Enterprise
Compliance at OpsAI
How framework controls map to policies, how policies produce evidence, and what an auditor can read instead of taking your word for it.
Two halves of the answer
- Ours
- No certifications held, no audit under way, no dates.
- Yours
- 5 obligations the record answers directly, 3 shared, 1 that stay entirely with you.
The first half
OpsAI holds no certifications, and this page will not imply otherwise.
A compliance page from a vendor normally opens with what it has achieved. This one opens with what it has not, because that fact is discoverable in five minutes and burying it costs the reader's trust in everything that follows.
Framework status
5 frameworks · 0 certifications held| Framework | Status | The position |
|---|---|---|
| SOC 2 | not certifiedmechanism documented | No report and no audit under way. The controls a SOC 2 examination looks at — access control, change management, monitoring — are implemented and documented, and you can read how rather than read an opinion about them. |
| ISO/IEC 27001 | not certified | Not certified and not in an audit cycle. Naming a target date for one would be inventing a commitment. |
| ISO/IEC 42001 | not certifiedmechanism documented | Not certified. The AI management-system practices the standard asks about — an inventory with named owners, versioned policy, review — are what the product does, so they are inspectable in the product itself. |
| GDPR and DPDP | not certifiedmechanism documented | Data-protection law is not something a vendor is certified against. What we can state is where data sits, what leaves, and what is never copied — all of which is documented rather than asserted. |
| HIPAA | not certified | No BAA offered today. Saying otherwise to keep a deal moving would be the exact failure this page exists to avoid. |
Train any model on your data, your policies or your decision records.
Use your estate as a reference or case study without a written agreement.
Offer a certification we do not hold, or a date for one we have not scheduled.
Claim to prevent prompt injection. Nothing does reliably; we make it ineffective at the boundary.
The second half
Which of your obligations the record can answer, and which stay yours.
This is the table a compliance professional actually needs and the one most vendors leave out — because every row in the 'yours' column looks like a gap in the product. It is not a gap. It is the division of responsibility, and pretending it does not exist is what makes a vendor matrix worthless.
Control obligations and whose job each one is
9 themes · 5 evidenced by OpsAI · 1 entirely yours| Your control obligation | Asked for by | Whose job | Mechanism |
|---|---|---|---|
| Inventory of AI systemsWhat AI is operating, and how do you know the list is complete? | ISO/IEC 42001NIST AI RMFEU AI Act | shared | Read it |
| Accountability and ownershipWho answers for this system, and was that recorded before the incident? | ISO/IEC 42001SOC 2 | OpsAI evidences it | Read it |
| Human oversight of consequential actionsWhich actions required a person, and what happened when nobody responded? | EU AI ActNIST AI RMFISO/IEC 42001 | OpsAI evidences it | Read it |
| Access control and least privilegeWhat could this system reach, and was the grant scoped and time-bound? | SOC 2ISO/IEC 42001 | OpsAI evidences it | Read it |
| Personal data handlingWhat personal data did AI read, and where was it permitted to go? | DPDP ActEU AI Act | shared | Read it |
| Change management for rulesWho changed this rule, when, and what did it decide before the change? | SOC 2ISO/IEC 42001 | OpsAI evidences it | Read it |
| Monitoring and incident responseHow was this detected, how long until it was contained, and who was told? | SOC 2NIST AI RMFISO/IEC 42001 | OpsAI evidences it | Read it |
| Model provenance and documentationWhat model version ran, where did it run, and what was it approved for? | EU AI ActISO/IEC 42001 | shared | Read it |
| Workforce competence and trainingAre the people accountable for these systems trained for it? | ISO/IEC 42001 | yours | Read it |
Obligations mapped
9
across five instruments
OpsAI evidences
5
the record answers directly
Shared
3
with the limit stated
Entirely yours
1
named, not omitted
IllustrativeAn illustrative mapping against the OpsAI sample estate. How a framework reaches a record.
The rows that stay yours, in full
Read these before the rest of the table. A vendor matrix showing an unbroken column of ticks is the genre an assessor discounts on sight, and these are the rows that make the others worth reading.
- Inventory of AI systemsshared
- Completeness cannot be proven, only evidenced. Discovery reads the systems you already run, and it names what each source is blind to.
- Personal data handlingshared
- Whether consent was validly obtained upstream is not something a control plane can observe. OpsAI evidences what was read and where it went, not the lawful basis for holding it.
- Model provenance and documentationshared
- Training-data provenance and the accuracy of a provider’s model card are the provider’s to substantiate. OpsAI records what you were told and when, not whether it was true.
- Workforce competence and trainingyours
- This is an HR record. It appears here because a mapping that silently omitted it would be implying coverage OpsAI does not have.
What an assessor is given
Records, not a report about records.
The distinction decides how the meeting goes. An assurance is challenged and defended with more assurance; a record is read and the conversation moves on to the next control.
- Per action
- The action, the rule version in force at the time, each check with its result, the accountable human, and a digest chain the assessor can verify without us.
- Per policy
- Its owner, its version history, and replay — so “what was the limit in March” is a lookup rather than an archaeology exercise.
- Including the refusals
- Recorded as completely as the authorizations. An assessor’s first question is what the system attempted, and a success log cannot answer it.
- What is not in the export
- The contents of anything read from a governed source, and no credential or grant. An evidence record carries references rather than payloads.
The mechanism
How a framework reaches a record
Framework, control theme, policy, record — and the themes OpsAI cannot evidence.
The job
For a compliance team
Written for whoever assembles evidence by hand today, and what they stop doing.
Our status
Trust center
Certification status as status, the properties behind each claim, and what OpsAI will not do.
Where to start
Send the 'yours' column to your assessor before you evaluate anything else.
If those rows are acceptable, the rest of the conversation is about mechanisms and it will go quickly. If they are not, you have found that out in an afternoon rather than in month three.