VeritomeHelp Centre
/
Browse documentation
Using Veritome

Controls: one thing you do, credited across every framework

What a control is, how it links to requirements, why the register starts empty, and why coverage only counts verified proof.

Updated Veritome documentation

A control is something your organisation actually does — a data-processing agreement with the model vendor, a logging policy, a retraining gate. A requirement is a row of a framework: an EU AI Act obligation, an ISO/IEC 42001 clause, a GDPR article group. Controls (under Do the work) is where the two meet.

Controls is absent from the rail while the frameworks-crosswalk switch is off — the cross-mapping of ISO/IEC 42001, ISO/IEC 27001 and NIST AI RMF lands by 13 October. It is not greyed out or upsold; a module that is not ready does not advertise itself. Once on, it needs the Govern plan or above.

The register starts empty — on purpose

A requirement is not something you do, so the Annex A rows are not pre-loaded as controls; they live under Frameworks → Requirements. Your controls come from your programmes: approve a step under Obligations and its control appears here — a key like CTL-014, the step's answers as its description, the requirements it satisfies already linked, the step's evidence attached — under the headline Produced by your programmes. You can also add your own with New control. While an enabled framework has no programme yet, Ask Aria to propose a starting set drafts one control per unlinked requirement group and lands it in Aria's Inbox — nothing is minted until a person accepts it.

Annex A items are not controls: they are decided in the Statement of Applicability step, which opens pre-filled from what the programme has already implemented. Open any control to set its status (Not started · In progress · Implemented · N/A), owner, review date and notes, attach proof, and tick the requirements it satisfies, grouped by framework.

How coverage is counted

Coverage is a report, never a write. A control credits the requirements it is linked to only when it carries verified evidence — status alone does not count, and a control marked not applicable never credits. Through the seeded crosswalk (Annex A ↔ EU AI Act articles, and the other standards as they are enabled) the same proof also credits the peers of those requirements. One DPA can evidence ten requirements across three frameworks; the page shows exactly which, and through what.

The headline reads requirements · linked · covered · controls needed. "Controls needed" is the honest number: requirements nothing is linked to yet. The same figures appear per framework on Frameworks, and the requirement-by-requirement matrix is Frameworks → Coverage.

What never counts

The six statutory-reuse routes the EU AI Act grants (Art. 27(4), 26(9), 8(2), 17(3), 17(4), 26(5)) are recorded on the obligation they concern and never count toward coverage or the Statement of Applicability — they are neither a crosswalk nor a claim that two requirements are equivalent. Related references shown on a programme step are supporting links, never credit.

Which frameworks count

Binding law (the EU AI Act, GDPR) is always in scope. Voluntary frameworks count once they are enabled for your organisation. Enabling one grows the requirement set; it never touches the links you already made.