Audit-ready evidence
Bring a dated AI-tool register to your next audit
Evidence, not certification. Choose the framework you are being assessed against and see exactly which controls the register feeds — and which ones it does not.
ISO/IEC 42001
SOC 2
NIST AI RMF
EU AI Act
Cyber-insurance
What it asks
Document AI resources, tooling, versions, and third-party suppliers inside the management-system scope.
Honest boundary
One inventory input. An independent assessor evaluates the wider management system.
rubricVersion=3 · kbSnapshotVersion=2026-07-27.2 · mapping=cm-6
What it asks
Maintain asset and vendor inventories under the existing CC6.1 and CC9 criteria.
Honest boundary
One evidence source. Access, ownership, review and ongoing operation remain organizational duties.
rubricVersion=3 · kbSnapshotVersion=2026-07-27.2 · mapping=cm-6
What it asks
Operate an AI-system inventory mechanism under GOVERN 1.6 and record context under MAP 1.1.
Honest boundary
Inventory evidence only. Risk measurement and treatment stay outside this surface.
rubricVersion=3 · kbSnapshotVersion=2026-07-27.2 · mapping=cm-6
What it asks
Scope Article 4 AI-literacy work around the AI tools staff actually use.
Honest boundary
A governance input, not a deadline or penalty claim. Heavier deployer duties depend on the use case.
rubricVersion=3 · kbSnapshotVersion=2026-07-27.2 · mapping=cm-6
What it asks
Answer inventory and usage-review questions with a current, supportable artifact.
Honest boundary
Does not change policy exclusions or replace written AI-use policy and staff education records.
rubricVersion=3 · kbSnapshotVersion=2026-07-27.2 · mapping=cm-6
What the assessor actually receives
Evidence Register
Dated rows grouped at the control level, each with its source.
Framework report
Control-by-control mapping with the boundary stated per row.
Evidence JSON
Machine-readable, versioned, diffable between snapshots.
JSON
AI-BOM
Bill of materials for the AI tooling found on the fleet.
CycloneDX
Anatomy of an export
What travels with the evidence
In every export
Not yet
No single run identifier
An export is dated and hashed per device, but the export as a whole has no stable ID to cite in an audit file. You reference it by date today.
Exports are recomputed, not pinned
Asking for the same period twice re-reads the current registers rather than replaying a frozen artifact. Keep the file you were given; do not assume it can be regenerated byte-for-byte.
Both are on the roadmap. Neither is claimed as shipped anywhere on this site.
Deterministic measurement
Reproducible, versioned, and honest about the window
observed used
Seen running inside a covered window.
not observed in window
Not the same claim as unused.
unattributable
Counted without a defensible match.
coverage insufficient
A finding about the evidence, not the asset.
Scan → Evidence Register → Framework Mapping → Report + Evidence JSON + AI-BOM → Control-level coverage
Getting evidence into your GRC tool
Working today
Export and upload
keeprails report --evidence Produces the sanitized evidence package you attach in Vanta, Drata, or a shared drive.
In pilot
Native push
Direct Vanta and Drata delivery is in pilot with design-partner accounts. Ask us for the current status.
Compliance questions
Is this an independent assessment?
No. It is evidence, not certification. KeepRails produces a dated inventory artifact; independent assessors evaluate the wider program.
What makes the register audit-ready?
Each artifact is source-attributed, timestamped, deterministic, labeled observed or inferred, and integrity-hashed.
What leaves the machine?
Nothing during the local scan. Only sanitized tool-identity metadata can be shared, and only after you pair a device into a signed-up org; code, prompts, config content, and secrets stay local.