Report outline
The packet starts with evidence gaps, not a compliance verdict.
- System profileProduct name, intended purpose, AI task, users, deployment context, high-impact decision exposure, and whether the team is acting as provider, deployer, or both.
- Framework mapISO 42001 management-system themes, NIST AI RMF Govern/Map/Measure/Manage rows, and EU AI Act provider/deployer documentation prompts.
- Evidence registerPolicies, model notes, evaluations, risk assessment, human oversight, monitoring, incident response, logging, change control, vendor inputs, and unresolved owner assignments.
- Reviewer handoffHTML report for internal review, print-to-PDF packet for audit prep, and a separate missing-facts list for counsel or compliance.
Sample output
A report row should make the owner and source framework visible.
{
"section": "Human oversight and escalation",
"owner_role": "deployer",
"framework_hooks": ["EU AI Act Article 14", "NIST AI RMF Manage", "ISO 42001 Annex A control evidence"],
"available_evidence": ["user instructions", "support escalation note"],
"missing_evidence": ["named oversight owner", "monitoring cadence", "exception review log"],
"report_status": "draft_gap",
"reviewer_note": "Do not mark audit-ready until owner, cadence, and log evidence are attached."
}
Framework matrix
One report, three evidence lenses.
Boundary
Draft generator, not certification.
This page is an acquisition surface for ActTier's draft packet workflow. It does not certify ISO 42001 compliance, implement NIST AI RMF, make an EU AI Act conformity assessment, submit official filings, or provide legal, audit, compliance, or procurement advice.
Use the generated packet to prepare a review conversation: which evidence exists, which owner is missing, which assumptions need counsel, and which framework rows are still unsupported.