Compliance Mapping

Detailed mapping of Vellaveto features to European regulatory requirements.

EU AI Act NIS2 DORA ISO 42001 SOC 2 OWASP

EU AI Act

Regulation (EU) 2024/1689 — effective August 2, 2026.

ArticleRequirementVellaveto Feature
Art 50(2) Transparency: mark AI-generated output VerdictExplanation with configurable verbosity injected into _meta
Art 10 Data governance for training/validation DataGovernanceRecord with classification, purpose, provenance, retention
Art 12 Record-keeping and traceability Tamper-evident audit: SHA-256 chains, Merkle proofs, Ed25519 checkpoints
Art 14 Human oversight RequireApproval verdict, human-in-the-loop workflow with timeout
Art 9 Risk management system Policy engine with risk scoring, ABAC, behavioral anomaly detection

NIS2 (D.Lgs. 138/2024)

Italy's implementation of Directive (EU) 2022/2555 on cybersecurity.

RequirementVellaveto Feature
Incident notification (24h pre-notifica, 72h notifica, 1M relazione) Incident reporting templates and audit evidence export
Supply chain security ETDI cryptographic tool verification, version pinning, attestation chains
Access control and identity management ABAC, RBAC, NHI lifecycle, delegation chains, SSO (OIDC/SAML)
Continuous monitoring and logging Real-time audit, SIEM export (CEF/syslog/webhook), anomaly detection
Risk assessment Policy simulation, gap analysis (7 frameworks), compliance evidence
Business continuity HA clustering, leader election, cross-transport smart fallback

DORA

Regulation (EU) 2022/2554 on digital operational resilience for financial services.

ChapterRequirementVellaveto Feature
Ch II ICT risk management framework Policy engine, risk scoring, circuit breakers, behavioral monitoring
Ch III ICT incident management Structured audit events, incident workflow, automated classification
Ch V ICT third-party risk Supply chain verification, tool registry trust scoring, vendor attestation

Additional Frameworks

SOC 2 Type II

Automated access review reports with CC6 evidence generation. Trust services criteria mapped to Vellaveto controls. HTML and JSON report export.

ISO 42001

AI management system controls mapped to policy engine features. Risk assessment, monitoring, and continuous improvement evidence.

OWASP Top 10 Agentic 2026

All 10 risks mitigated: prompt injection (ASI01), tool poisoning (ASI02), insecure output (ASI03), rug pull (ASI04), memory poisoning (ASI05), and more.

CoSAI Landscape

38/38 CoSAI controls implemented. Adversa TOP 25: 25/25. 7-framework gap analysis with remediation guidance.


Need a compliance assessment?

Our Compliance-as-a-Service offering provides auditor-ready evidence packages.