce the records as they work: Survey the inventory of what you have, Origin the provenance of the code, Core the test and assurance evidence, and Trace the record of what agents did. The compliance layer indexes them.

04

The UK picture

JSP 936 expects dependable AI to be justified through life. A point-in-time assessment cannot do that: the system changes, the threat landscape changes, and the original justification quietly stops holding. That through-life justification is Core's job, with Trace covering how agents behave once they are running.

SSCoP asks you to know what is in your software and where it came from. When AI writes it, provenance is the first thing to break. That is Origin, backed by Survey's inventory of what is actually deployed.

Secure by design and the NCSC's secure AI guidance both push assurance earlier and make it continuous. Same engine, same evidence.

05

Attestations, incidents and retention

Attestation. Submitted, then reviewed by a second person, with both identities and timestamps recorded.

Incidents. Tracked against framework reporting deadlines, so the clock is visible from the moment one is raised.

Retention and legal hold. Policies per record class, holds that suspend deletion, and a report covering what is held, where and for how long, across assurance evidence, provenance and agent activity alike.

06

Evidence that survives leaving the platform

Exports are signed and independently verifiable: whoever you hand a bundle to can check it without access to your instance. Underneath, the event store is append-only, which is what makes end-to-end traceability a property of the system rather than a reporting exercise.

07

Built for regulated environments

  • Defence & national security
  • Financial services
  • Healthcare & life sciences
  • Critical national infrastructure
  • Government & public sector
  • Regulated software supply chains