Compliance
Turn AI governance into evidence you can hand over.
MERIDVAR helps organisations operationalise governance controls and generate evidence relevant to the frameworks they answer to. Compliance itself remains your determination. MERIDVAR gives you the record to support it.
Computed, not typed in
A control status that reads the running system.
Each mapped control's status is derived from named observations of the live appliance. Each observation shows what was measured and whether it satisfied the control. Switch off a control and the status changes.
ISO/IEC 42001 · Clause 8, operational controls Partial
Three of four observations satisfied.
A control the product cannot observe is reported as uncomputed, with the reason, instead of being shown as assessed.
By territory
What is mapped, and what is supporting evidence.
Two categories. Mapped means the product ships a control mapping for the framework. Evidence means records in MERIDVAR are relevant to it, with no mapping in the product.
Europe · EMEA
| Framework | Status | What MERIDVAR contributes |
|---|---|---|
| EU AI Act | Mapped | Control mapping with computed status. The risk rules read the organisation's own EU AI Act classification of each system. |
| GDPR | Evidence | Prompt DLP on personal identifiers, data residency policy and a privacy review that records the organisation's DPIA position. |
| DORA | Evidence | Vendor due diligence, vendor approval and the register of AI systems that depend on each provider. |
| NIS2 | Evidence | Access roles, audit trail and security review records. |
United Kingdom
| Framework | Status | What MERIDVAR contributes |
|---|---|---|
| UK GDPR and Data Protection Act | Evidence | The same privacy review, DLP and residency evidence as for GDPR. |
| Regulator led AI principles | Evidence | Inventory, ownership, risk classification and approval history per AI system. |
United States
| Framework | Status | What MERIDVAR contributes |
|---|---|---|
| NIST AI RMF | Mapped | Govern, Map, Measure and Manage, each with observations computed from the running appliance. |
| State AI and privacy laws | Evidence | Records of systems whose outputs support decisions about individuals, and of human review. |
International standards
| Framework | Status | What MERIDVAR contributes |
|---|---|---|
| ISO/IEC 42001 | Mapped | Clauses 5 to 9 and the supplier controls of Annex A, with computed status. |
| ISO/IEC 27001 and SOC 2 | Evidence | Access control and logging evidence for your own programme. |
Latin America
| Framework | Status | What MERIDVAR contributes |
|---|---|---|
| Brazil LGPD | Evidence | Prompt DLP on personal identifiers, residency policy and privacy review records. |
Asia Pacific · Middle East
| Framework | Status | What MERIDVAR contributes |
|---|---|---|
| National AI governance frameworks and data protection laws | Evidence | The governance record, residency policy and evidence log apply regardless of framework. No regional framework is mapped in the product today. |
Framework summaries are drawn from public sources and are not legal advice. Your own counsel should confirm what applies to you.
EU AI Act timeline
Scoped to obligations actually on the calendar.
The Digital Omnibus on AI moved the high risk deadlines. Transparency and general purpose model obligations did not move. MERIDVAR's mapping reflects the amended timeline.
| Date | What applies |
|---|---|
| 2 February 2025 | Prohibited practices |
| 2 August 2025 | General purpose AI model obligations |
| 2 August 2026 | Transparency obligations under Article 50 |
| 2 December 2027 | High risk systems listed in Annex III |
| 2 August 2028 | High risk systems embedded in products under Annex I |
The audit package
Evidence that is explicit about its own scope.
What each package holds
- The subject's governance state
- Its classifications, reviews and approvals
- Its assessments, with the exact questionnaire versions answered
- Every evidence record about it, as stored, with hash, previous hash and signature
- The public signing keys
What it states about its scope
- Each record can be checked against its hash and signature
- Signatures are made with a key held on your appliance
- Statements are recorded as stated, with who made them and when
See MERIDVAR refuse a request on your own network.
A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.