The control status documents the review of the evidence — it does not certify conformity.
Filter by source: All sources · AI literacy · Audit · EU AI Act · GDPR · Internal policy · Security
v0.1.0| ID | Control | Expected evidence | Risk classes | AI functions |
|---|---|---|---|---|
security_access_control |
Access control ISO 27001 A.9 (Referenz) |
Role-based access control and audit logs for sensitive objects in place. | Near high-risk — mandatory human oversight, external legal review recommended Elevated risk — human review required | All functions (not restricted) |