Skip to content
3.0Compliance & Frameworks

Every Framework.One Set of Evidence.

Map every AI system to the obligations that apply to it, from data localisation to model risk, and hold one body of evidence that satisfies all of them at once — refreshed as the systems change, not assembled when someone asks.

3.1 Where it applies

Obligations follow your AI across borders.

Your AI does not live in one place. Tell us where it is trained, where it runs, and who uses it. We automatically determine which regulations apply, including data sovereignty, cross-border data transfer, and residency requirements—without relying on generic checklists.

3.2 What’s blocking deployment

From failed controls to actionable fixes.

Every alert includes technical evidence, impacted systems, responsible owners, and framework mappings so remediation is immediate.

What is actually stopping you
6AI systems in the estate0 prohibited · 2 high-risk · 4 not yet classified
6 of 6have at least one EU AI Act control failing100% of the inventory
80high-severity issuesA high-severity rule trip blocks deployment until it is cleared
10controls behind the worst obligationSorted by reach, not by article number
1fixed onceClears 6 systems and 4 frameworks
Fix onceHIGH · 6 systems · 0 n/a
Upload one accuracy test resultThe same evidence satisfies every control that asks for it. The drawer beside this one is the proof.
6AI systems clear
4frameworks updated
1engineering task
EU AI Act postureREG-EUAIACT-2024/1689 · last sync 26 Jul 2026
Where you stand43 tracked · worst first
Art-15Accuracy, Robustness and Cybersecurity13%
Art-13Transparency and Information to Deployers17%
Art-72Post-Market Monitoring System21%
Art-9Risk Management System29%
Art-19Automatically Generated Logs Retention29%
Art-10Data and Data Governance31%
Art-12Record-Keeping (Logging)38%

and 36 more, re-evaluated on every sync.

← Back to obligationsAccuracy, Robustness and CybersecurityArt-15 · EU AI Act obligation
Coverage13%
Systems failing6
Controls failing39 of 45
Failing controls10 controls · sorted by reach
Accuracy not tested against criteriaHIGH6systems
No misuse mitigation in placeHIGH6systems
Robustness not testedHIGH6systems
Security and resilience not evaluatedHIGH6systems

and 6 more under this obligation.

← Back to failing controlsAccuracy not tested against criteriaA deployed AI system’s accuracy and performance have not been tested against declared criteria for deployment-like conditions.
Open alerts6
Systems affected6
Not applicable0
Frameworks4
Frameworks & clausesmaps to 4
MDS-10CSA AI Controls Matrix (AICM) v1.0.3Model Continuous Monitoring
Art-15EU AI Act (Regulation 2024/1689) currentAccuracy, Robustness and Cybersecurity
A.6.3ISO/IEC 42001:2023Testing and Validation
MEASURE-2.3NIST AI Risk Management Framework 1.0Performance Criteria
Alert lineage6 systems · 2 repos · 1 agent · 2 owners · 4 clauses · 4 frameworks

Tracing the alert’s lineage…

AlertAccuracy not testedagainst criteriaAI systemHR screening assistantAI systemCustomer service chatbotAI system+ 4 more systemsCompliance checkFailRepositoryhr-screening/serviceRepositorychat-gateway/apiAgentcandidate-scoring-agentEvidence · missingAccuracy test resultsRuleNo accuracy testTechnical ownerPlatform EngineeringBusiness ownerRisk & ComplianceFramework clauseModel Continuous MonitoringFramework clauseAccuracy & RobustnessFramework clauseTesting and ValidationFramework clausePerformance CriteriaFrameworkCSA AICM v1.0.3FrameworkEU AI Act 2024/1689FrameworkISO/IEC 42001:2023FrameworkNIST AI RMF 1.0
What to do nextAttach accuracy test results against declared criteria. Clears the check on all 6 AI systems and lifts every one of the 4 mapped frameworks.
3.3 Continuous compliance

Compliance that scales across frameworks.

From AI regulations to security and governance standards, monitor every requirement continuously through a single set of controls and evidence.

