AI Governance: 30 Key Questions, 8 Regulatory Frameworks, 1 Layer of Evidence
+ Evidence Layer V-PROOF
's stress test questions
provides evidence
complements
frameworks define the WHAT.
the HOW and the WHEN.
Declarative compliance
vs. verifiable compliance.
| 30 Questions on AI Governance | POPIAProtection of Personal Information Act (ZA) |
ISO 42001AI Management s System Standard |
EU AI ActRegulation (EU) 2024/1689 |
NIST AI RMFAI Risk Management Framework (U.S.) |
PCI DSSPayment Card Industry Data Security Standard |
HIPAAHealth Insurance Portability Act (U.S.) |
ISO 27001 , Information Security Management System |
ISO 27701Privacy Information Management System |
V-PROOF
's cryptographic evidence, verifiable at the source ◈ EU-Native
|
|---|---|---|---|---|---|---|---|---|---|
| Data, Privacy, and Data Minimization | |||||||||
| Is personal data processed lawfully? | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Are privacy and data minimization being applied? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Are the data sources accurate and appropriate for the purpose? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Are there data retention and disposal policies? | ✓ | ✓ | ✓ | ✓ |
~
Prior obligation
of the AI operator. V-PROOF seals the resulting evidence. |
||||
| Transparency, Explainability, and Rights | |||||||||
| Is the AI system transparent and explainable? | ✓ | ✓ | ✓ | ✓ | |||||
| Are individuals well-informed and able to exercise their rights? | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Has the system been evaluated in terms of bias and fairness? | ✓ | ✓ | ✓ |
~
Prior obligation
of the AI operator. V-PROOF seals the resulting evidence. |
|||||
| Human Oversight and Governance | |||||||||
| Is there a governance and accountability structure in place? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Is human oversight built in where it should be? | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Is there a change management process for AI systems? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Risk, Classification, and Life Cycle | |||||||||
| Is the system categorized by risk and impact? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
~
Prior obligation
of the AI operator. V-PROOF seals the resulting evidence. |
||
| Are risks assessed throughout the life cycle? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Is the system continuously reviewed and improved? | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Security, Auditing, and Reliability | |||||||||
| Have security controls been implemented? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ |
| Are the outputs reliable, accurate, and auditable? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Is there a robust documentation and record-keeping process in place? | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Is the model's performance monitored continuously? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Third Parties, Incidents, and Industry Compliance | |||||||||
| Are third parties and suppliers being managed properly? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | |||
| Has incident detection and response been implemented? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Are the sector-specific obligations addressed? | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Traceability, Authorship, and Ownership | |||||||||
| Can you verify the exact origin and chain of custody for each AI-generated asset? | ✓ | ✓ | ✓ | ✓ | ✓ | ||||
| Is the identity of the AI system used in each output recorded? | ✓ | ✓ | ✓ | ✓ | |||||
| Is there verifiable evidence of authorship and ownership of the organization's AI assets? | ✓ | ✓ | |||||||
| Are digital assets protected against manipulation or subsequent alteration? | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ✓ | ||
| Specific Regulatory Obligations for AI | |||||||||
| Is AI-generated content identified and labeled before it is shared externally? | ✓ | ✓ | |||||||
| Can you demonstrate compliance with the active transparency obligations effective August 2025? | ✓ | ✓ | ✓ | ||||||
| Is there evidence that each automated decision was reviewed and approved by a human? | ✓ | ✓ | ✓ | ✓ | |||||
| Can you demonstrate to clients and partners that AI deliverables meet agreed-upon standards? | ✓ | ✓ | ✓ | ||||||
| Have the AI usage agreements with external model providers been verified? | ✓ | ✓ | ✓ |
~
Prior obligation
of the AI operator. V-PROOF seals the resulting evidence. |
|||||
| Can your organization respond to a regulatory complaint with verifiable evidence in less than 24 hours? | ✓ | ✓ | ✓ | ✓ | |||||
Adapted from: Unified AI Governance Framework · ISO 42001 · EU AI Act · NIST AI RMF · ISO 27001/27701
V-PROOF Analysis · July 2026 · Gartner AI Governance Platforms ↗
Declarative compliance vs. verifiable compliance. That’s the difference.
You have the frameworks in place. You have the policies documented. Can you cryptographically prove that every AI asset was generated, reviewed, and approved exactly as you claim?
When the auditor or regulator arrives, they won’t bring a questionnaire about policies. They’ll ask for evidence—a verifiable record of what your AI decided, when, and who authorized it. Do you have it?
Your infrastructure doesn't change. Your team doesn't change. You simply add the layer that makes everything you already have verifiably compliant with any auditor or regulatory authority.
vproofprotocol.com/contacto
Methodological Note. The coverage indicators for each regulatory framework reflect the general scope stated in the official public documentation of POPIA, ISO/IEC 42001:2023, Regulation (EU) 2024/1689, NIST AI RMF 1.0, PCI DSS v4.0, HIPAA, ISO/IEC 27001:2022, and ISO/IEC 27701:2019. This analysis is for informational purposes only and does not constitute legal advice, regulatory compliance guidance, or official certification. The V-PROOF capabilities described correspond to active protocol features as of July 2026. To assess applicability to your organization, please contact the team at vproofprotocol.com/contacto.
