Live workspace. Durable storage schema active — live connectors, billing, and AI automation are activation-gated.View Activation Status
Signed out
Sign in as the approved QA user before running RLS-bound QA.
Sign in
Control matrix

Framework → control → evidence readiness

ZAGOS evaluates every control against collected evidence, linked findings, and the workflow that closes the gap. Deterministic scoring - sample workspace, no live writes.

64Readiness

Portfolio readiness

Weighted across 42 evaluated controls

Controls evaluated

42

Passing

21

meets evidence bar

Partial

13

needs strengthening

Failing

8

evidence gap or finding

Legend:Pass — evidence verifiedPartial — weak / aging evidenceFail — missing evidence or open findingPlanned/future frameworks are visible for roadmap transparency.
Control matrix
Representative sample of the 42 evaluated controls (enterprise portfolio view) — required evidence, actual status, finding linkage, and recommended workflow. Showing 16 of 16 sampled controls.
FrameworkControlCategoryEvidenceStatusImpactLinked findingWorkflow
ISO 42001
ISO42001-6.1
AI management system policy
Board-approved AI governance policy in force
ai governance
verified
pass
low
NoneMet
ISO 27001
ISO27001-A.5
Information security policies
Approved and communicated security policy set
security
verified
pass
low
NoneMet
SOC 2(Planned)
SOC2-CC1.1
Control environment
Integrity and ethical-values commitment documented
operational
collected
pass
low
NoneMet
GDPR
GDPR-30
Records of processing activities
Maintained RoPA covering all processing
privacy
verified
pass
low
NoneMet
ISO 42001
ISO42001-9.1
AI performance monitoring
Model performance and drift monitored
ai governance
collected
pass
low
NoneMet
ISO 27001
ISO27001-A.12
Operations security logging
Event logging enabled and retained
security
verified
pass
low
NoneMet
PCI DSS(Planned)
PCI-3.4
Stored cardholder data protection
Stored account data rendered unreadable
security
collected
pass
low
NoneMet
ISO 27001
ISO27001-A.9
Privileged access review
Periodic recertification of privileged access
security
weak
partial
medium
Privileged-access recertification overdue Run
SOC 2(Planned)
SOC2-CC7.2
Continuous security monitoring
Anomalies detected and triaged
operational
weak
partial
medium
Gateway monitoring evidence incomplete Run
ISO 42001
ISO42001-7.1
AI system inventory completeness
Full inventory of AI systems maintained
ai governance
weak
partial
medium
AI system inventory partially complete Run
EU AI Act
EUAI-9
AI risk management system
Risk management process across the lifecycle
ai governance
collected
partial
medium
NoneMet
ISO 27701(Planned)
ISO27701-7.3
Data subject rights handling
DSAR process operating within SLA
privacy
weak
partial
medium
NoneMet
GDPR
GDPR-5.1
Data retention & disposal
Storage-limitation schedule applied to records
privacy
missing
fail
critical
GDPR data-retention schedule missing Run
Cloud / API Guard
GUARD-3.4
API key management
No unrestricted or frontend-exposed keys
cloud api
weak
fail
critical
Unrestricted API key exposure (frontend-exposed) Run
EU AI Act
EUAI-14
Human oversight of AI systems
Effective human oversight for high-risk models
ai governance
missing
fail
high
Human-oversight evidence missing Run
ISO 28000
ISO28000-6.2
Supplier security assurance
Current supplier assurance attestations
supply chain
expired
fail
high
Supplier assurance attestation expired Run

Trace the evidence path

See how one evidence item can support multiple frameworks and findings.

View traceability