Every system asks if an action is allowed. None asks if it should happen.

Frameworks

What the rules are mapped against

Tredy does not hold a generic checklist. Each obligation is mapped to the framework it comes from, so an answer can cite the clause behind it — and a gap can name what is missing rather than scoring it.

AI governance

Obligations that attach to how models and agents are built, deployed and supervised.

  • EU AI Act
  • ISO 42001
  • NIST AI RMF

Operational resilience

Continuity, recovery and third-party dependency requirements, including exit readiness.

  • DORA

Security

Control frameworks that a service can gather evidence against as the work runs.

  • ISO 27001
  • NIST CSF
  • NIST 800-53
  • SOC 2
  • PCI DSS

Privacy

Processing, retention and disclosure duties that constrain what an action may do.

  • GDPR
  • HIPAA

Your own policies, contracts and internal thresholds sit alongside these. Most of what a regulated organisation has to answer for is not in a public framework at all — it is in a commitment someone already made. Those are mapped the same way.

Start with one service.

A 30-minute scoping session with your risk owner and your IT contact. We leave with the first service named, the connections listed, and a date.