AI Governance: 30 Key Questions, 8 Regulatory Frameworks, 1 Layer of Evidence

AI Governance · Unified Framework · 30 Questions · 8 Frameworks
Unified AI Governance Framework
+ Evidence Layer V-PROOF
This matrix maps the 30 key AI governance questions against 8 regulatory frameworks and global standards. V-PROOF adds the missing layer: it allows evidence to be linked to governance responses and verifies the integrity of the recorded information. The seal alone does not certify the accuracy of a response or compliance with the requirement.
30

's stress test questions
8
Regulatory frameworks
26
V-PROOF
provides evidence
4
V-PROOF
complements
◈ Positioning

frameworks define the WHAT.
V-PROOF Generates verifiable evidence of
the HOW and the WHEN.

Declarative compliance
vs. verifiable compliance.
← Swipe to see all the frameworks →
30 Questions on AI Governance POPIAProtection of Personal
Information Act (ZA)
ISO 42001AI Management
s System Standard
EU AI ActRegulation (EU)
2024/1689
NIST AI RMFAI Risk Management
Framework (U.S.)
PCI DSSPayment Card Industry
Data Security Standard
HIPAAHealth Insurance
Portability Act (U.S.)
ISO 27001
, Information Security Management System
ISO 27701Privacy Information
Management System
V-PROOF
's cryptographic evidence, verifiable at the source
◈ EU-Native
Data, Privacy, and Data Minimization
Is personal data processed lawfully? ✓✓✓ ✓ ✓
Are privacy and data minimization being applied? ✓✓✓✓ ✓ ✓
Are the data sources accurate and appropriate for the purpose? ✓✓✓✓ ✓✓ ✓
Are there data retention and disposal policies? ✓✓ ✓✓ ~
Prior obligation
of the AI operator.
V-PROOF seals
the resulting evidence.
Transparency, Explainability, and Rights
Is the AI system transparent and explainable? ✓✓✓ ✓
Are individuals well-informed and able to exercise their rights? ✓✓✓ ✓ ✓
Has the system been evaluated in terms of bias and fairness? ✓✓✓ ~
Prior obligation
of the AI operator.
V-PROOF seals
the resulting evidence.
Human Oversight and Governance
Is there a governance and accountability structure in place? ✓✓✓✓ ✓✓ ✓
Is human oversight built in where it should be? ✓✓✓ ✓ ✓
Is there a change management process for AI systems? ✓✓✓ ✓✓ ✓
Risk, Classification, and Life Cycle
Is the system categorized by risk and impact? ✓✓✓✓ ✓✓ ~
Prior obligation
of the AI operator.
V-PROOF seals
the resulting evidence.
Are risks assessed throughout the life cycle? ✓✓✓✓ ✓✓ ✓
Is the system continuously reviewed and improved? ✓✓ ✓✓ ✓
Security, Auditing, and Reliability
Have security controls been implemented? ✓✓✓✓✓✓ ✓✓ ✓
Are the outputs reliable, accurate, and auditable? ✓✓✓ ✓✓ ✓
Is there a robust documentation and record-keeping process in place? ✓✓ ✓✓ ✓
Is the model's performance monitored continuously? ✓✓✓✓ ✓✓ ✓
Third Parties, Incidents, and Industry Compliance
Are third parties and suppliers being managed properly? ✓✓✓ ✓✓ ✓
Has incident detection and response been implemented? ✓✓✓✓ ✓✓ ✓
Are the sector-specific obligations addressed? ✓✓ ✓✓ ✓
Traceability, Authorship, and Ownership
Can you verify the exact origin and chain of custody for each AI-generated asset? ✓✓✓ ✓ ✓
Is the identity of the AI system used in each output recorded? ✓✓✓ ✓
Is there verifiable evidence of authorship and ownership of the organization's AI assets? ✓ ✓
Are digital assets protected against manipulation or subsequent alteration? ✓✓✓✓ ✓✓ ✓
Specific Regulatory Obligations for AI
Is AI-generated content identified and labeled before it is shared externally? ✓ ✓
Can you demonstrate compliance with the active transparency obligations effective August 2025? ✓✓ ✓
Is there evidence that each automated decision was reviewed and approved by a human? ✓✓✓ ✓
Can you demonstrate to clients and partners that AI deliverables meet agreed-upon standards? ✓✓ ✓
Have the AI usage agreements with external model providers been verified? ✓ ✓✓ ~
Prior obligation
of the AI operator.
V-PROOF seals
the resulting evidence.
Can your organization respond to a regulatory complaint with verifiable evidence in less than 24 hours? ✓ ✓✓ ✓
Regulatory Frameworks
✓ The framework includes requirements regarding this question
Outside the main scope of the framework
V-PROOF Evidence Layer
✓ Related and verifiable evidence; it does not, on its own, prove compliance
~ A complementary, verifiable registry reinforces compliance

Adapted from: Unified AI Governance Framework · ISO 42001 · EU AI Act · NIST AI RMF · ISO 27001/27701

V-PROOF Analysis · July 2026 · Gartner AI Governance Platforms ↗

◈
Frameworks define what to govern. V-PROOF generates verifiable evidence that governance took placeat the time it occurred, with cryptographic evidence that can be verified by any auditor or supervisory authority, without the content ever leaving the organization.
Declarative compliance vs. verifiable compliance. That’s the difference.
Three Questions Every C-Suite Executive Should Ask Themselves
“

You have the frameworks in place. You have the policies documented. Can you cryptographically prove that every AI asset was generated, reviewed, and approved exactly as you claim?

“

When the auditor or regulator arrives, they won’t bring a questionnaire about policies. They’ll ask for evidence—a verifiable record of what your AI decided, when, and who authorized it. Do you have it?

“

Your infrastructure doesn't change. Your team doesn't change. You simply add the layer that makes everything you already have verifiably compliant with any auditor or regulatory authority.

V-PROOF
Trust Layer s for the AI Economy · vproofprotocol.com
Request a Strategic Assessment
Questions about your case?
vproofprotocol.com/contacto

Methodological Note. The coverage indicators for each regulatory framework reflect the general scope stated in the official public documentation of POPIA, ISO/IEC 42001:2023, Regulation (EU) 2024/1689, NIST AI RMF 1.0, PCI DSS v4.0, HIPAA, ISO/IEC 27001:2022, and ISO/IEC 27701:2019. This analysis is for informational purposes only and does not constitute legal advice, regulatory compliance guidance, or official certification. The V-PROOF capabilities described correspond to active protocol features as of July 2026. To assess applicability to your organization, please contact the team at vproofprotocol.com/contacto.

Previous
Previous

August 2, 2026: What Changes Today for Organizations Using High-Risk AI

Next
Next

The first requirement of the AI regulation is not technical. #ARTICLE 50 AI ACT