Editorial scope reviewed on September 9, 2026. Confirm the applicable legal version and scope for each assessment. Features described correspond to the current product version.
Features already implemented
The administrative workflows and exports below are implemented and tested. Full validation against each reference is a separate step, depending on applicable obligations and the organization’s evidence.
Organize the program
Declare scope, owners and obligations. Record evidence references and submit work for review by another administrator.
Track privacy work
For LGPD and GDPR: record processing activities, track data subject requests and document impact assessments. The organization declares the information and external actions.
Bring the trail to your audit
Export records and revisions in the complete dossier, with a manifest and verifiable signature. File integrity does not prove the truth of declarations or compliance with a requirement.
Explore the scope by reference
The 23 benchmark references and Brazilian CFM Resolution No. 2,454/2026. Each card separates implemented capabilities from required expansion. Documentation explains scope; it does not declare full compliance.
24 references
Privacy · Law
Australian Privacy Act
Management foundation available
What is implemented
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
The technical pack evaluates available signals of AI usage, code durability and security, and reviews of agent actions, with evaluation history. Missing data is not treated as evidence of compliance.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
CFM-2454 pack with technical evaluations and manual controls, declared initiative risk classification and Annex III documentation. Results and exceptions form part of the evidence trail.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
The technical pack evaluates identified code and dependency risks, diagnosis freshness, gates, test coverage, readiness and change reviews, using collected data. Evaluations are recorded.
Record applicability, owners and declared obligations, with evidence references and internal review. Catalog inclusion does not provide a complete requirements package.
Your organization determines applicability, validates information, carries out measures and obtains the necessary external opinions and assessments. Internal review or risk acceptance does not constitute certification or turn a control into compliance.