Governance
Compliance should be mapped to evidence, owners and systems.
The platform adds a control/evidence register and AI-use-case inventory. It is a readiness framework, not a claim of certification or legal advice.
| Control area | Architecture | Evidence / owner | Claim |
|---|---|---|---|
| Privacy / data rights | Data-rights requests, retention policies, exports and access controls | Request logs, policy versions, access audit | Readiness architecture only |
| Safeguarding | Restricted case workflow, controlled messaging and escalation | Case/action logs and role evidence | No external certification claimed |
| AI governance | Use-case register, risk assessment, evaluation, provenance, approvals | Evaluation results, approval records and model registry | Operational readiness |
| Security | MFA-ready identity, session logs, incidents, backups, restore tests | Control evidence and test records | No SOC/ISO certification claimed |
| Payments | Provider tokens remain external; event/reconciliation architecture | Provider/webhook and reconciliation records | Provider compliance remains provider-specific |
Regulatory snapshot — 11 September 2026: the EU AI Act is generally applicable from 2 August 2026. Under the current EU implementation timeline, certain high-risk use cases in education and other Annex III areas are scheduled to apply from 2 December 2027. Requirements and classification depend on the exact use case, so this page should be reviewed against current official guidance before production reliance.