Compliance
Turn AI governance into evidence your compliance program can inspect
Framework mapping matters, but evidence matters more. Vayon AI applies controls during AI operation and produces reviewable artifacts that governance, risk and compliance teams can use in their own reporting and assessment processes. The product is not the compliant party — your organization is — but it does not only map controls to a framework: it can show that those controls were exercised during organizational AI activity.
Frameworks Vayon AI maps to
EU AI Act
Transparency and risk obligations for AI systems, including Article 50 disclosure that a user is interacting with AI.
Vayon AI can present the Article 50 disclosure and enforce policy per request, and maps its controls to the Act’s transparency and record obligations.
NIST AI RMF
A voluntary framework to govern, map, measure and manage AI risk.
Vayon AI’s policy, routing and evidence controls map to the Govern and Manage functions, giving your risk program concrete artifacts to point to.
ISO/IEC 42001
The management-system standard for artificial intelligence (AIMS).
Vayon AI provides operational controls and records that support an AI management system built around the standard.
YAHAV 5.48
An Israeli information-security regulation profile.
Vayon AI includes a selectable YAHAV 5.48 regulation profile whose controls map to the regulation, alongside EU, NIST and ISO profiles.
Operational evidence, not only a mapping
Each of these is produced by the part of the product that already owns it — nothing here recomputes a status or decides what “compliant” means.
- Policy decision evidence, applied per request before a model runs.
- Request evidence and distributed traces — receipt, routing decision, egress decision and provider call under one trace id, exportable as JSON.
- The AI Use-Case Registry, and the deviations between what was declared and what was observed.
- Access Review across agents, resources and people.
- Deployment verification of the control posture an installation actually booted with.
- Provider and model risk evidence, including supply-chain and provenance records.
- Retention and deletion evidence, including data-subject export and erasure.
- Incident evidence, correlated from recorded events and acknowledged by a named operator.
- Sensitive-operation approvals, where the requester can never be the approver.
- Content Audit records, when the organization enables them.
A generated regulation report states its own limits in the body — point-in-time, unsigned, self-reported evidence, and never an overall “compliant” verdict.
How the mapping works
- Select the regulation profile for the deployment — EU, NIST, ISO or YAHAV.
- Policy is applied per request before a model runs.
- Organizational-knowledge queries produce a reviewable record.
- Your team maps the resulting controls and evidence to its reporting obligations.
Frequently asked questions
Who is responsible for compliance — the product or our organization?
Your organization is the responsible party, not the product. Vayon AI provides controls, framework mapping and evidence that support your compliance program under these frameworks.
Which frameworks does Vayon AI map to?
EU AI Act (including Article 50 disclosure), NIST AI RMF, ISO/IEC 42001 and YAHAV 5.48. The regulation profile is selectable per deployment.
What evidence does it produce?
Policy decisions are applied and recorded per request, and the product produces request traces, audit records, a use-case registry with declared-versus-observed deviations, access review, deployment verification, provider and model risk evidence, retention and deletion evidence, incident evidence, sensitive-operation approvals, and Content Audit records where enabled. A regulation report can be exported as JSON.
