Platform
Turn AI activity into evidence
Map a framework to a control, a control to a policy, and a policy to the AI activity that satisfies it, so an audit reads records rather than assurances.
What this is not
A mapping is not an attestation.
OpsAI is not certified against these frameworks and is not a certification body. It produces records that map to control themes. Your assessor decides whether those records satisfy anything.
Themes mapped
9
With a stated limit
4
How a framework reaches a record
An audit should read records, not assurances.
The gap between a policy document and an audit is usually a person assembling screenshots. Four steps close it: a framework asks a question, a control theme names what would answer it, a policy implements it as a bound, and the activity writes the record as it happens.
A framework asks a questionexternal
Not a clause reference — the question an assessor actually puts to you, which several instruments ask in slightly different words.
A control theme names what would answer ityours
The organization decides what evidence would satisfy the question. This step is a judgement, and it belongs to the organization rather than to OpsAI.
A policy implements it as a boundenforced
Where the control is enforceable at an action, it compiles to a bound: owned, versioned, and evaluated with no model call in the path.
The activity produces the recordread by the assessor
Every attempt, decision, refusal and expiry is written as it happens. Nobody assembles it later, which is what makes it evidence rather than a report.
The record is written as it happens, or it is not evidence.
An assurance is somebody stating that a control operated. Evidence is the control having written down what it did at the time, including the times it refused. That distinction is the whole reason this page can exist without a spreadsheet behind it.
The instruments
Different kinds of thing, asking for different kinds of proof.
A management system, a risk framework, an attestation and two regulations are not interchangeable, and treating them as one list is how a compliance programme ends up evidencing the wrong thing thoroughly.
- ISO/IEC 42001management system
- That AI is managed by a system with owners, policies and review, not by individual good intentions.
- NIST AI RMFrisk framework
- That AI risk is identified, measured and managed continuously rather than assessed once.
- SOC 2attestation
- That the controls you described are the controls that operated, over a period, with evidence.
- EU AI Actregulation
- That higher-risk uses carry human oversight, record-keeping and traceability.
- DPDP Actregulation
- That personal data is processed for a stated purpose, with a lawful basis and a record.
- No clause numbers
- A precise citation is a factual claim about a document, these instruments are revised, and a wrong reference on a compliance page is worse than none. Themes are phrased as the question an assessor asks instead.
The mapping
9 control themes, and an honest column for how far the record goes.
Each row names the question, which frameworks ask it, the policy that enforces it where one does, and how completely OpsAI can evidence it. That last column is the one worth reading first.
Control themes
9 themes · 5 evidenced end to end| Control theme | Asked for by | Policy | Evidence | Mechanism |
|---|---|---|---|---|
| Inventory of AI systemsWhat AI is operating, and how do you know the list is complete? | ISO/IEC 42001NIST AI RMFEU AI Act | — | partial | Open |
| Accountability and ownershipWho answers for this system, and was that recorded before the incident? | ISO/IEC 42001SOC 2 | — | complete | Open |
| Human oversight of consequential actionsWhich actions required a person, and what happened when nobody responded? | EU AI ActNIST AI RMFISO/IEC 42001 | payout.dual_controlvendor.new_payee | complete | Open |
| Access control and least privilegeWhat could this system reach, and was the grant scoped and time-bound? | SOC 2ISO/IEC 42001 | write.window | complete | Open |
| Personal data handlingWhat personal data did AI read, and where was it permitted to go? | DPDP ActEU AI Act | pii.export_block | partial | Open |
| Change management for rulesWho changed this rule, when, and what did it decide before the change? | SOC 2ISO/IEC 42001 | refund.ceilingdelegation.depth | complete | Open |
| Monitoring and incident responseHow was this detected, how long until it was contained, and who was told? | SOC 2NIST AI RMFISO/IEC 42001 | — | complete | Open |
| Model provenance and documentationWhat model version ran, where did it run, and what was it approved for? | EU AI ActISO/IEC 42001 | — | partial | Open |
| Workforce competence and trainingAre the people accountable for these systems trained for it? | ISO/IEC 42001 | — | none | Open |
Themes mapped
9
across 5 instruments
Evidenced end to end
5
the record answers directly
Partial
3
with the limit stated
Not evidenced
1
named, not omitted
IllustrativeAn illustrative mapping for the OpsAI sample estate. 6 of 8 policies in the register are cited by a theme; the rest govern actions rather than controls.
What OpsAI does not evidence
A mapping with no gaps is a brochure.
These are the themes where the record stops short, and they are on the page for a reason: an assessor who has read a vendor compliance matrix before will assume an unbroken row of ticks is inflated, and be right to. Naming the limits is what makes the other rows worth reading.
- Inventory of AI systemspartial
- Completeness cannot be proven, only evidenced. Discovery reads the systems you already run, and it names what each source is blind to.
- Personal data handlingpartial
- Whether consent was validly obtained upstream is not something a control plane can observe. OpsAI evidences what was read and where it went, not the lawful basis for holding it.
- Model provenance and documentationpartial
- Training-data provenance and the accuracy of a provider’s model card are the provider’s to substantiate. OpsAI records what you were told and when, not whether it was true.
- Workforce competence and trainingnone
- This is an HR record. It appears here because a mapping that silently omitted it would be implying coverage OpsAI does not have.
Completeness is evidenced, never proven.
The inventory theme is partial for a reason that applies to every discovery tool ever built: you cannot prove a list is complete. What you can do is show which sources were consulted and state what each one is blind to, which is a weaker claim and a true one.
One theme is not evidenced at all. It stays in the mapping because a matrix that silently dropped its inconvenient rows would be implying coverage that does not exist, which is the failure mode this whole section is written against.
Where to start
Pick the control your last assessment argued about, and ask what record would have settled it.
Usually the answer is a timestamp, a named person and a decision — three things that either existed at the time or did not. Everything on this page is downstream of writing them down as they happen.