Frameworks

How Fideria capabilities map to the frameworks your auditors care about.

A reference mapping between Fideria capabilities and the EU AI Act, ISO/IEC 42001, NIS2, SOC 2 Common Criteria and GDPR. Informational only, not a certification statement.

Disclaimer. This mapping is provided for orientation and procurement conversations only. It does not constitute legal advice and is not a substitute for an attested audit or certification. Article and control numbering reflect the most widely-cited references and may be updated as the relevant standards evolve.

Capability-to-framework matrix

CapabilityEU AI ActISO/IEC 42001NIS2SOC 2 (CC)GDPR
AI system inventoryArt. 16, 50, provider obligationsA.6.2.6, A.6.2.7Art. 21(2)(a), asset managementCC3.2, risk identificationArt. 30, record of processing
Risk classification & assessmentArt. 6, 9, risk management systemA.5, A.6.1Art. 21(2)(b)CC3.3Art. 35, DPIA
Human oversight & approvalArt. 14A.9.2Art. 21(2)(d)CC1.4, CC2.3Art. 22, automated decisions
Data governanceArt. 10A.7Art. 21(2)(e)CC6.1, CC6.5Art. 5, 25, by design
Logging & audit trailArt. 12, 13A.8.4Art. 21(2)(g)CC7.2Art. 30, 32
Vendor & sub-processor governanceArt. 25, 28A.10Art. 21(2)(j)CC9.2Art. 28
Incident reportingArt. 73A.9.3Art. 23CC7.3, CC7.4Art. 33, 34
Transparency & disclosureArt. 13, 52A.8.2Not applicableCC2.2Art. 13, 14

How customers use this

  • Procurement & vendor review. Drop into your AI vendor assessment to show where Fideria covers obligations.
  • Internal audit. Start from a capability you need evidence for and trace to the underlying control.
  • Regulator dialogue. Use the matrix as a shared language between IT, Legal and the business.

What Fideria does not claim

  • We do not certify your AI systems on your behalf.
  • We do not replace your DPO, CISO, internal audit or legal counsel.
  • We do not currently hold SOC 2 Type II or ISO 27001 certification, see Security for the current posture and roadmap.
Need a deeper mapping?
Request the extended control mapping (CSV).
Shared on request to qualified procurement and audit teams.
Request mapping