Skip to main content
Version: v0.12.4

Governance Mappings

PEAC receipts provide portable, signed evidence that maps to requirements across major AI governance frameworks. Each mapping documents which PEAC extension groups, receipt types, and verification behaviors satisfy specific framework controls.


Available Mappings

FrameworkScopeMapping
NIST AI RMFAI risk management lifecycleMap, Measure, Manage, Govern functions
EU AI ActEuropean AI regulationHigh-risk system documentation, transparency, human oversight
OWASP ASIAgent securityASI-01 through ASI-10 zero-trust controls
ISO 42001AI management systemsAnnex A controls for AI lifecycle management
IEEE 7001TransparencyAlgorithmic transparency and explainability
OECD AI PrinciplesInternational AI principlesAccountability, transparency, robustness
Singapore MGFAAFinancial AI governanceModel governance for financial institutions
AWS RAIResponsible AI practicesAWS responsible AI service mapping

Compliance Documentation

DocumentScope
GDPRData protection and privacy rights
SOC 2Trust services criteria mapping
EU AI Act (detailed)Article-level compliance mapping

How PEAC Supports Governance

PEAC does not enforce governance requirements. It provides the evidence layer:

  • Consent extension records consent basis, scope, and expiry for GDPR Article 7
  • Safety extension records guardrail evidence for EU AI Act Article 14
  • Compliance extension records framework controls and assessment results
  • Provenance extension records data lineage for NIST AI RMF Map function
  • Attribution extension records content origin for IEEE 7001 transparency
  • Offline verification provides audit-ready evidence without network dependencies