Browse documentation
Help Centre · 5 articles
Frameworks explained
The five frameworks in plain language — what each asks, what it does not give you.
01EU AI Act — roles, tiers, dates, and the Article 25 trapThe statutory core. Obligations attach by your role for each system and its risk tier; most high-risk duties apply from 2 December 2027; Article 25 can make a deployer the provider.02GDPR for AI systems — where the Act meets data protectionPersonal data through a running AI system brings the GDPR into the same register: lawful basis, transparency, DPIA, Art. 22, processor terms, transfers — per system from five questions, plus an organisation-wide programme.03ISO/IEC 42001 — the management system, and why it is not a legal shieldThe AI management-system standard as a programme from Stage 1 to Stage 2. Genuinely useful, certifiable by an accredited body — and not a presumption of conformity with the EU AI Act.04ISO/IEC 27001 — 93 controls as themes, one management systemInformation security, modelled as one management system with ISO/IEC 42001 where the clauses are the same. The 93 Annex A controls are worked as four guided theme records, not empty rows.05NIST AI RMF — a profile, not a certificateThe US framework a counterparty may ask for: Govern, Map, Measure, Manage. Veritome produces the profile document from approved records; there is no certification to obtain.