Skip to content

Platform

Turn AI activity into evidence

Map a framework to a control, a control to a policy, and a policy to the AI activity that satisfies it, so an audit reads records rather than assurances.

What this is not

A mapping is not an attestation.

OpsAI is not certified against these frameworks and is not a certification body. It produces records that map to control themes. Your assessor decides whether those records satisfy anything.

Themes mapped

9

With a stated limit

4

How a framework reaches a record

An audit should read records, not assurances.

The gap between a policy document and an audit is usually a person assembling screenshots. Four steps close it: a framework asks a question, a control theme names what would answer it, a policy implements it as a bound, and the activity writes the record as it happens.

  1. A framework asks a questionexternal

    Not a clause reference — the question an assessor actually puts to you, which several instruments ask in slightly different words.

  2. A control theme names what would answer ityours

    The organization decides what evidence would satisfy the question. This step is a judgement, and it belongs to the organization rather than to OpsAI.

  3. A policy implements it as a boundenforced

    Where the control is enforceable at an action, it compiles to a bound: owned, versioned, and evaluated with no model call in the path.

  4. The activity produces the recordread by the assessor

    Every attempt, decision, refusal and expiry is written as it happens. Nobody assembles it later, which is what makes it evidence rather than a report.

The record is written as it happens, or it is not evidence.

An assurance is somebody stating that a control operated. Evidence is the control having written down what it did at the time, including the times it refused. That distinction is the whole reason this page can exist without a spreadsheet behind it.

The instruments

Different kinds of thing, asking for different kinds of proof.

A management system, a risk framework, an attestation and two regulations are not interchangeable, and treating them as one list is how a compliance programme ends up evidencing the wrong thing thoroughly.

ISO/IEC 42001management system
That AI is managed by a system with owners, policies and review, not by individual good intentions.
NIST AI RMFrisk framework
That AI risk is identified, measured and managed continuously rather than assessed once.
SOC 2attestation
That the controls you described are the controls that operated, over a period, with evidence.
EU AI Actregulation
That higher-risk uses carry human oversight, record-keeping and traceability.
DPDP Actregulation
That personal data is processed for a stated purpose, with a lawful basis and a record.
No clause numbers
A precise citation is a factual claim about a document, these instruments are revised, and a wrong reference on a compliance page is worse than none. Themes are phrased as the question an assessor asks instead.

The mapping

9 control themes, and an honest column for how far the record goes.

Each row names the question, which frameworks ask it, the policy that enforces it where one does, and how completely OpsAI can evidence it. That last column is the one worth reading first.

Control themes

9 themes · 5 evidenced end to end
Every control theme in the mapping: the question an assessor asks, the frameworks that ask it, the policies that implement it, how completely OpsAI evidences it, and where the mechanism lives.
Control themeAsked for byPolicyEvidenceMechanism
Inventory of AI systemsWhat AI is operating, and how do you know the list is complete?ISO/IEC 42001NIST AI RMFEU AI ActpartialOpen
Accountability and ownershipWho answers for this system, and was that recorded before the incident?ISO/IEC 42001SOC 2completeOpen
Human oversight of consequential actionsWhich actions required a person, and what happened when nobody responded?EU AI ActNIST AI RMFISO/IEC 42001payout.dual_controlvendor.new_payeecompleteOpen
Access control and least privilegeWhat could this system reach, and was the grant scoped and time-bound?SOC 2ISO/IEC 42001write.windowcompleteOpen
Personal data handlingWhat personal data did AI read, and where was it permitted to go?DPDP ActEU AI Actpii.export_blockpartialOpen
Change management for rulesWho changed this rule, when, and what did it decide before the change?SOC 2ISO/IEC 42001refund.ceilingdelegation.depthcompleteOpen
Monitoring and incident responseHow was this detected, how long until it was contained, and who was told?SOC 2NIST AI RMFISO/IEC 42001completeOpen
Model provenance and documentationWhat model version ran, where did it run, and what was it approved for?EU AI ActISO/IEC 42001partialOpen
Workforce competence and trainingAre the people accountable for these systems trained for it?ISO/IEC 42001noneOpen

Themes mapped

9

across 5 instruments

Evidenced end to end

5

the record answers directly

Partial

3

with the limit stated

Not evidenced

1

named, not omitted

IllustrativeAn illustrative mapping for the OpsAI sample estate. 6 of 8 policies in the register are cited by a theme; the rest govern actions rather than controls.

What OpsAI does not evidence

A mapping with no gaps is a brochure.

These are the themes where the record stops short, and they are on the page for a reason: an assessor who has read a vendor compliance matrix before will assume an unbroken row of ticks is inflated, and be right to. Naming the limits is what makes the other rows worth reading.

Inventory of AI systemspartial
Completeness cannot be proven, only evidenced. Discovery reads the systems you already run, and it names what each source is blind to.
Personal data handlingpartial
Whether consent was validly obtained upstream is not something a control plane can observe. OpsAI evidences what was read and where it went, not the lawful basis for holding it.
Model provenance and documentationpartial
Training-data provenance and the accuracy of a provider’s model card are the provider’s to substantiate. OpsAI records what you were told and when, not whether it was true.
Workforce competence and trainingnone
This is an HR record. It appears here because a mapping that silently omitted it would be implying coverage OpsAI does not have.

Completeness is evidenced, never proven.

The inventory theme is partial for a reason that applies to every discovery tool ever built: you cannot prove a list is complete. What you can do is show which sources were consulted and state what each one is blind to, which is a weaker claim and a true one.

One theme is not evidenced at all. It stays in the mapping because a matrix that silently dropped its inconvenient rows would be implying coverage that does not exist, which is the failure mode this whole section is written against.

Where to start

Pick the control your last assessment argued about, and ask what record would have settled it.

Usually the answer is a timestamp, a named person and a decision — three things that either existed at the time or did not. Everything on this page is downstream of writing them down as they happen.