AuditRailsAuditRails
18 frameworks, all available now

Compliance, every framework included

AuditRails satisfies 18 compliance frameworks, from EU AI Act to SOC 2 to seven country-specific standards, all bundled free on Compliance Trails. No per-framework fee, ever. Tamper-evident retention that scales to each framework's requirement. Auditor-ready reports.

EU AI Act, articles covered

Our deepest framework detail, since AI Act deadlines got us started. Five articles are auto-verified by ingest pattern alone. Three more we support, you provide the process and documentation.

Article 12

Automatic recording of events

Auto-verified

High-risk AI systems must log events that ensure traceability over the lifetime of the system.

How: Every aiact.model_inference_logged event extends the per-tenant tamper-evident hash chain. Logs are retained for at least 10 years in WORM storage.

Article 14

Human oversight measures

Auto-verified

High-risk AI systems must support effective human oversight, including the ability to intervene or interrupt operation.

How: Log every operator override, stop, or correction as a human_oversight_intervention event. AuditRails verifies presence of these events for every system in production.

Article 50

Transparency obligations to natural persons

Auto-verified

Users interacting with an AI system must be informed that they are interacting with AI, unless obvious from context.

How: Log every disclosure shown to an end user as a transparency_disclosure_shown event. AuditRails verifies coverage across user-facing AI flows.

Article 72

Post-market monitoring system

Auto-verified

Providers must establish a post-market monitoring system to evaluate continuous compliance.

How: Stream drift, accuracy, and field-incident signals as post_market_monitoring_event entries. AuditRails confirms a continuous stream is present.

Article 73

Reporting of serious incidents

Auto-verified

Providers must report any serious incident or malfunction to market surveillance authorities within strict deadlines.

How: Capture each incident as a serious_incident_logged event with severity and authority-notification metadata. AuditRails surfaces notification-deadline coverage.

Article 9

Risk management system

Supported

Providers must establish a continuous, iterative risk management system across the full lifecycle.

How: AuditRails records each risk_management_review event for the audit trail. Documentation + process is your responsibility.

Article 10

Data and data governance

Supported

Training, validation, and testing datasets must be subject to governance, including provenance and bias detection.

How: Log each dataset version change as a training_data_lineage_recorded event. Dataset cards + bias review are your responsibility.

Article 43

Conformity assessment procedure

Supported

Providers must complete the relevant conformity assessment before placing the system on the market.

How: Record each completed assessment as a conformity_assessment_record event with the certificate reference. The assessment itself is performed by a notified body.

17 more frameworks, all available now

Every framework below is active today and bundled free on Compliance Trails, enable any of them from Settings in minutes, no separate fee, no waiting on a roadmap.

Available now

GDPR

General Data Protection Regulation

EU data protection. Article 30 records of processing + Article 33 breach reporting, both backed by a tamper-evident audit trail.

Available now

DORA

Digital Operational Resilience Act

Mandatory ICT operational resilience for EU financial services. Incident reporting, third-party risk, and audit logging.

Available now

NIS2

Network and Information Systems Directive 2

Cybersecurity requirements for EU essential and important entities, incident reporting and security measures verified by audit logs.

Available now

HIPAA

Health Insurance Portability and Accountability Act

US healthcare. PHI access, disclosure, and breach-notification logging with minimum-necessary justification tracking.

Available now

SOC 2

SOC 2 Type II

Trust Services Criteria audit evidence, access control, change management, and incident response, continuously logged.

Available now

ISO 27001

ISO/IEC 27001:2022

Information security management system evidence across all 93 Annex A controls, from access review to incident handling.

Available now

PCI DSS

Payment Card Industry Data Security Standard

Cardholder data access, firewall changes, and vulnerability scans logged to the standard your acquiring bank expects.

Available now

SOX

Sarbanes-Oxley Act

IT general controls for financial reporting, segregation of duties, change approval, and 7-year immutable retention.

Available now

CCPA

California Consumer Privacy Act / CPRA

Consumer rights requests, opt-outs, and Global Privacy Control signal handling, logged end to end.

Available now

FedRAMP

Federal Risk and Authorization Management Program

NIST SP 800-53-aligned audit logging for US federal cloud authorization, including POA&M-tracked vulnerabilities.

Available now

UK GDPR

UK General Data Protection Regulation

ICO-enforced UK data protection, SAR turnaround, breach notification, and international transfer records.

Available now

LOPDGDD

Ley Orgánica de Protección de Datos (Spain)

Spain-specific GDPR implementation, video surveillance logging, whistleblower protection, digital rights at work.

Available now

Cyber Essentials

UK Cyber Essentials

NCSC-backed certification scheme, firewall config, patch SLAs, and access control evidence for UK government contracts.

Available now

BSI C5

BSI Cloud Computing Compliance Criteria Catalogue

German BSI cloud-provider standard, operational security, logging, and incident management for the Mittelstand.

Available now

DNB Good Practice

De Nederlandsche Bank Good Practice

Dutch central bank IT-risk guidance for financial institutions, closely aligned with DORA and EBA expectations.

Available now

SecNumCloud

ANSSI SecNumCloud

French national cybersecurity qualification for cloud providers, data sovereignty and encryption key lifecycle logging.

Available now

amm_sistema

Provvedimento Amministratori di Sistema (Italy)

Italian Garante requirement for tamper-proof system-administrator access logging, minimum 6-month retention.

Need a framework that's not listed? Talk to us.

Get audit-ready, for every framework you need.

90-day free trial. No credit card required.

Start free trial