Obligations directory

AI compliance obligations

The concrete requirements underneath every AI framework — risk management systems, bias audits, impact assessments, documentation, oversight, transparency, incident reporting. Each obligation links to the vendors that help you meet it.

All obligations

9 obligations

AI Impact Assessment

Documented assessment of an AI system's intended use, risks, safeguards, and monitoring, completed before deployment and annually thereafter.

6 vendors help meet this
Colorado AI ActEU AI ActGDPR Art. 22

Bias Audit

Independent testing of an AI system for disparate impact across protected classes, with public summary of results.

2 vendors help meet this
NYC LL 144Colorado AI Act

Data & Data Governance

Controls on training, validation, and testing data — quality, representativeness, bias examination, and documentation.

7 vendors help meet this
EU AI ActISO/IEC 42001GDPR Art. 22

Human Oversight

Meaningful human review of AI outputs, particularly for high-risk and consequential decisions.

1 vendor help meet this
EU AI ActGDPR Art. 22Colorado AI Act

Incident Reporting

Process for detecting, documenting, and reporting AI system malfunctions or algorithmic discrimination to regulators within defined timelines.

6 vendors help meet this
EU AI ActColorado AI Act

Post-Market Monitoring

Ongoing monitoring of AI system performance, drift, and incidents after deployment.

9 vendors help meet this
EU AI ActNIST AI RMFISO/IEC 42001

Risk Management System

A documented, iterative process to identify, analyze, evaluate, and mitigate risks from an AI system throughout its lifecycle.

6 vendors help meet this
EU AI ActNIST AI RMFISO/IEC 42001

Technical Documentation

Detailed documentation of a model's training data, architecture, performance metrics, limitations, and intended use — required for conformity assessment and audit.

9 vendors help meet this
EU AI ActISO/IEC 42001

Transparency & Notice to Individuals

Clear notice to individuals when AI is used for consequential decisions and meaningful information about the logic involved.

4 vendors help meet this
EU AI ActGDPR Art. 22Colorado AI Act

How obligations connect to frameworks

Frameworks like the EU AI Act, NIST AI RMF, and ISO/IEC 42001 overlap substantially on what they require. Indexing by obligation — rather than only by framework — makes it easier to see which vendor capabilities map to which concrete deliverables.

See the frameworks directory for the regulation-side view.