Compliance

Turn AI governance into evidence you can hand over.

MERIDVAR helps organisations operationalise governance controls and generate evidence relevant to the frameworks they answer to. Compliance itself remains your determination. MERIDVAR gives you the record to support it.

Computed, not typed in

A control status that reads the running system.

Each mapped control's status is derived from named observations of the live appliance. Each observation shows what was measured and whether it satisfied the control. Switch off a control and the status changes.

CONTROL EVIDENCEILLUSTRATIVE

ISO/IEC 42001 · Clause 8, operational controls Partial

Three of four observations satisfied.

Prompt DLP blocking categories6Satisfied
Threat detection enforcing on live trafficyesSatisfied
Teams with an enforced residency policy0 of 4Not satisfied
Vendor risk requirements enforced at the callyesSatisfied

A control the product cannot observe is reported as uncomputed, with the reason, instead of being shown as assessed.

By territory

What is mapped, and what is supporting evidence.

Two categories. Mapped means the product ships a control mapping for the framework. Evidence means records in MERIDVAR are relevant to it, with no mapping in the product.

Europe · EMEA

FrameworkStatusWhat MERIDVAR contributes
EU AI ActMappedControl mapping with computed status. The risk rules read the organisation's own EU AI Act classification of each system.
GDPREvidencePrompt DLP on personal identifiers, data residency policy and a privacy review that records the organisation's DPIA position.
DORAEvidenceVendor due diligence, vendor approval and the register of AI systems that depend on each provider.
NIS2EvidenceAccess roles, audit trail and security review records.

United Kingdom

FrameworkStatusWhat MERIDVAR contributes
UK GDPR and Data Protection ActEvidenceThe same privacy review, DLP and residency evidence as for GDPR.
Regulator led AI principlesEvidenceInventory, ownership, risk classification and approval history per AI system.

United States

FrameworkStatusWhat MERIDVAR contributes
NIST AI RMFMappedGovern, Map, Measure and Manage, each with observations computed from the running appliance.
State AI and privacy lawsEvidenceRecords of systems whose outputs support decisions about individuals, and of human review.

International standards

FrameworkStatusWhat MERIDVAR contributes
ISO/IEC 42001MappedClauses 5 to 9 and the supplier controls of Annex A, with computed status.
ISO/IEC 27001 and SOC 2EvidenceAccess control and logging evidence for your own programme.

Latin America

FrameworkStatusWhat MERIDVAR contributes
Brazil LGPDEvidencePrompt DLP on personal identifiers, residency policy and privacy review records.

Asia Pacific · Middle East

FrameworkStatusWhat MERIDVAR contributes
National AI governance frameworks and data protection lawsEvidenceThe governance record, residency policy and evidence log apply regardless of framework. No regional framework is mapped in the product today.

Framework summaries are drawn from public sources and are not legal advice. Your own counsel should confirm what applies to you.

EU AI Act timeline

Scoped to obligations actually on the calendar.

The Digital Omnibus on AI moved the high risk deadlines. Transparency and general purpose model obligations did not move. MERIDVAR's mapping reflects the amended timeline.

DateWhat applies
2 February 2025Prohibited practices
2 August 2025General purpose AI model obligations
2 August 2026Transparency obligations under Article 50
2 December 2027High risk systems listed in Annex III
2 August 2028High risk systems embedded in products under Annex I

The audit package

Evidence that is explicit about its own scope.

What each package holds

  • The subject's governance state
  • Its classifications, reviews and approvals
  • Its assessments, with the exact questionnaire versions answered
  • Every evidence record about it, as stored, with hash, previous hash and signature
  • The public signing keys

What it states about its scope

  • Each record can be checked against its hash and signature
  • Signatures are made with a key held on your appliance
  • Statements are recorded as stated, with who made them and when

See MERIDVAR refuse a request on your own network.

A working session with the founder. We install the appliance with you, route a test request and walk through the evidence it leaves behind.