Skip to content
Kaldros
Compliance

Mapped to the frameworks you're already being asked about.

For every framework below, Kaldros ships a control mapping, an evidence pack template, and a verifier your auditor can run offline. Pick a framework to see the exact controls we answer.

Regulation (EU) 2024/1689
EU AI Act

Obligations for providers and deployers of high-risk AI systems: logging (Art. 12), human oversight (Art. 14), post-market monitoring (Art. 72), and transparency to affected persons.

View mapping →
Digital Operational Resilience Act
DORA

EU Regulation 2022/2554 for financial entities: ICT risk management, incident reporting, operational resilience testing, and third-party risk — including AI-powered ICT services.

View mapping →
Directive (EU) 2022/2555
NIS2

Cybersecurity obligations for essential and important entities: risk management, incident handling, supply-chain security, and 24-hour early warning for significant incidents.

View mapping →
AI Management System
ISO/IEC 42001

Requirements for establishing, implementing, maintaining, and improving an AI management system, with Annex A controls for data, lifecycle, monitoring, and third parties.

View mapping →
AI Risk Management Framework
NIST AI RMF 1.0

Voluntary framework from NIST for trustworthy AI: Govern, Map, Measure, Manage. Widely used as the spine of enterprise AI governance programs.

View mapping →
AICPA Trust Services Criteria
SOC 2

Type 1 and Type 2 reports on security, availability, processing integrity, confidentiality, and privacy. The baseline ask from most US enterprise buyers.

View mapping →
US 45 CFR §164
HIPAA

Safeguards for protected health information. When agents touch PHI, §164.312(b) audit controls and §164.308(a)(1)(ii)(D) log review become regulator evidence.

View mapping →
Payment Card Industry Data Security Standard
PCI DSS 4.0

When an agent touches cardholder data or authentication data, Requirement 10 (logging) and Requirement 12 (policies) apply.

View mapping →

Framework missing? We'll map it if you're willing to fund one design partner seat.