ZAGOS evaluates every control against collected evidence, linked findings, and the workflow that closes the gap. Deterministic scoring - sample workspace, no live writes.
Portfolio readiness
Weighted across 42 evaluated controls
Controls evaluated
42
Passing
21
meets evidence bar
Partial
13
needs strengthening
Failing
8
evidence gap or finding
| Framework | Control | Category | Evidence | Status | Impact | Linked finding | Workflow |
|---|---|---|---|---|---|---|---|
| ISO 42001 | ISO42001-6.1 AI management system policy Board-approved AI governance policy in force | ai governance | verified | pass | low | None | Met |
| ISO 27001 | ISO27001-A.5 Information security policies Approved and communicated security policy set | security | verified | pass | low | None | Met |
| SOC 2(Planned) | SOC2-CC1.1 Control environment Integrity and ethical-values commitment documented | operational | collected | pass | low | None | Met |
| GDPR | GDPR-30 Records of processing activities Maintained RoPA covering all processing | privacy | verified | pass | low | None | Met |
| ISO 42001 | ISO42001-9.1 AI performance monitoring Model performance and drift monitored | ai governance | collected | pass | low | None | Met |
| ISO 27001 | ISO27001-A.12 Operations security logging Event logging enabled and retained | security | verified | pass | low | None | Met |
| PCI DSS(Planned) | PCI-3.4 Stored cardholder data protection Stored account data rendered unreadable | security | collected | pass | low | None | Met |
| ISO 27001 | ISO27001-A.9 Privileged access review Periodic recertification of privileged access | security | weak | partial | medium | Privileged-access recertification overdue | Run |
| SOC 2(Planned) | SOC2-CC7.2 Continuous security monitoring Anomalies detected and triaged | operational | weak | partial | medium | Gateway monitoring evidence incomplete | Run |
| ISO 42001 | ISO42001-7.1 AI system inventory completeness Full inventory of AI systems maintained | ai governance | weak | partial | medium | AI system inventory partially complete | Run |
| EU AI Act | EUAI-9 AI risk management system Risk management process across the lifecycle | ai governance | collected | partial | medium | None | Met |
| ISO 27701(Planned) | ISO27701-7.3 Data subject rights handling DSAR process operating within SLA | privacy | weak | partial | medium | None | Met |
| GDPR | GDPR-5.1 Data retention & disposal Storage-limitation schedule applied to records | privacy | missing | fail | critical | GDPR data-retention schedule missing | Run |
| Cloud / API Guard | GUARD-3.4 API key management No unrestricted or frontend-exposed keys | cloud api | weak | fail | critical | Unrestricted API key exposure (frontend-exposed) | Run |
| EU AI Act | EUAI-14 Human oversight of AI systems Effective human oversight for high-risk models | ai governance | missing | fail | high | Human-oversight evidence missing | Run |
| ISO 28000 | ISO28000-6.2 Supplier security assurance Current supplier assurance attestations | supply chain | expired | fail | high | Supplier assurance attestation expired | Run |
Trace the evidence path
See how one evidence item can support multiple frameworks and findings.