Overview
BASIS provides built-in support for major regulatory and compliance frameworks. This document maps BASIS capabilities to specific compliance requirements.
Supported Frameworks
| Framework | Jurisdiction | Focus | BASIS Relevance |
|---|---|---|---|
| SOC 2 Type II | Global | Security, Availability | High |
| ISO 27001:2022 | Global | Information Security | High |
| GDPR | EU/EEA | Data Protection | High |
| HIPAA | US | Health Information | High |
| PCI DSS 4.0 | Global | Payment Card Data | Medium |
| EU AI Act | EU | AI Systems | Critical |
NIST AI Risk Management Framework
BASIS maps directly to the NIST AI RMF four core functions: GOVERN, MAP, MEASURE, MANAGE.
GOVERN
Full- ✓ Policy definition via trust tiers
- ✓ Accountability assignment
- ✓ Organizational roles
MAP
Full- ✓ Risk classification engine
- ✓ Context categorization
- ✓ Capability scope mapping
MEASURE
Full- ✓ Trust scoring
- ✓ Audit metrics
- ✓ PROOF layer records
MANAGE
Full- ✓ ENFORCE layer controls
- ✓ Escalation circuits
- ✓ Incident response hooks
SOC 2 Type II
BASIS provides comprehensive coverage for SOC 2 Trust Services Criteria:
Security (CC)
Full- ✓ Access control via trust tiers
- ✓ Capability gating
- ✓ Audit logging
Availability (A)
Full- ✓ Failure mode handling
- ✓ Circuit breakers
- ✓ Graceful degradation
Processing Integrity (PI)
Full- ✓ ENFORCE layer validation
- ✓ PROOF layer integrity
- ✓ Hash chains
Confidentiality (C)
Full- ✓ Data capability restrictions
- ✓ Tier-based access
- ✓ Encryption requirements
ISO/IEC 42001:2023
The first international standard for AI management systems. BASIS satisfies its core requirements:
| Clause | Requirement | BASIS Implementation |
|---|---|---|
| �6.1 | Risk treatment | Trust tier risk classification |
| �8.1 | Operational planning | Capability gating, ENFORCE layer |
| �8.4 | AI system lifecycle | Versioned policy, audit chain |
| �9.1 | Performance monitoring | Trust decay, health checks |
| �10.1 | Improvement | Incident ? policy update loop |
GDPR
| Article | Requirement | BASIS Implementation |
|---|---|---|
| Art. 5(1)(f) | Integrity & confidentiality | Cryptographic proofs, access control |
| Art. 5(2) | Accountability | Complete audit trail in PROOF layer |
| Art. 25 | Data protection by design | Governance-before-execution |
| Art. 30 | Records of processing | PROOF layer records all decisions |
| Art. 32 | Security of processing | Trust boundaries, capability gating |
EU AI Act
BASIS provides critical support for high-risk AI system requirements:
| Article | Requirement | BASIS Implementation |
|---|---|---|
| Art. 9 | Risk management | Risk classification, trust scoring |
| Art. 11 | Technical documentation | PROOF layer records |
| Art. 12 | Record-keeping | 7-year retention, hash chain |
| Art. 13 | Transparency | Audit trail, decision explanations |
| Art. 14 | Human oversight | Escalation mechanism |
| Art. 15 | Accuracy & robustness | Trust decay, failure handling |
Minimum Conformance by Framework
| Framework | Min BASIS Level | Key Components |
|---|---|---|
| SOC 2 | BASIS Core | ENFORCE + PROOF |
| ISO 27001 | BASIS Core | Full capability gating |
| GDPR | BASIS Complete | Data capabilities + PROOF |
| HIPAA | BASIS Complete | PHI capabilities + encryption |
| EU AI Act | BASIS Complete | Full governance + human oversight |
For complete compliance mappings including HIPAA, PCI DSS, NIST AI RMF, and audit evidence guidance, see the full document on GitHub.
View Full Compliance Mapping on GitHub