Compliance, every framework included
AuditRails satisfies 18 compliance frameworks, from EU AI Act to SOC 2 to seven country-specific standards, all bundled free on Compliance Trails. No per-framework fee, ever. Tamper-evident retention that scales to each framework's requirement. Auditor-ready reports.
EU AI Act, articles covered
Our deepest framework detail, since AI Act deadlines got us started. Five articles are auto-verified by ingest pattern alone. Three more we support, you provide the process and documentation.
Article 12
Automatic recording of events
High-risk AI systems must log events that ensure traceability over the lifetime of the system.
How: Every aiact.model_inference_logged event extends the per-tenant tamper-evident hash chain. Logs are retained for at least 10 years in WORM storage.
Article 14
Human oversight measures
High-risk AI systems must support effective human oversight, including the ability to intervene or interrupt operation.
How: Log every operator override, stop, or correction as a human_oversight_intervention event. AuditRails verifies presence of these events for every system in production.
Article 50
Transparency obligations to natural persons
Users interacting with an AI system must be informed that they are interacting with AI, unless obvious from context.
How: Log every disclosure shown to an end user as a transparency_disclosure_shown event. AuditRails verifies coverage across user-facing AI flows.
Article 72
Post-market monitoring system
Providers must establish a post-market monitoring system to evaluate continuous compliance.
How: Stream drift, accuracy, and field-incident signals as post_market_monitoring_event entries. AuditRails confirms a continuous stream is present.
Article 73
Reporting of serious incidents
Providers must report any serious incident or malfunction to market surveillance authorities within strict deadlines.
How: Capture each incident as a serious_incident_logged event with severity and authority-notification metadata. AuditRails surfaces notification-deadline coverage.
Article 9
Risk management system
Providers must establish a continuous, iterative risk management system across the full lifecycle.
How: AuditRails records each risk_management_review event for the audit trail. Documentation + process is your responsibility.
Article 10
Data and data governance
Training, validation, and testing datasets must be subject to governance, including provenance and bias detection.
How: Log each dataset version change as a training_data_lineage_recorded event. Dataset cards + bias review are your responsibility.
Article 43
Conformity assessment procedure
Providers must complete the relevant conformity assessment before placing the system on the market.
How: Record each completed assessment as a conformity_assessment_record event with the certificate reference. The assessment itself is performed by a notified body.
17 more frameworks, all available now
Every framework below is active today and bundled free on Compliance Trails, enable any of them from Settings in minutes, no separate fee, no waiting on a roadmap.
GDPR
General Data Protection Regulation
EU data protection. Article 30 records of processing + Article 33 breach reporting, both backed by a tamper-evident audit trail.
DORA
Digital Operational Resilience Act
Mandatory ICT operational resilience for EU financial services. Incident reporting, third-party risk, and audit logging.
NIS2
Network and Information Systems Directive 2
Cybersecurity requirements for EU essential and important entities, incident reporting and security measures verified by audit logs.
HIPAA
Health Insurance Portability and Accountability Act
US healthcare. PHI access, disclosure, and breach-notification logging with minimum-necessary justification tracking.
SOC 2
SOC 2 Type II
Trust Services Criteria audit evidence, access control, change management, and incident response, continuously logged.
ISO 27001
ISO/IEC 27001:2022
Information security management system evidence across all 93 Annex A controls, from access review to incident handling.
PCI DSS
Payment Card Industry Data Security Standard
Cardholder data access, firewall changes, and vulnerability scans logged to the standard your acquiring bank expects.
SOX
Sarbanes-Oxley Act
IT general controls for financial reporting, segregation of duties, change approval, and 7-year immutable retention.
CCPA
California Consumer Privacy Act / CPRA
Consumer rights requests, opt-outs, and Global Privacy Control signal handling, logged end to end.
FedRAMP
Federal Risk and Authorization Management Program
NIST SP 800-53-aligned audit logging for US federal cloud authorization, including POA&M-tracked vulnerabilities.
UK GDPR
UK General Data Protection Regulation
ICO-enforced UK data protection, SAR turnaround, breach notification, and international transfer records.
LOPDGDD
Ley Orgánica de Protección de Datos (Spain)
Spain-specific GDPR implementation, video surveillance logging, whistleblower protection, digital rights at work.
Cyber Essentials
UK Cyber Essentials
NCSC-backed certification scheme, firewall config, patch SLAs, and access control evidence for UK government contracts.
BSI C5
BSI Cloud Computing Compliance Criteria Catalogue
German BSI cloud-provider standard, operational security, logging, and incident management for the Mittelstand.
DNB Good Practice
De Nederlandsche Bank Good Practice
Dutch central bank IT-risk guidance for financial institutions, closely aligned with DORA and EBA expectations.
SecNumCloud
ANSSI SecNumCloud
French national cybersecurity qualification for cloud providers, data sovereignty and encryption key lifecycle logging.
amm_sistema
Provvedimento Amministratori di Sistema (Italy)
Italian Garante requirement for tamper-proof system-administrator access logging, minimum 6-month retention.
Need a framework that's not listed? Talk to us.
Get audit-ready, for every framework you need.
90-day free trial. No credit card required.
Start free trial