One evidence item can support multiple frameworks. This view shows how local evidence maps to controls, findings, and remediation workflow recommendations.
Missing evidence gaps
27
Weak evidence gaps
7
Expired evidence
1
Reused evidence
5
ISO 42001
1/2 controls with evidence -1 verified evidence records
EU AI Act
0/2 controls with evidence -1 verified evidence records
NIST AI RMF
0/1 controls with evidence -0 verified evidence records
GDPR
4/5 controls with evidence -1 verified evidence records
ISO 27001
2/3 controls with evidence -0 verified evidence records
SOC 2
1/2 controls with evidence -0 verified evidence records
ISO 28000
2/5 controls with evidence -0 verified evidence records
Cloud/API Guard
2/5 controls with evidence -0 verified evidence records
A.6.2.2 needs system config
Art.14 needs policy document
Art.14 needs attestation
Art.13 needs policy document
Art.13 needs screenshot
A.8.3 needs risk assessment
Linked policy document exists, but it is not verified high-confidence evidence.
Linked scan result exists, but it is not verified high-confidence evidence.
Linked log export exists, but it is not verified high-confidence evidence.
Linked scan result exists, but it is not verified high-confidence evidence.
Linked log export exists, but it is not verified high-confidence evidence.
Linked vendor doc exists, but it is not verified high-confidence evidence.
AI Inventory export (ZAGOS Governance)
Snapshot of 14 registered AI systems with risk classification from the Governance module.
Supports 2 frameworks and 2 controls
Encryption configuration scan
TLS 1.2+ enforced; at-rest encryption enabled on primary datastore.
Supports 2 frameworks and 2 controls
Records of Processing Activities (RoPA)
Current RoPA covering 22 processing activities with lawful basis mapping.
Supports 1 frameworks and 2 controls
IAM policy export
Exported IAM bindings for review of least-privilege adherence.
Supports 3 frameworks and 3 controls
Supplier security questionnaire — Acme Logistics
Partially completed supplier questionnaire — sections on encryption missing.
Supports 1 frameworks and 2 controls
| Evidence | Frameworks | Controls | Findings | Workflows |
|---|---|---|---|---|
| AI Inventory export (ZAGOS Governance) May 20, 2026 | ISO 42001 EU AI Act | |||
| Encryption configuration scan May 25, 2026 | GDPR ISO 27001 | No linked findings | No workflow mapped | |
| Data retention policy v3 Mar 1, 2026 | GDPR | |||
| Records of Processing Activities (RoPA) Apr 10, 2026 | GDPR | No linked findings | No workflow mapped | |
| IAM policy export May 26, 2026 | ISO 27001 SOC 2 Cloud/API Guard | |||
| Supplier security questionnaire — Acme Logistics May 5, 2026 | ISO 28000 | |||
| AI provider usage log (sample) May 27, 2026 | Cloud/API Guard |