The controls matrix

Each control below names the obligations it answers and the record it produces. Most records are items in the evidence pack. The rest stay in your repository or your CI, and an auditor can ask for them.

§01

How an audit grades each control

An audit gives every control one of four grades, listed here in the order a report sorts them, worst first.

Fail
The control is missing, or it exists and cannot produce its evidence.
Partial
The control exists, but it is not yet running in production, its evidence has a gap for the period, or an exception is open.
Pass
The control runs in production, and its evidence for the last full period can be exported today.
Not applicable
The obligation does not bind you for this system, and the reason is written down.

§02

The twenty-one controls

ControlWhat it does
GD-01

Every paid model call is metered through one function, and the ledger is the only record of spend

Obligations
Art. 12, Art. 26(6), GDPR Art. 5(2), DORA Art. 9, ISO/IEC 42001 A.6, ISO/IEC 42001 A.4, NIST AI RMF MEASURE, PRA SS1/23 Principle 2
Record produced
Ledger extract: time, subject, model version, estimated and actual cost, outcome
Evidence
Evidence pack item 1: Ledger extract
GD-02

An append-only audit log, hash-chained

Obligations
Art. 12, Art. 26(6), Art. 11 + Annex IV, GDPR Art. 5(2), GDPR Art. 30, DORA Art. 9, DORA Art. 17, ISO/IEC 42001 A.6, NIST AI RMF GOVERN, PRA SS1/23 Principle 5
Record produced
Chain verification output for the period
Evidence
Evidence pack item 2: Audit log integrity proof
GD-03

A human approves before any consequential output leaves the system

Obligations
Art. 14, Art. 26(2), GDPR Art. 22, ISO/IEC 42001 A.9, ISO/IEC 42001 A.6, NIST AI RMF MANAGE, PRA SS1/23 Principle 5
Record produced
Approval log: who, when, what they saw, what they decided
Evidence
Evidence pack item 3: Approval log
GD-04

No message, document or notice leaves the organisation until a person sends it

Obligations
Art. 14, Art. 26(2), Art. 26(11), GDPR Art. 22, ISO/IEC 42001 A.9, NIST AI RMF MANAGE
Record produced
Gate log: each item held, released or rejected
Evidence
Evidence pack item 3: Approval log
GD-05

A killswitch read on every paid call, tested by breaking it on purpose

Obligations
Art. 14(4)(e), Art. 26(5), Art. 73, DORA Art. 11, ISO/IEC 42001 A.6, NIST AI RMF MANAGE 2.4, PRA SS1/23 Principle 5
Record produced
Drill record: date, operator, what stopped, recovery time, the safe-state behaviour observed
Evidence
Evidence pack item 4: Killswitch test record
GD-06

Every model response is checked against a versioned schema, and a rejection is logged rather than quietly corrected

Obligations
Art. 15, Art. 26(4), ISO/IEC 42001 A.6, NIST AI RMF MEASURE, PRA SS1/23 Principle 2
Record produced
Schema registry with version history, and reject counts for the period
Evidence
Evidence pack item 8: Schema registry
GD-07

A ceiling on each unit of work, and rolling 24-hour ceilings for each organisation and for the whole system

Obligations
Art. 9, DORA Art. 9, DORA Art. 10, ISO/IEC 42001 A.6, NIST AI RMF MANAGE
Record produced
Ceiling configuration under version control, and every breach
Evidence
Evidence pack item 5: Ceiling configuration and breaches
GD-08

Personal data is hashed or left out before anything is logged, under a written list of what may be kept

Obligations
Art. 26(4), GDPR Art. 25, GDPR Art. 32, GDPR Art. 5(1)(c), NIST AI RMF GOVERN, ICO guidance on AI and data protection
Record produced
The redaction rules in force, and a test showing no raw personal data reaches a log
Evidence
Evidence pack item 9: Redaction rules and test results
GD-09

A tenant boundary, with egress only to named providers

Obligations
Art. 15, GDPR Art. 32, GDPR Art. 44 to 49, DORA Art. 9, DORA Art. 28, DORA Art. 29, ISO/IEC 42001 A.10, ISO/IEC 42001 A.4, NIST AI RMF GOVERN, PRA SS1/23 Principle 4
Record produced
The provider list, and the code test showing no unmetered egress
Evidence
Evidence pack item 7: Provider list and egress proof
GD-10

Each part of the system checks its own settings when it starts, and no secret crosses from one part to another

Obligations
Art. 15, GDPR Art. 32, DORA Art. 9, ISO/IEC 42001 A.4, ISO/IEC 42001 A.6, NIST AI RMF GOVERN
Record produced
The settings schema for each part, and the smoke test output
Evidence
Held outside the pack, in the client's repository (the schema) and CI (the smoke test output), and available on request
GD-11

