Regulatory mapping
Every clause, and whose job it is.
Four instruments are encoded clause by clause. For each one this page says how many clauses the map holds and how many of them the platform can produce evidence for — counted out of the files the engine loads, not typed onto a page.
What is encoded today
| Instrument | Where | Status | Clauses | We evidence | Yours |
|---|---|---|---|---|---|
| Regulation (EU) 2024/1689 — Artificial Intelligence Act Regulation (EU) 2024/1689 |
EU European Commission / national market surveillance authorities |
in-force | 14 | 14 | 0 |
| Regulation (EU) 2016/679 — General Data Protection Regulation Regulation (EU) 2016/679 |
EU National data protection authorities / EDPB |
in-force | 11 | 11 | 0 |
| AI Risk Management Framework 1.0 NIST AI 100-1 |
US NIST (voluntary framework) |
voluntary | 11 | 11 | 0 |
| Supervisory Guidance on Model Risk Management SR 11-7 / OCC Bulletin 2011-12 |
US Federal Reserve / OCC / FDIC |
guidance | 10 | 10 | 0 |
“We evidence” is not “you comply”. It counts the clauses in a map for which this platform can produce an artefact — a grant, a refusal, a sealed record, a pack. Whether those artefacts satisfy your regulator, for your deployment, is a determination for you and your counsel. Rotascale governs the action; it does not warrant the outcome.
What is not encoded, and why
Four more instruments have pages on this site and no clause map. Two of them cannot have one — MAS FEAT asks a firm to define its own objective and the UK approach has no statute to enumerate. Two of them could and we have not written them: DORA and ISO/IEC 42001. Each page says which of the two it is, in those words.