Compliance

Compliance resources for enterprise AI

ISO 42001, SOC 2, GDPR DPIA, and AI FRIA — everything your legal, risk, and engineering teams need to deploy AI agents in regulated environments.

Compliance Frameworks

The frameworks your regulated deployment needs

ISO 42001

AI Management System for Engineers

ISO/IEC 42001 is the first international standard for AI management systems. It requires organizations to document AI objectives, risk assessments, and governance controls — and to demonstrate that those controls actually work in production.

AgentTrust OS maps directly to ISO 42001's requirements: Trust Certify generates pre-production evidence, Trust Runtime enforces governance controls, and Trust Audit produces the documentation your certifying body needs.

Clause 6: AI risk assessment documentation
Clause 8: Operational planning and control
Clause 9: Monitoring and measurement
Clause 10: Continuous improvement evidence
AI EU Act

Fundamental Rights Impact Assessment (FRIA)

High-risk AI systems under the EU AI Act require a Fundamental Rights Impact Assessment (FRIA) before deployment. This covers bias, fairness, transparency, and accountability obligations — with documented evidence of control.

AgentTrust OS generates the behavioral evidence your FRIA needs: Trust Certify documents how the agent behaves under adversarial conditions, Trust Runtime proves controls are enforced at execution, Trust Audit provides the accountability trail required for high-risk systems.

Bias and fairness documentation
Transparency and explainability records
Human oversight evidence
Incident response and correction logs
SOC 2 Type II

LLM Deployment Trust Criteria

SOC 2 was designed for traditional software. Adding LLMs and agentic systems creates new evidence requirements under the Trust Services Criteria — especially Security, Availability, and Confidentiality.

AgentTrust OS produces SOC 2-compatible control evidence: Trust Certify provides pre-deployment testing records, Trust Runtime generates continuous control operation logs, and Trust Audit exports formatted reports your auditor can review directly.

CC6.1: Logical access controls
CC7.2: System monitoring
CC8.1: Change management
A1.2: Capacity and availability management
GDPR

Data Protection Impact Assessment for AI Agents

GDPR Article 35 requires a Data Protection Impact Assessment (DPIA) when processing is likely to result in high risk to individual rights. Agentic AI systems — which access, process, and act on personal data autonomously — trigger this requirement in most enterprise deployments.

AgentTrust OS provides the data access logs, permission evidence, and processing records your DPO needs to complete and defend a DPIA for AI agent deployments.

Article 35: DPIA requirement mapping
Data access audit logs (per session)
Purpose limitation enforcement records
Right-to-explanation evidence
Enterprise Compliance

Ready to build the compliance evidence your regulator expects?

Enterprise plans include full audit pack exports, compliance report templates, and legal review coordination.

Book a Compliance Demo →See Enterprise Pricing →