Each component's model is pinned to a version, and every change is dated with its reason

Obligations
Art. 11 + Annex IV, Art. 13, Art. 72, ISO/IEC 42001 A.6, NIST AI RMF MAP, PRA SS1/23 Principle 1, PRA SS1/23 Principle 2
Record produced
Model version manifest: which model answered which component, and when it changed
Evidence
Evidence pack item 6: Model version manifest
GD-12

Model providers are reachable from one fenced part of the code, and a test proves no call goes around the meter

Obligations
Art. 15, DORA Art. 28, DORA Art. 29, ISO/IEC 42001 A.10, NIST AI RMF GOVERN
Record produced
The provider list and the policy test output
Evidence
Evidence pack item 7: Provider list and egress proof
GD-13

A test suite with fixed thresholds must pass before every merge, and CI runs the same checks

Obligations
Art. 9, Art. 17, ISO/IEC 42001 A.6, NIST AI RMF MEASURE, PRA SS1/23 Principle 3
Record produced
CI history for the period
Evidence
Held outside the pack, in the client's CI run history, and available on request
GD-14

An append-only decisions log, where a correction keeps the line it replaces

Obligations
Art. 11 + Annex IV, Art. 18, Art. 72, ISO/IEC 42001 A.6, NIST AI RMF GOVERN, PRA SS1/23 Principle 5
Record produced
The decisions log
Evidence
Held outside the pack, in the client's repository, where the log itself is kept, and available on request
GD-15

Every control in the matrix must point at evidence that exists, or the build fails

Obligations
Art. 17, GDPR Art. 5(2), ISO/IEC 42001 A.6, NIST AI RMF GOVERN
Record produced
The matrix, the register of what is not covered, and the build check over both
Evidence
Evidence pack item 11: The controls matrix
Evidence pack item 12: The not-covered register
Held outside the pack, in the client's CI run history, and available on request
GD-16

Each outside data source has a written contract, and every record says where it came from

Obligations
Art. 13, Art. 26(11), Art. 50, Art. 50(2), GDPR Art. 13, GDPR Art. 14, DORA Art. 30, ISO/IEC 42001 A.8, NIST AI RMF GOVERN
Record produced
The contract for each source, versioned with the code
Evidence
Held outside the pack, in the client's repository, beside the code it describes, and available on request
GD-17

Incidents are recorded as typed events in the audit log, with a written path to your incident process and to the authorities where required

Obligations
Art. 26(5), Art. 73, GDPR Art. 33, DORA Art. 17, DORA Art. 19, ISO/IEC 42001 A.8, NIST AI RMF MANAGE, PRA SS1/23 Principle 5
Record produced
Incident register for the period, open and closed
Evidence
Evidence pack item 10: Incident log
GD-18

One script exports the evidence pack

Obligations
Art. 26(12), Art. 11 + Annex IV, GDPR Art. 5(2), DORA Art. 30, ISO/IEC 42001 A.8, NIST AI RMF GOVERN, PRA SS1/23 Principle 5
Record produced
The pack: twelve items in a dated folder, generated rather than written
Evidence
Every item in the evidence pack
GD-19

Webhooks and ingest jobs can be replayed safely, and a replay test runs in CI

Obligations
Art. 15, DORA Art. 9, ISO/IEC 42001 A.6, NIST AI RMF MEASURE
Record produced
Replay test output
Evidence
Held outside the pack, in the client's CI run history, and available on request
GD-20

Any pipeline can run end to end without a paid call, booking each step at zero cost

Obligations
Art. 9, ISO/IEC 42001 A.6, NIST AI RMF MEASURE, PRA SS1/23 Principle 3
Record produced
Ledger rows for each dry run, at zero actual cost
Evidence
Evidence pack item 1: Ledger extract
GD-21

An agent's tool, API and MCP calls get the same controls: metered, logged, gated where it matters, and stoppable

Obligations
Art. 3, Art. 12, Art. 15, Art. 25, ISO/IEC 42001 A.6, NIST AI RMF MANAGE, NIST AI RMF MANAGE 2.4, NIST AI RMF MEASURE
Record produced
Action log rows per tool call, with the same fields as the ledger, and the gate decision where a call is consequential
Evidence
Evidence pack item 1: Ledger extract
Evidence pack item 3: Approval log

§03

Book a scoping call

Thirty minutes on one system: what it does, who is asking about it, and which engagement fits. Nothing to prepare. For firms in the UK and Europe.