SR 11-7
SR 11-7 model-risk governance
Documented intent, review, and exceptions, with risk monitored over time — not at one approval point.
Evidence produced
- Intent Fidelity events
- Requirement-to-change trace
- Approvals & governance audit
- PR merge evidence
- Evidence package export
- Cognitive-debt manager report
- Agent Trust Score
- Signed threshold sign-offs
Still to validate
Model-inventory linkage, independent validation, and model-risk owner signoff in your environment.
FFIEC
FFIEC bank technology risk
Every change traces to its agent; every sensitive action to an actor, a policy, and an outcome.
Evidence produced
- Normalized event ledger
- Policy decisions
- Approval bridge records
- Audit explorer
- PR merge evidence & Check Runs
- Merge-gate & branch protection
- Connector provenance
- Pre-execution policy blocks
Still to validate
IAM integration, live identity mapping, and a validated deployment inside your own cloud.
DORA
DORA (EU operational resilience) ICT change & third-party risk
Controlled changes, approvals that deny when review is unavailable, and a clear view of reliance on outside agents.
Evidence produced
- Governance-path docs (local, CI, worker)
- Portal approval bridge
- Audit records
- Evidence packages
- Connector proof walkthroughs
- Architecture boundary statement
- Cloud-boundary docs
- Deployment readiness checks
Still to validate
Full deployment automation, customer-environment validation, live connector proof, and resilience runbooks.
EU AI Act
EU AI Act governance concepts
Demonstrable human oversight: approvals on record, unrewritable logs, documented risk decisions.
Evidence produced
- Human approval bridge
- Append-only audit log
- Intent Fidelity notes
- Agent Run Audit
- Policy decision reasons
- Evidence export
Still to validate
Legal classification, role-specific human-oversight procedures, and retention-policy alignment.
ISO 42001
ISO 42001 AI management system
An AI management system needs defined roles, risk controls, monitoring, and traceable records.
Evidence produced
- Scope & boundary documentation
- Private registry provenance
- Policy packs
- Cognitive-debt report
- Agent Trust Score
- Audit & evidence exports
- Control-ownership matrix
Still to validate
Formal AI management-system procedures, completed control-owner matrices, and an approved trust-score use policy.
SOC 2
SOC 2 / ISO 27001 change management
The same questions as human code: authorized by whom, tested how, traceable to what record.
Evidence produced
- PR merge evidence
- Approvals & audit records
- Agent Run Audit
- Conformance tests
- Build & test attestations
- Check Run & merge gate
- Branch-protection verifier
- Deployment attestations
Still to validate
CI and ticketing integration, and live deployment attestations.
AutoDevOps produces the evidence; the opinion belongs to your auditor. Customer-cloud validation of AutoDevOps itself is still open in every mapping above.