← SentRAI

SR-DL · Coverage disclosure

Framework coverage disclosure

Exactly which controls SentRAI evaluates per framework, measured against the full size of each regime — published so our claims can never drift from our code. This page and the product are generated from the same manifest.

Why we publish this. A governance product that overstates its own coverage invites exactly the audit it sells protection from. Where coverage is partial we say so, say what a verdict means, and say what is on the roadmap.

RBI FREE-AI (7 Sutras) India

DEEP COVERAGE

11 controls evaluated · regime size: 26 committee recommendations

All 7 sutras are evaluated on every model. Of the committee report’s 26 recommendations, 4 are enforced as explicit per-model controls (14, 16, 20, 24); several others are implemented as platform machinery rather than per-model checks (see operational list). Remaining recommendations are on the pack roadmap.

Show the 11 evaluated controls
  • SUTRA-1 Trust is the Foundation
  • SUTRA-2 People First
  • SUTRA-3 Innovation over Restraint
  • SUTRA-4 Fairness and Equity
  • SUTRA-5 Accountability
  • SUTRA-6 Understandable by Design
  • SUTRA-7 Safety, Resilience & Sustainability
  • REC-14 Board-approved AI policy (checked per model; gates live promotion)
  • REC-16 Accountability chain / named owner (gates live promotion)
  • REC-20 Bias-test evidence for MEDIUM/HIGH risk
  • REC-24 Explainability mechanism for MEDIUM/HIGH risk
Platform machinery implementing this regime
  • Incident reporting with severity-driven regulatory deadline clocks
  • Consumer grievance tracking per model
  • Lifecycle gating: ungoverned models cannot be promoted to live stages
  • Statistical drift monitoring with circuit breaker and business-continuity fallback
  • Append-only model ledger and PII-masked audit trail

NIST AI RMF 1.0 United States

PARTIAL COVERAGE

14 controls evaluated · regime size: 72 playbook subcategories

14 of the playbook’s 72 subcategories are evaluated as per-model controls across all four functions (GOVERN, MAP, MEASURE, MANAGE), chosen for signal over ceremony. A verdict here means those 14 controls pass; it is an indicative posture signal, not full-framework conformance. Full subcategory coverage ships as a data-driven control pack on the current roadmap.

Show the 14 evaluated controls
  • GOVERN-1.1 Organizational Ownership & Responsibility
  • GOVERN-1.2 Board Policy Alignment
  • GOVERN-1.3 Audit Cadence Defined
  • MAP-1.1 Purpose & Use-Case Documentation
  • MAP-1.2 Deployment Context & Affected Users
  • MAP-1.3 Source & Dependency Provenance
  • MEASURE-2.1 Security Red Teaming & Bias Auditing
  • MEASURE-2.2 Performance Drift Measurement
  • MEASURE-2.3 Performance Benchmarks Recorded
  • MANAGE-1.1 Human Oversight Controls
  • MANAGE-1.2 Fallback / Business-Continuity Plan
  • MANAGE-1.3 Incident Reporting Hygiene
  • MANAGE-2.1 Risk Response Resourcing (Named Owner)
  • MEASURE-3.1 Risk Tracking Mechanisms (Ledger History)

EU AI Act European Union

PARTIAL COVERAGE

14 controls evaluated · regime size: 113 articles in the Act

Fourteen articles are evaluated per model: the core high-risk provider obligations (Articles 9–15, 17), value-chain and deployer duties (Articles 25, 26, 27), post-market monitoring (Article 72), and the Article 50 transparency duty, plus a risk-tier check for minimal-risk systems. Conformity assessment, CE-marking and EU-database registration (e.g. Article 16) are process/paperwork obligations we do not implement — we deliberately do not claim them. Annex III use-case classification is on the pack roadmap.

Show the 14 evaluated controls
  • Art-9 Risk Management System
  • Art-10 Data & Data Governance
  • Art-11 Technical Documentation
  • Art-12 Record-Keeping (Automatic Logs)
  • Art-13 Transparency & Information to Deployers
  • Art-14 Human Oversight Gate
  • Art-15 Accuracy, Robustness & Cybersecurity
  • Art-17 Quality Management System
  • Art-25 Provider Responsibilities Along the Value Chain
  • Art-26 Deployer Operational Record
  • Art-27 Fundamental Rights Impact Assessment
  • Art-50 Transparency & Disclosure
  • Art-72 Post-Market Monitoring
  • Art-Min Minimal-risk general guidelines check

ISO/IEC 42001 International

PARTIAL COVERAGE

8 controls evaluated · regime size: 38 Annex A controls

Eight management-system checks spanning clauses 6, 7, 8, 9 and 10 plus Annex A documentation are evaluated per model. The full 38 Annex A controls are not yet individually mapped; SentRAI supports an ISO 42001 programme — it does not by itself constitute certifiable conformance. Complete Annex A mapping is on the pack roadmap.

Show the 8 evaluated controls
  • AIMS-6.1.2 AI System Risk Assessment
  • AIMS-8.2 AI System Impact Assessment
  • AIMS-8.3 Data & Codebase Governance
  • AIMS-7.2 Competence & Accountability
  • AIMS-9.1 Performance Monitoring & Measurement
  • AIMS-9.2 Internal Audit Cadence
  • AIMS-10.1 Nonconformity & Corrective Action
  • AIMS-A.6.2 AI System Documentation (Model Card)

Machine-readable version: /api/v1/compliance/coverage · Source of truth: src/compliance/coverage.data.ts, updated in the same commit as any validator change. Build 1.2.5.