EU AI ActRegulation (EU) 2024/1689
Four risk tiers
UnacceptableHigh-riskLimitedMinimal

Binding law. Prohibited practices, high-risk duties, transparency and GPAI — tracked article by article.

CSA AI Controls MatrixAICM v1.0.3 · Cloud Security Alliance
Eighteen control domains
A&AAISBCRCCCCEKDCSDSPGRCHRSIAMIPYIVSLOGMDSSEFSTATVMUEM
MDS · model security

Cloud and AI control in one matrix, already mapped across the EU AI Act, ISO/IEC 42001 and NIST AI RMF.

ISO/IEC 42001:2023AI management systems
The management cycle
PlanDoCheckAct
continual improvement

The requirements for running an AI management system — and the one standard here an auditor can certify you against.

NIST AI RMF 1.02023 · with the GenAI Profile
The four functions
Govern
MapMeasureManage
govern runs across all three

Voluntary, and the one most US programmes are written to — with the Generative AI Profile layered on top.

ISO/IEC 23894:2023AI risk management guidance
The risk process
01Identify02Analyse03Evaluate04Treat05Monitor

How risk management is actually applied to AI: where a model’s risk comes from, and what to do about each source.

EU AI ActRegulation (EU) 2024/1689
Four risk tiers
UnacceptableHigh-riskLimitedMinimal

Binding law. Prohibited practices, high-risk duties, transparency and GPAI — tracked article by article.

CSA AI Controls MatrixAICM v1.0.3 · Cloud Security Alliance
Eighteen control domains
A&AAISBCRCCCCEKDCSDSPGRCHRSIAMIPYIVSLOGMDSSEFSTATVMUEM
MDS · model security

Cloud and AI control in one matrix, already mapped across the EU AI Act, ISO/IEC 42001 and NIST AI RMF.

ISO/IEC 42001:2023AI management systems
The management cycle
PlanDoCheckAct
continual improvement

The requirements for running an AI management system — and the one standard here an auditor can certify you against.

NIST AI RMF 1.02023 · with the GenAI Profile
The four functions
Govern
MapMeasureManage
govern runs across all three

Voluntary, and the one most US programmes are written to — with the Generative AI Profile layered on top.

ISO/IEC 23894:2023AI risk management guidance
The risk process
01Identify02Analyse03Evaluate04Treat05Monitor

How risk management is actually applied to AI: where a model’s risk comes from, and what to do about each source.

3.4 One continuous loop

From discovery to governance, in one continuous loop. Each stage feeds the next over the same estate, and the whole cycle re-runs itself the moment anything changes.

DiscoveryWatching
38connected sources read continuously
ChatbotDoc assistantCode assistantClaims triageHR screeningCredit model
Detect
Strai8 continuously discovers AI systems from endpoint telemetry, cloud integrations, and enterprise applications, building a living inventory without relying on manual declarations.
AssessmentDerived, not asked
57fields evaluated on every record
Testing & Evaluation
Privacy & Data
Model Security
Safety & Risk
+ 13 more domains
ClassificationHigh-riskAnnex III 5(b)
Assess
Every discovered system is evaluated against regulatory requirements, organizational policies, and technical signals to continuously classify risk and determine applicable obligations.
EvidenceCollected, then matched
3 of 3required documents on file
Model cardDocumented
Data provenanceTraceable
Bias reportEvaluated
No screenshots, no spreadsheet
Verify
Strai8 gathers technical evidence directly from your environment, links it to the right controls, and keeps documentation audit-ready without spreadsheets or manual uploads.
AlignmentIn step
5frameworks kept in step
One control satisfied
EUAI Act
ISO42001
NISTAI RMF
AICMv1.0.3
ISO223894
Govern
Every approved decision automatically propagates across policies, controls, and compliance frameworks, so a single update stays consistent everywhere it matters.
3.5 Talk to us

See It Run Against Your Own Frameworks.

Bring the frameworks you are held to. We will show you which obligations reach each AI system you run — geo-fenced data included — what is failing today, and the evidence that closes it.