Most AI governance vendors answer a compliance question with a badge. SOC 2 certified. GDPR ready. The badge tells you a process happened once, audited by someone else, at some point in the past. It does not tell you which specific requirement your control actually satisfies, what evidence it produces on demand, or where it quietly stops short. We built something different: an in-app compliance report that maps every one of OBEL's controls to the specific paragraph or clause it satisfies, across nine frameworks, and states plainly where a control is only partial.
Nine frameworks, 87 controls, one honest status field
The report currently covers the EU AI Act, the NIST AI Risk Management Framework, SOC 2 Type II, ISO/IEC 27001:2022, ISO/IEC 42001:2023, APRA CPS 230, APRA CPS 234, Australia's Privacy Act 1988, and Australia's Voluntary AI Safety Standard. That's 87 individual controls, each one tied to a specific article, paragraph, guardrail, or clause, not a generic "addresses data protection" line.
Every control carries one of three statuses, and we mean all three of them literally. Satisfied means the control fully closes the requirement and the evidence exists to prove it on demand. Partial means OBEL provides real, load-bearing evidence toward the requirement, but part of the obligation sits with the deploying organisation and we say exactly which part. Planned means the control doesn't exist yet. A vendor that only ever shows you green checkmarks isn't more compliant, it's just not telling you where the actual boundary of its product sits.
What a gap field actually says
APRA CPS 230 Paragraph 31 (Service Provider Management) is marked partial in our own report, and the gap field says exactly why: OBEL supplies the vendor and provider evidence to populate a service provider register, but doesn't maintain that register or an exit plan itself, because that's the regulated entity's obligation, not ours. That's a true sentence, and it's more useful to a buyer than a badge that implies the whole problem is solved.
Why APRA CPS 230 and CPS 234 specifically
Australia shelved a dedicated, mandatory AI Act in its December 2025 National AI Plan. The government's position now is that existing law, Privacy Act, sector rules, and APRA's prudential standards for regulated entities, already governs AI outcomes, backed by a voluntary standard rather than new AI-specific legislation. That makes CPS 230 (operational risk, in force since July 2025) and CPS 234 (information security) more relevant to an Australian financial institution's AI governance question than a hypothetical future AI Act, not less. We built an 8-control, paragraph-cited mapping to both, covering critical operations identification, service provider management, business continuity, incident management, information security capability, classification of information assets, third-party information security, and incident notification.
Closing a gap is a real process, not a status flip
When we added the Voluntary AI Safety Standard's 10 guardrails to the report, two of them, challenge processes and stakeholder engagement, came back planned. Both are process guardrails, not technical ones: a way for someone affected by an AI decision to challenge it, and a documented way we engage the people our decisions actually affect. We didn't want to leave two guardrails marked planned indefinitely, so we built the process for both.
Challenging an AI decision is now a request type in OBEL's own Help & Support panel, and every submission is written to an auditable, RLS-protected record, not just an email that might get lost. A human reviewer checks it against the audit ledger and responds, typically within five business days. Stakeholder engagement is now a documented quarterly review that looks at challenge themes, security event patterns, and every other control's gap fields together, specifically looking for fairness and diversity signals, not just operational health. The challenge process is marked satisfied now. Stakeholder engagement is marked partial, honestly, because right now it runs as a founder-led review rather than a cross-functional committee, and that's stated in the report too.
“The point of an honest gap field isn't to look less finished. It's that a buyer who finds a gap we already disclosed trusts every satisfied control a lot more than one who finds a gap we didn't mention.”
- Denis Bouton
87
Individual controls mapped, each to a specific paragraph or clause
9
Frameworks covered, from EU AI Act to Australia's Voluntary AI Safety Standard
3
Honest statuses: satisfied, partial, and planned - no fourth status that hides the difference
Where to look in OBEL
Settings > Compliance, for any org on a paid tier. Filter by framework, category, or status, click any control for the full requirement text, OBEL's implementation, the evidence it produces, and generate a dated report scoped to any date range, ready to hand to an auditor or a customer's security team.
This piece was prepared by the OBEL editorial team at ninthLABS Ventures, drawing on OBEL's own in-app compliance mapping.
More in Product