Exactly which controls SentRAI evaluates per framework, measured against the full size of each regime — published so our claims can never drift from our code. This page and the product are generated from the same manifest.
11 controls evaluated · regime size: 26 committee recommendations
All 7 sutras are evaluated on every model. Of the committee report’s 26 recommendations, 4 are enforced as explicit per-model controls (14, 16, 20, 24); several others are implemented as platform machinery rather than per-model checks (see operational list). Remaining recommendations are on the pack roadmap.
SUTRA-1 Trust is the FoundationSUTRA-2 People FirstSUTRA-3 Innovation over RestraintSUTRA-4 Fairness and EquitySUTRA-5 AccountabilitySUTRA-6 Understandable by DesignSUTRA-7 Safety, Resilience & SustainabilityREC-14 Board-approved AI policy (checked per model; gates live promotion)REC-16 Accountability chain / named owner (gates live promotion)REC-20 Bias-test evidence for MEDIUM/HIGH riskREC-24 Explainability mechanism for MEDIUM/HIGH risk14 controls evaluated · regime size: 72 playbook subcategories
14 of the playbook’s 72 subcategories are evaluated as per-model controls across all four functions (GOVERN, MAP, MEASURE, MANAGE), chosen for signal over ceremony. A verdict here means those 14 controls pass; it is an indicative posture signal, not full-framework conformance. Full subcategory coverage ships as a data-driven control pack on the current roadmap.
GOVERN-1.1 Organizational Ownership & ResponsibilityGOVERN-1.2 Board Policy AlignmentGOVERN-1.3 Audit Cadence DefinedMAP-1.1 Purpose & Use-Case DocumentationMAP-1.2 Deployment Context & Affected UsersMAP-1.3 Source & Dependency ProvenanceMEASURE-2.1 Security Red Teaming & Bias AuditingMEASURE-2.2 Performance Drift MeasurementMEASURE-2.3 Performance Benchmarks RecordedMANAGE-1.1 Human Oversight ControlsMANAGE-1.2 Fallback / Business-Continuity PlanMANAGE-1.3 Incident Reporting HygieneMANAGE-2.1 Risk Response Resourcing (Named Owner)MEASURE-3.1 Risk Tracking Mechanisms (Ledger History)14 controls evaluated · regime size: 113 articles in the Act
Fourteen articles are evaluated per model: the core high-risk provider obligations (Articles 9–15, 17), value-chain and deployer duties (Articles 25, 26, 27), post-market monitoring (Article 72), and the Article 50 transparency duty, plus a risk-tier check for minimal-risk systems. Conformity assessment, CE-marking and EU-database registration (e.g. Article 16) are process/paperwork obligations we do not implement — we deliberately do not claim them. Annex III use-case classification is on the pack roadmap.
Art-9 Risk Management SystemArt-10 Data & Data GovernanceArt-11 Technical DocumentationArt-12 Record-Keeping (Automatic Logs)Art-13 Transparency & Information to DeployersArt-14 Human Oversight GateArt-15 Accuracy, Robustness & CybersecurityArt-17 Quality Management SystemArt-25 Provider Responsibilities Along the Value ChainArt-26 Deployer Operational RecordArt-27 Fundamental Rights Impact AssessmentArt-50 Transparency & DisclosureArt-72 Post-Market MonitoringArt-Min Minimal-risk general guidelines check8 controls evaluated · regime size: 38 Annex A controls
Eight management-system checks spanning clauses 6, 7, 8, 9 and 10 plus Annex A documentation are evaluated per model. The full 38 Annex A controls are not yet individually mapped; SentRAI supports an ISO 42001 programme — it does not by itself constitute certifiable conformance. Complete Annex A mapping is on the pack roadmap.
AIMS-6.1.2 AI System Risk AssessmentAIMS-8.2 AI System Impact AssessmentAIMS-8.3 Data & Codebase GovernanceAIMS-7.2 Competence & AccountabilityAIMS-9.1 Performance Monitoring & MeasurementAIMS-9.2 Internal Audit CadenceAIMS-10.1 Nonconformity & Corrective ActionAIMS-A.6.2 AI System Documentation (Model Card)Machine-readable version: /api/v1/compliance/coverage · Source of truth: src/compliance/coverage.data.ts, updated in the same commit as any validator change. Build 1.2.5.