Source assurance documentation

Regulatory source mapping

This page maps capabilities visible in reviewed source to selected regulatory and assurance topics. It is a technical aid for deployment-specific assessment.

EU AI Act

Source capabilities are grouped against selected EU AI Act topics. Applicability, classification, and conformity decisions require deployment-specific legal review.

Article 9: Risk Management

Reviewed source contains policy evaluation, configurable risk thresholds, escalation paths, and Guardian evaluation paths. Continuous coverage, threshold suitability, and effectiveness in the exact deployment remain open assurance gates.

Fleet Guardian VCP

Article 12: Record-Keeping

Reviewed source contains audit logging and cryptographic integrity paths for designated decisions. Record coverage varies by integration and configuration. Completeness, retention, key custody, and independent verification of the exact deployment remain open.

Fleet

Article 14: Human Oversight

Reviewed source contains configurable approval, escalation, pause, override, and termination paths. Effective operator authority, response times, procedure coverage, and exercised audit records remain deployment-specific assurance work.

Fleet

Article 15: Accuracy, Robustness, Cybersecurity

Reviewed source contains governance checks, risk signals, and signature-verification paths. Accuracy targets, robustness testing, cybersecurity validation, monitoring coverage, and runtime effectiveness remain open for each deployment.

Guardian Fleet VCP

NIST AI Risk Management Framework

The following source-level mapping is an implementation aid. Formal attestation and maturity rating remain separate, open activities.

Govern

VCP source supports portable policy documents, version metadata, and signature verification. Organisational adoption, approval authority, and enforcement coverage remain open.

Map

Guardian and Fleet source expose risk-context and threshold concepts that can contribute to system mapping. Completeness of the deployment inventory and context classification remain open.

Measure

Source includes evaluation scores, risk observations, and audit-capable data paths. Metric validity, sampling, aggregation, coverage, and independent review remain open.

Manage

Source includes configurable pause, override, escalation, termination, and incident response paths. Operational authority, exercised response, and record completeness remain open.

GDPR support

Reviewed source includes controls intended to support selected data-protection duties. Controller decisions and deployment evidence remain open.

Data Minimisation

The source includes a local Guardian package alongside optional gateway and provider integrations. Actual inputs, outputs, metadata, recipients, logs, and retention depend on the selected configuration and require a deployment data-flow review.

Data Subject Rights

Reviewed source contains authenticated export and erasure workflows. Exact-revision deployment, complete datastore and provider coverage, retention approval, identity verification, and exercised request evidence remain open.

Legal Basis

Source contains consent and withdrawal records for designated workflows. The controller must document and approve a lawful basis for each processing purpose. Any legitimate interests assessment and consent exception remain legal-review decisions.

International Transfers

Transfer posture depends on hosting, configured providers, support access, and other recipients. The processor inventory, transfer map, data residency evidence, contractual safeguards, and transfer impact assessments remain open.

Data Protection by Design

Source includes configurable privacy policies, access controls, audit paths, and data subject workflows. Threat modelling, configuration review, necessity and proportionality decisions, and runtime exercises remain necessary.

Audit capability

Reviewed source includes audit and integrity mechanisms. Coverage, durability, signing, export, retention, and reviewer access vary by path and deployment.

Source capability examples

  • Designated governance evaluations and outcomes can emit audit events
  • Selected approval and override workflows can record decisions
  • Policy and configuration paths carry version information
  • Selected lifecycle, risk, and escalation paths expose recordable events
  • Exact event coverage and field completeness require deployment verification

Integrity mechanisms

  • Selected records and artifacts have hashing or signing paths
  • VCP source includes signature-verification support for signed policies
  • Some audit paths support chained integrity records
  • Algorithm use, key custody, coverage, and verifier exercises remain open

Export and review

  • Selected workflows expose structured export or reporting paths
  • Available filters and formats depend on the specific service
  • Regulatory reporting still requires scope and legal review
  • Deployment exercises must prove completeness and reviewer access

For questions about source assurance, accountable deployment, or public-good use: [email protected]