Control mappings

Answer your examiners with artifacts, not assurances.

Every governed action leaves customer-owned evidence: normalized events, policy decisions, human approvals, tamper-evident exports.

SR 11-7 · FFIEC · DORA · EU AI Act · ISO 42001 · SOC 2 — see each mapping below.

Evidence, not attestations

Eight artifacts. One system of record.

Each mapping below is built from artifacts your auditor can open and verify.

Normalized agent events

Every tool and model call, one schema across vendors.

Policy decisions

Allow, confirm, or block, recorded with the rule that fired.

Human approvals

Who approved what, with rationale and timestamps.

Append-only audit log

Hash-chained records that cannot be silently rewritten.

Intent Fidelity evidence

What was asked, bound to what the agent actually built.

Provenance queries

Audited answers to “which sessions touched this change?”

PR merge evidence

The decision record inside the PR reviewers already read.

Evidence packages

Tamper-evident exports your auditor can verify offline.

Control mapping

Where the evidence lines up

Each mapping names what the artifacts cover today and what you still validate in your environment.

SR 11-7

SR 11-7 model-risk governance

Documented intent, review, and exceptions, with risk monitored over time — not at one approval point.

Evidence produced

  • Intent Fidelity events
  • Requirement-to-change trace
  • Approvals & governance audit
  • PR merge evidence
  • Evidence package export
  • Cognitive-debt manager report
  • Agent Trust Score
  • Signed threshold sign-offs

Still to validate

Model-inventory linkage, independent validation, and model-risk owner signoff in your environment.

FFIEC

FFIEC bank technology risk

Every change traces to its agent; every sensitive action to an actor, a policy, and an outcome.

Evidence produced

  • Normalized event ledger
  • Policy decisions
  • Approval bridge records
  • Audit explorer
  • PR merge evidence & Check Runs
  • Merge-gate & branch protection
  • Connector provenance
  • Pre-execution policy blocks

Still to validate

IAM integration, live identity mapping, and a validated deployment inside your own cloud.

DORA

DORA (EU operational resilience) ICT change & third-party risk

Controlled changes, approvals that deny when review is unavailable, and a clear view of reliance on outside agents.

Evidence produced

  • Governance-path docs (local, CI, worker)
  • Portal approval bridge
  • Audit records
  • Evidence packages
  • Connector proof walkthroughs
  • Architecture boundary statement
  • Cloud-boundary docs
  • Deployment readiness checks

Still to validate

Full deployment automation, customer-environment validation, live connector proof, and resilience runbooks.

EU AI Act

EU AI Act governance concepts

Demonstrable human oversight: approvals on record, unrewritable logs, documented risk decisions.

Evidence produced

  • Human approval bridge
  • Append-only audit log
  • Intent Fidelity notes
  • Agent Run Audit
  • Policy decision reasons
  • Evidence export

Still to validate

Legal classification, role-specific human-oversight procedures, and retention-policy alignment.

ISO 42001

ISO 42001 AI management system

An AI management system needs defined roles, risk controls, monitoring, and traceable records.

Evidence produced

  • Scope & boundary documentation
  • Private registry provenance
  • Policy packs
  • Cognitive-debt report
  • Agent Trust Score
  • Audit & evidence exports
  • Control-ownership matrix

Still to validate

Formal AI management-system procedures, completed control-owner matrices, and an approved trust-score use policy.

SOC 2

SOC 2 / ISO 27001 change management

The same questions as human code: authorized by whom, tested how, traceable to what record.

Evidence produced

  • PR merge evidence
  • Approvals & audit records
  • Agent Run Audit
  • Conformance tests
  • Build & test attestations
  • Check Run & merge gate
  • Branch-protection verifier
  • Deployment attestations

Still to validate

CI and ticketing integration, and live deployment attestations.

AutoDevOps produces the evidence; the opinion belongs to your auditor. Customer-cloud validation of AutoDevOps itself is still open in every mapping above.

See the evidence on a real workflow.

Policy, approvals, audit, and a tamper-evident evidence package on the validated AWS path.