Enterprise / RiGi Group

Compliance

Map AI controls to applicable obligations while preserving the difference between alignment and certification.

Enterprise considerations

Make the boundary explicit.

Map AI controls to applicable obligations while preserving the difference between alignment and certification.

What to examine

Compliance in practice

01

Consider EU AI Act, NIST AI RMF, ISO/IEC 42001, GDPR, and CCPA where relevant.

02

Keep owners, control evidence, and changes traceable.

03

Get qualified legal or compliance review for claims about your specific use.

Frameworks

Map requirements without overstating status

EU AI ActNIST AI RMFISO/IEC 42001GDPRCCPA

Framework mapping is context dependent and does not establish compliance or certification.

Review questions

Before this moves into production

  1. 01What is the exact system and deployment boundary?
  2. 02Who owns the control and its exceptions?
  3. 03Which evidence proves operation for this use case?