Full transparency on compliance, security, and data handling. Verifiable evidence for every claim.
58 controls mapped, 25 implemented. Management review, post-market monitoring, bias framework.
Evidence: ISO-42001-COMPLIANCE-MAP.md
Art.13 Transparency, Art.14 Human Oversight (17 HITL gates), Art.72 Post-Market Monitoring.
AI Literacy (Art.4): mandatory since 02.02.2025
EU-only storage (Hetzner DE/FI), Art.28 DPA template, 72h breach notification, no AI training on customer data.
GOVERN + MAP + MEASURE (partial) + MANAGE. Full coverage Q3 2026.
| Control | Status | Evidence |
|---|---|---|
| Human-in-the-Loop (Art.14) | 17 Gates Active | hitl-gate-definitions.yaml |
| Risk Register (ISO §6.1) | 15 Risks, All Owned | RISK-REGISTER.yaml |
| Incident Response (Art.33) | 72h Procedure | INCIDENT-RESPONSE-PROCEDURE.md |
| AI Literacy Training (Art.4) | Level 1–3b, Certificate | training/ai-governance-compliance/ |
| Bias & Fairness (ISO A.6.1) | Framework + F-1..F-6 | AI-BIAS-FAIRNESS-FRAMEWORK.md |
| Post-Market Monitoring (Art.72) | Quarterly Review | POST-MARKET-MONITORING-PLAN.md |
| Data Protection by Design (Art.25) | EU-only, No AI Training | PII-DATA-RETENTION-POLICY.md |
| Internal Audit (ISO §9.2) | Q3 2026 | Geplant — non-blocking |
| OWASP AI Top-10 | Pen-Test Q3 2026 | Mitigated — formal test pending |