Stack Compli maps your AI controls to NIST AI RMF, ISO 42001, EU AI Act, SOC 2, and HIPAA — auto-collecting evidence from your stack so audits stop being projects.
Most GRC platforms have one row for 'AI'. We have 200, mapped to your actual model layer.
All 19 subcategories across Govern, Map, Measure, Manage — mapped to live telemetry from your model gateway.
Risk-tier classification, transparency obligations, and conformity assessment evidence collected continuously.
Annex A controls automated where automatable. Manual controls assigned, tracked, and evidence-stored.
CC1–CC9 with AI-specific control narratives that auditors actually accept. AICPA TSC mapping included.
Security Rule + AI-specific PHI handling controls. BAA-ready architecture from day one.
FFIEC, NYDFS Part 500, FedRAMP, CMMC, and HITRUST AI-specific overlays.
Straightforward answers about scope, integration, data handling, and rollout.
We extend them. If you have an existing GRC platform, we feed AI-specific evidence into it. If you don't, we can be the system of record.
Read-only API integrations with your model gateway, vector store, agent platform, and CI/CD. Evidence is timestamped, hashed, and exportable.
They've seen our evidence packs. We publish auditor-acceptance attestations for the Big 4 and the major AI-aware regional firms.
Full Annex IV technical documentation generation, conformity assessment workflow, and post-market monitoring — out of the box.