Compliance FrameworksSix frameworks, one platform

Every major AI regulation.
One evidence chain.

OnTargetCompliance maps EU AI Act, GDPR, UK GDPR, SOC 2, ISO 27001, and the Clarity Act to a single node execution — so one compliance run produces evidence for every applicable framework simultaneously.

Compliance Profiles

Five profiles for five audiences

Different stakeholders need different compliance outputs. OnTargetCompliance generates evidence tailored to each audience from the same underlying node execution.

EU AI Act

EU GPAI / Systemic Risk

Full compliance for general-purpose AI models with systemic risk under EU AI Act Title III Chapter 2.

The EU AI Act introduces specific obligations for providers of general-purpose AI (GPAI) models — and elevated requirements for those with systemic risk. OnTargetCompliance maps the complete GPAI obligation set across the platform, from model documentation and capability evaluation through to adversarial testing, incident reporting, and EU AI Office registration. For systemic risk models (those trained on compute above 10²⁵ FLOPs), the platform supports the full Article 55 enhanced obligation set.

Obligations covered
Art. 53Technical documentation for GPAI models
Art. 53(1)(b)Training data summary and data governance
Art. 53(1)(c)Training, fine-tuning, and testing procedures
Art. 54Authorised representative obligations (non-EU providers)
Art. 55(1)(a)Adversarial testing for systemic risk models
Art. 55(1)(b)Incident reporting to EU AI Office
Art. 55(1)(c)Cybersecurity protection measures
Art. 55(1)(d)Energy efficiency reporting
Art. 56Codes of practice compliance
Nodes executed
Model Registration Node (A)
Dataset Inventory Node (B)
Benchmark Execution Node (C)
Safety Mitigation Node (D)
Independent Review Node (E)
Submission Packet Node (F)
Outputs generated
GPAI technical documentation package
Adversarial test log (signed)
Incident report templates
EU AI Office registration record
Five compliance profiles

Which profile fits your organisation?

Book a demo and we will map your AI systems to the right compliance profile — EU GPAI, UK advanced assurance, NIST-aligned, contractual, or board reporting.

Supported Frameworks

Framework coverage in detail

Select a framework to see the specific articles, controls, and platform coverage.

Active

EU AI Act

RegionEuropean Union
EffectiveAugust 2024 (phased enforcement)
Scope

Providers and deployers of AI systems in the EU market. High-risk systems subject to conformity assessment. GPAI models subject to Title III Chapter 2 obligations.

Key articles / controls
Art. 9Risk management system
Art. 10Data and data governance
Art. 11Technical documentation
Art. 13Transparency and information provision
Art. 14Human oversight
Art. 43Conformity assessment
Art. 49Registration obligations
Art. 53-55GPAI and systemic risk obligations
Art. 72Post-market monitoring
Platform coverage

Full — all six Trust-Verified Nodes map to EU AI Act obligations. The platform generates EU AI Office registration records, GPAI technical documentation, and conformity assessment evidence.

Discuss your EU AI Act obligations
Framework coverage

Six frameworks. One platform. Zero duplication.

Evidence collected for one framework is automatically mapped to overlapping requirements in others. No double-handling, no manual cross-referencing.

Book a Demo See the Nodes
Multi-framework advantage

One execution. Every framework.

The Policy Engine maps every node execution to all applicable frameworks simultaneously. Running a node once produces evidence for all six frameworks — eliminating duplicate compliance work.

Without OnTargetCompliance
Separate compliance projects per framework
Duplicate documentation for each regulator
Manual mapping of evidence to obligations
Weeks of preparation per audit
Evidence scattered across teams and tools
Policy Engine mapping
EU AI Act Art. 9 → Safety Mitigation Node
GDPR Art. 30 → Dataset Inventory Node
SOC 2 CC4 → Independent Review Node
ISO 27001 A.8 → Model Registration Node
Clarity Act Sec. 4 → Model Registration Node
With OnTargetCompliance
One node execution covers all frameworks
Evidence automatically mapped to obligations
Regulator-specific packages generated instantly
Audit preparation in hours, not weeks
All evidence in one signed, verifiable chain
Next step

Map your obligations.
Build your evidence chain.

Book a demo to walk through the specific obligations that apply to your AI systems and see how the platform maps them to signed evidence.