GovernCompliance and AI governancex, accounted for

Compliance and AI governance, assessed from live signals.

Frameworks mapped to your AI controls, assessed from runtime evidence where a signal exists, with policies and evidence an auditor can check.

How it works

Specs

Compliance and AI governance, in detail

Delivery and data

Delivery
SaaS, from one login.
Isolation
Each customer runs in an isolated workspace with its own database.
Certifications
None held. Frameworks are mapped to and assessed against.

Frameworks

NIST AI RMF
Mapped to: AI controls assessed from live signals.
EU AI Act
Mapped to: AI-governance controls cross-mapped, with evidence.
ISO/IEC 42001
Mapped to: The same AI controls, with clause references.
NIS2
Cross-mapped to: AI-governance controls cross-mapped.
India DPDP
Mapped to: Consent and data governance controls.
See the frameworks

Last reviewed 6 Oct 2026

One control, many frameworksIllustrative

One control, many frameworks: AI agent inventory, owned maps to EU AI Act (Art. 49); NIST AI RMF (MAP 1.1, GOVERN 1.6); NIS2 (Art. 21(2)(d)). Mapped to and assessed against, not certified.

In short

Compliance and AI governance in ColossalX maps your controls to frameworks such as the EU AI Act, ISO/IEC 42001, NIST AI RMF and India DPDP, and assesses them from live signals where a signal exists. A control with none is not assessable, never silently passed. Policies are versioned and accepted per person, and evidence is graded and timestamped.

An auditor asks for proof that AI controls work, and the evidence is a folder of screenshots.

ColossalX collects evidence from live signals, grades it by how it was obtained and timestamps it daily.

How it works

From a live signal to an auditor's proof pack.

One AI-governance control, human oversight and the kill switch, followed from its runtime signal to the proof pack an auditor downloads.

Workflow · a control, assessed from live signalsIllustrative

01 Signal collected

Runtime evidence for the control is collected automatically and graded A.

02 Health labelled

A health label sits beside the status a person decided.

03 Gaps kept honest

A control with no runtime signal is excluded, not failed.

04 Proof pack

An auditor downloads each control with its clauses and evidence.

What you see

Evidence from live signals, graded and timestamped.

Evidence mapped to framework controls, collected by automated checks, graded by how it was obtained, timestamped and shown as valid until it expires.

  1. Switch on frameworksActivate the frameworks that apply; stop tracking one without losing its history.
  2. Assess from live signalsEvidence collects itself; a control without a signal is not assessable.
  3. Status beside healthThe status a person decided sits beside a health label from evidence.
  4. Policy and proofGenerate or upload an AI policy; auditors download a proof pack.
Read the detail, step by step4
  1. Switch on frameworks. The catalogue comes from jurisdiction packs: global, India, EU and US. Each framework carries a baseline control set, one score computed the same way on screen and in the nightly trend, and dates that show when an assessment is overdue or stale.
  2. Assess from live signals. Control validation gives each control a verdict, pass, partial, fail or not assessable, with a one-sentence reason an auditor can challenge. Controls needing a human artefact, such as a board approval, are never silently passed. Recent red-team and recovery tests count as control evidence.
  3. Status beside health. Health reads healthy, degraded, failing or untested, with the latest check, audit tests, expired evidence and open issues behind it. Marking a control not applicable needs a written reason, recorded against the person.
  4. Policy and proof. Policies are published by version with a fingerprint of the text, and each person accepts each version. Evidence is graded A to D by how it was obtained, verified by a second person, timestamped daily and withdrawn with a reason, never deleted.
The evidence vault in a demo workspace: evidence mapped to framework controls in SOC 2, ISO 42001 and India DPDP, each collected by an automated check, graded A, timestamped and shown as valid.
From a demo workspace
3notes
  1. Mapped to a control
  2. Graded and timestamped
  3. Valid, not expired

How it connectsx, accounted for

Where a control gap goes next.

A gap is owned work and a risk, not a red cell on a dashboard.

  1. A control gap opens one issue with an owner and a due date, closed only on positive evidence.

  2. An unmet AI-governance control becomes a tracked risk and closes when covered.

  3. Audits sample the same graded evidence and read the same control health.

  4. The compliance and AI-governance pillars read this same position.

Honest by design

What it does, and what it does not.

Control · not assessableIllustrative

Control · not assessable: Control Board approval of AI policy; Runtime signal None exists; Verdict Not assessable; Score Excluded, not failed; Reason Stated for the auditor. Not silently passed.

What it does not do

x, not measured

ColossalX holds no certification; mapping a framework does not confer conformity with it.

All 4 limits
  • Framework control sets are baselines, not clause-by-clause mappings of the regulatory text.
  • Jurisdiction packs ship as starting content for your counsel to review, not as legal advice.
  • RBI and CERT-In guidance is context only; neither is a mapped framework.

How we know

  • A control with no runtime signal is not assessable: excluded from the score, not failed.
  • Controls needing a human artefact, such as a board approval, are never silently passed.
  • One scoring rule serves the screen and the nightly snapshot, so the trend matches the page.
  • Evidence is withdrawn with a reason and kept; it is never deleted.

Questions

Questions buyers ask

How does ColossalX support an EU AI Act programme?

It maps an AI control catalogue to the EU AI Act alongside NIST AI RMF, ISO/IEC 42001 and NIS2, assesses those controls from your live agents and AI traffic where a runtime signal exists, and gives auditors a proof pack with clause references and evidence status. It does not classify your systems into risk tiers or confer conformity.

Is ISO/IEC 42001 mandatory?

No. ISO/IEC 42001 is a voluntary international standard for an AI management system, which organisations adopt and can have independently audited. ColossalX maps its AI controls to ISO/IEC 42001 and collects evidence for them, but holds no certification itself and cannot certify you against the standard.

How do NIST AI RMF and ISO/IEC 42001 relate?

NIST AI RMF is a voluntary US framework organised around four functions, govern, map, measure and manage; ISO/IEC 42001 is an international management-system standard. They overlap heavily, so one AI control often serves both. ColossalX maps each of its AI-governance controls to clauses in both, and to the EU AI Act and NIS2.

What does "mapped to" mean here?

Mapped to means a ColossalX control is linked to the framework clauses it supports, and assessed against means its evidence was checked against them. It is not a certification or a statement of conformity, which only an accredited body or a regulator can give. Framework control sets are baselines, not clause-by-clause mappings.

How is evidence collected and graded?

Evidence collects itself from runtime signals and can also be uploaded. Each item is graded A to D by how it was obtained: A from a ColossalX check, B pulled from your own system, C a named person's file or a verified attestation, D a screenshot or typed note. A daily manifest of the store is timestamped by a public authority.

Related

Next step

Account for your x.

See your own AI controls assessed from live signals, with what is not assessable said plainly.

  1. 01Tell us what you run
  2. 02See the four verbs on it
  3. 03Decide where to start