Skip to content

Enterprise

Compliance at OpsAI

How framework controls map to policies, how policies produce evidence, and what an auditor can read instead of taking your word for it.

Two halves of the answer

Ours
No certifications held, no audit under way, no dates.
Yours
5 obligations the record answers directly, 3 shared, 1 that stay entirely with you.

The first half

OpsAI holds no certifications, and this page will not imply otherwise.

A compliance page from a vendor normally opens with what it has achieved. This one opens with what it has not, because that fact is discoverable in five minutes and burying it costs the reader's trust in everything that follows.

Framework status

5 frameworks · 0 certifications held
Each framework, OpsAI's honest position on it, and where the underlying mechanism is documented.
FrameworkStatusThe position
SOC 2not certifiedmechanism documentedNo report and no audit under way. The controls a SOC 2 examination looks at — access control, change management, monitoring — are implemented and documented, and you can read how rather than read an opinion about them.
ISO/IEC 27001not certifiedNot certified and not in an audit cycle. Naming a target date for one would be inventing a commitment.
ISO/IEC 42001not certifiedmechanism documentedNot certified. The AI management-system practices the standard asks about — an inventory with named owners, versioned policy, review — are what the product does, so they are inspectable in the product itself.
GDPR and DPDPnot certifiedmechanism documentedData-protection law is not something a vendor is certified against. What we can state is where data sits, what leaves, and what is never copied — all of which is documented rather than asserted.
HIPAAnot certifiedNo BAA offered today. Saying otherwise to keep a deal moving would be the exact failure this page exists to avoid.
  • Train any model on your data, your policies or your decision records.

  • Use your estate as a reference or case study without a written agreement.

  • Offer a certification we do not hold, or a date for one we have not scheduled.

  • Claim to prevent prompt injection. Nothing does reliably; we make it ineffective at the boundary.

The second half

Which of your obligations the record can answer, and which stay yours.

This is the table a compliance professional actually needs and the one most vendors leave out — because every row in the 'yours' column looks like a gap in the product. It is not a gap. It is the division of responsibility, and pretending it does not exist is what makes a vendor matrix worthless.

Control obligations and whose job each one is

9 themes · 5 evidenced by OpsAI · 1 entirely yours
Every control theme in the mapping: the question an assessor asks, the frameworks that ask it, whether OpsAI evidences it, and where the mechanism lives.
Your control obligationAsked for byWhose jobMechanism
Inventory of AI systemsWhat AI is operating, and how do you know the list is complete?ISO/IEC 42001NIST AI RMFEU AI ActsharedRead it
Accountability and ownershipWho answers for this system, and was that recorded before the incident?ISO/IEC 42001SOC 2OpsAI evidences itRead it
Human oversight of consequential actionsWhich actions required a person, and what happened when nobody responded?EU AI ActNIST AI RMFISO/IEC 42001OpsAI evidences itRead it
Access control and least privilegeWhat could this system reach, and was the grant scoped and time-bound?SOC 2ISO/IEC 42001OpsAI evidences itRead it
Personal data handlingWhat personal data did AI read, and where was it permitted to go?DPDP ActEU AI ActsharedRead it
Change management for rulesWho changed this rule, when, and what did it decide before the change?SOC 2ISO/IEC 42001OpsAI evidences itRead it
Monitoring and incident responseHow was this detected, how long until it was contained, and who was told?SOC 2NIST AI RMFISO/IEC 42001OpsAI evidences itRead it
Model provenance and documentationWhat model version ran, where did it run, and what was it approved for?EU AI ActISO/IEC 42001sharedRead it
Workforce competence and trainingAre the people accountable for these systems trained for it?ISO/IEC 42001yoursRead it

Obligations mapped

9

across five instruments

OpsAI evidences

5

the record answers directly

Shared

3

with the limit stated

Entirely yours

1

named, not omitted

IllustrativeAn illustrative mapping against the OpsAI sample estate. How a framework reaches a record.

The rows that stay yours, in full

Read these before the rest of the table. A vendor matrix showing an unbroken column of ticks is the genre an assessor discounts on sight, and these are the rows that make the others worth reading.

Inventory of AI systemsshared
Completeness cannot be proven, only evidenced. Discovery reads the systems you already run, and it names what each source is blind to.
Personal data handlingshared
Whether consent was validly obtained upstream is not something a control plane can observe. OpsAI evidences what was read and where it went, not the lawful basis for holding it.
Model provenance and documentationshared
Training-data provenance and the accuracy of a provider’s model card are the provider’s to substantiate. OpsAI records what you were told and when, not whether it was true.
Workforce competence and trainingyours
This is an HR record. It appears here because a mapping that silently omitted it would be implying coverage OpsAI does not have.

What an assessor is given

Records, not a report about records.

The distinction decides how the meeting goes. An assurance is challenged and defended with more assurance; a record is read and the conversation moves on to the next control.

Per action
The action, the rule version in force at the time, each check with its result, the accountable human, and a digest chain the assessor can verify without us.
Per policy
Its owner, its version history, and replay — so “what was the limit in March” is a lookup rather than an archaeology exercise.
Including the refusals
Recorded as completely as the authorizations. An assessor’s first question is what the system attempted, and a success log cannot answer it.
What is not in the export
The contents of anything read from a governed source, and no credential or grant. An evidence record carries references rather than payloads.

Where to start

Send the 'yours' column to your assessor before you evaluate anything else.

If those rows are acceptable, the rest of the conversation is about mechanisms and it will go quickly. If they are not, you have found that out in an afternoon rather than in month three.