Platform
Platform overview Six modules from discovery to evidence on one governance backbone. AI Inventory & Discovery Make shadow AI usage visible. Use-case Intake & Triage One-page intake, 5 business-day SLA. Risk & Autonomy Tiering Green / Amber / Red decision model. AI Gateway & Policy All model traffic through one control point. Audit Trail & Evidence Audit-ready, tamper-evident record.
Solutions
AI Center of Excellence A single operating console for the hub team. CISO & Security Data-leak control and kill switch. Legal & Compliance Collect regulatory evidence automatically. Executive Leadership Measure the return on AI investment. Business Units (Spoke) Make the approved path the easy path. Industries Manufacturing, finance, health and public sector.
Compliance
EU AI Act Obligation timeline and readiness map. ISO/IEC 42001 AI management system (AIMS) controls. NIST AI RMF Govern, Map, Measure, Manage mapping. KVKK & GDPR Personal data and DPIA linkage. Security & Architecture Tenant isolation, SSO, MFA, data residency. Control matrix Which module satisfies which clause.
Framework
Resources
About Contact Customer login Request a demo
Compliance

Four frameworks, one control set.

The EU AI Act, ISO/IEC 42001, NIST AI RMF and data protection law speak different languages but ask the same thing: who decided what, on what basis, and how do you prove it?

EU AI Act

Regulation (EU) 2024/1689 and the timeline that concerns you

The Regulation binds not only model developers but also deployers who use an AI system under their own authority. Scope depends less on where you are established than on where the output is used.

  • Penalties for prohibited practices reach up to €35 million or 7% of total worldwide annual turnover, whichever is higher.
  • Other breaches are capped at €15 million or 3%; supplying incorrect or misleading information at €7.5 million or 1%.
  • High-risk systems require a risk management system, technical documentation, logging and human oversight.
  • Deployers must follow the instructions for use, ensure human oversight and report serious incidents.
  1. 1 Aug 2024

    Entry into force

    The Regulation entered into force.

  2. 2 Feb 2025

    Prohibitions and AI literacy

    Unacceptable-risk practices became prohibited; the AI literacy obligation for staff began.

  3. 2 Aug 2025

    GPAI and enforcement structure

    Obligations for general-purpose AI models and the competent authority / penalty regime took effect.

  4. 2 Aug 2026

    General application

    Most of the Regulation applies, including Annex III high-risk systems.

  5. 2 Aug 2027

    Annex I products

    The transition period ends for high-risk systems covered by product safety legislation.

Unacceptable risk

Practices such as social scoring and manipulative techniques are prohibited. AIZEC flags and blocks such usage in the inventory.

High risk

Systems producing decisions in areas such as employment, credit and education. In AIZEC these map directly to the red tier.

Limited risk

Systems with transparency obligations (for example chatbots). User disclosure is linked to the inventory record.

Minimal risk

Free to use. In AIZEC this maps to the green tier: recording and logging are sufficient.

This page is informational and is not legal advice. The scope of your obligations depends on the role of the system and its context of use.

ISO/IEC 42001:2023

Record infrastructure ready for an AI management system (AIMS)

ISO/IEC 42001 is the first management system standard for artificial intelligence. It does for AI governance what ISO 27001 does for information security: policy, roles, risk and a continual improvement cycle.

  • Defining policy and objectives and assigning roles and responsibilities.
  • A repeatable process to identify, assess and treat AI risks.
  • Documented information obligations across the system lifecycle.
  • Evidence of internal audit, management review and continual improvement.

What evidence does AIZEC produce?

Some of the records an ISO 42001 auditor will ask for are produced as a by-product of daily operations. The list below shows which ones.

  • Role and responsibility matrix (RBAC records)
  • Risk assessment records and test results
  • Decision rationales and approval chains
  • Incident and revocation (kill switch) records
  • Monthly management report snapshots
NIST AI RMF 1.0

Govern, Map, Measure, Manage mapping

The four functions of the NIST framework map to concrete modules in the platform.

Govern

Policy, roles and accountability. In AIZEC: RBAC, CoE ownership and the mandatory decision rationale.

Map

Establishing context and risks. In AIZEC: inventory, use-case intake and data sensitivity flags.

Measure

Measuring risk and performance. In AIZEC: risk assessment, DLP checks and business impact metrics.

Manage

Responding to and monitoring risk. In AIZEC: approval flows, gateway monitoring and the kill switch.

GDPR & Turkish DPL 6698

Personal data cannot be separated from the AI inventory.

When an AI use-case processes personal data, AI governance and data protection obligations become two sides of the same record.

  • Data sensitivity and internal-data usage are flagged separately in the inventory.
  • Use-cases involving personal data are automatically escalated during tiering.
  • Decision records provide input into data protection impact assessment (DPIA) processes.
  • The provider inventory makes processor relationships easier to track.

Data minimisation in practice

AIZEC records which data category a use-case touches. That way the question "what data did the model see?" is answered at intake, not after an incident.

Control matrix

Which module satisfies which obligation?

The same record serves as evidence across multiple frameworks. Produce it once, present it in every audit.

Obligation EU AI Act ISO/IEC 42001 NIST AI RMF AIZEC module
Risk classification Risk categories Risk assessment Map Risk & Autonomy Tiering
Inventory and scope System records Context definition Map AI Inventory & Discovery
Human oversight Art. 14 human oversight Operational control Manage Approval flows
Record-keeping Automatic logging Documented information Measure Audit Trail & Evidence
Incident response Serious incident reporting Improvement Manage Kill switch & revocation
Management review Quality management system Management review Govern Monthly report

The matrix is an orientation aid showing how obligations map to the platform; it is not a declaration of legal conformity.

FAQ

Compliance questions

The Regulation can cover providers and deployers established in third countries where the output of the AI system is used within the EU. If you have customers, subsidiaries or operations in the EU, a scoping assessment is needed. That assessment belongs with your legal team.

No, and you should distrust any product that claims otherwise. AIZEC provides the process, decision and evidence infrastructure that compliance requires; interpreting obligations and bearing final responsibility remain with your organisation.

In practice the hardest part is reconstructing records after the fact. Turning on inventory and decision records as early as possible removes the need to reconstruct records retroactively during audit preparation.

Classification, approval, rejection and revocation decisions are held in the audit trail with actor, rationale and timestamp, and can be exported. Monthly report snapshots serve as periodic evidence.

Let us map your compliance gaps together.

We will assess your current AI usage against four frameworks and produce a prioritised remediation plan.

The information on this page is general in nature and does not constitute legal advice.