Home · Compliance
Regulatory coverage

Mapped to the frameworks your regulators enforce.

Receipts supply the runtime evidence these regimes demand: what an AI system did, when, and under which policy. The same receipt that verifies your AI savings comes pre-mapped across the major global frameworks, so one evidence layer covers them all.

Global coverage

Every framework, one signed record.

A scope note, stated plainly: these mappings are authored by AskLedger from the published regulator texts. No regulator or standards body has reviewed, approved, or endorsed them. A receipt carries evidence for an article or a control; only your own auditor or regulator can decide whether that evidence satisfies the obligation.

European Union
  • EU AI Act (Reg. 2024/1689)Art. 9, 11, 12, 14, 15, 50 · Annex IV technical documentation
  • GDPR (Reg. 2016/679)Art. 22 automated decisions · Art. 5 accountability
United Kingdom
  • PRA SS1/23Model risk management principles for banks
  • ICO guidance · DPA 2018AI, automated decisions, data protection
United States
  • NIST AI RMF 1.0Govern · Map · Measure · Manage
  • Federal Reserve SR 11-7Supervisory guidance on model risk
  • Colorado AI Act · HIPAA · SOC 2 · FedRAMPSector and state requirements
India
  • RBI: FREE-AI & Model Risk Management (2026)Explainability, human oversight, board accountability, kill switch
  • DPDP Act 2023 · CERT-InPersonal data protection and incident reporting
Middle East
  • UAE: CBUAE Federal Decree-Law No. 6Responsible AI principles for financial institutions
  • KSA: SAMA · SDAIA AI Ethics · PDPLGovernance, data residency, decision logging
Asia-Pacific
  • Singapore: MAS FEAT · IMDA Model AI GovernanceFairness, ethics, accountability, transparency
  • Australia: Voluntary AI Safety StandardTen guardrails for responsible AI
International standards
  • ISO/IEC 42001AI management systems (AIMS)
  • ISO/IEC 23894AI risk management
  • OECD AI PrinciplesTransparency, accountability, robustness
One evidence layer
  • Every framework, one recordEach receipt can cite the articles and controls the evidence is being kept for. The same signed record serves an auditor, a regulator, and an insurer.
Imminent · EU AI Act Article 12

The logging duty that lands in December 2027.

Article 12 requires high-risk AI systems to automatically record events over the system's lifetime, in logs that are tamper-evident and retained for at least six months, or 24 months for biometric and law-enforcement systems. The high-risk obligations, including this logging duty, apply from 2 December 2027, after the 2026 Digital Omnibus deferred them from 2026; the Article 50 transparency obligations still apply from 2 August 2026. An AskLedger receipt chain is exactly that kind of record: an automatic, signed, tamper-evident log of what an AI system did, portable enough to hand a regulator. It supports the Article 12 record-keeping obligation; it does not by itself make you compliant, and legal sufficiency always depends on your use case and your counsel.

Know every deadline before your auditors do.

Our free 2026 tracker maps each framework to the exact evidence it expects you to produce.