Frameworks
What the rules are mapped against
Tredy does not hold a generic checklist. Each obligation is mapped to the framework it comes from, so an answer can cite the clause behind it — and a gap can name what is missing rather than scoring it.
AI governance
Obligations that attach to how models and agents are built, deployed and supervised.
- EU AI Act
- ISO 42001
- NIST AI RMF
Operational resilience
Continuity, recovery and third-party dependency requirements, including exit readiness.
- DORA
Security
Control frameworks that a service can gather evidence against as the work runs.
- ISO 27001
- NIST CSF
- NIST 800-53
- SOC 2
- PCI DSS
Privacy
Processing, retention and disclosure duties that constrain what an action may do.
- GDPR
- HIPAA
Your own policies, contracts and internal thresholds sit alongside these. Most of what a regulated organisation has to answer for is not in a public framework at all — it is in a commitment someone already made. Those are mapped the same way.
Start with one service.
A 30-minute scoping session with your risk owner and your IT contact. We leave with the first service named, the connections listed, and a date.