# Simplify AI governance and ensure compliance

> Manage AI governance with clear, actionable controls across your organisation. Stay compliant with policies and regulations like the EU AI Act with ease.

**Source:** https://deeploy.ai/product/control-frameworks/

**About this file:** Machine-readable markdown version of the page above, for LLMs and AI assistants. Regenerated automatically whenever the page is updated.

Don't let compliance risks and regulatory uncertainty hold back your AI initiatives. **Deeploy gives you the control**, accountability, and oversight you need to stay compliant with regulations like the EU AI Act with ease.

## Struggling to organise AI governance?

Managing AI governance with ever-evolving regulations like the **EU AI Act** can be overwhelming. Without the right controls, organisations risk regulatory fines, non-compliance, and struggle to scale AI models confidently.

- ✗ Keeping up with evolving AI regulations
- ✗ Governance risks from scattered models
- ✗ The threat of fines and reputational damage

## Effortless compliance with a guided workflow

Deeploy provides a guided governance workflow to simplify AI governance and ensure compliance across your organisation. Get ready for frameworks like the EU AI Act & ISO 42001.

Implement comprehensive governance across teams with built-in frameworks like the EU AI Act, ISO/IEC 42001, and NIST AI RMF or create custom frameworks tailored to your organisation’s specific requirements.

Available frameworks:

- Responsible AI - Helps you use AI responsibly in high-risk use cases
- ISO/IEC 42001 - Aligns with international AI management system standards
- EU AI Act - Supports your compliance with EU AI regulations
- AIUC-1 - The world's first AI standard for enterprise adoption of agents
- NIST AI RMF - Manage risks to individuals, organisations, and society associated with AI

Transform policy requirements into actionable controls at every AI lifecycle stage and track framework-wide progress. Apply ready-to-use controls, create custom ones or bulk import from existing policies.

Classify any AI use case instantly with the built-in EU AI Act risk classification assessment, and know exactly which controls apply to your use case.

Prevent unauthorised changes with approval rules that distribute responsibility across teams, requiring sign-off for new Deployments and updates.

Schedule periodic reviews to ensure AI systems stay compliant and reliable, with built-in notifications when use cases require reassessment or updates.

Monitor organisation-wide AI governance at a glance with a unified dashboard showing compliance status, risk levels, and framework progress across all use cases and teams.

## Frequently asked questions

### What are Control Frameworks in Deeploy?

Control Frameworks in Deeploy are structured sets of AI compliance and risk controls that translate AI governance policies and regulations into actionable requirements. They allow organisations to implement, enforce, and track AI controls consistently across multiple AI systems and use cases.

Each AI control framework is made of individual AI controls. You can start with pre-built control frameworks aligned with regulatory and standards-based requirements, such as the EU AI Act and ISO 42001, or create custom frameworks to match your internal AI policy and risk management needs.

### Which AI governance frameworks does Deeploy support out of the box?

Deeploy comes with five pre-built frameworks: the EU AI Act, ISO/IEC 42001, NIST AI RMF, AIUC-1 (the world's first AI standard for enterprise adoption of agents), and Deeploy's own Responsible AI Control Framework for high-risk use cases. These default frameworks are maintained and updated by Deeploy to reflect the latest regulatory requirements, so you always have a reliable baseline to work from.

### Can I create a custom control framework in Deeploy?

Yes. Alongside the default frameworks, you can build your own control framework from scratch. Custom frameworks let you define controls tailored to your organisation's specific compliance requirements, map them to the relevant use case lifecycle stages and risk classifications, and add automated checks for validation. You can also bulk import controls from existing internal policies. Once created, a custom framework is applied to a Workspace just like any built-in framework.

### What is a control?

In Deeploy, a control is an actionable implementation of an AI policy or risk requirement. Controls define what must be in place to ensure AI governance, accountability, and compliance for a specific AI use case.

Controls can be verified through automated checks, such as confirming required documentation exists or that monitoring rules are configured, or they may require evidence to be uploaded manually.

### What’s the difference between default and custom controls?

Deeploy comes with a library of default AI governance controls aligned with commonly used regulatory and standards-based frameworks. Custom controls allow organisations to define their own AI policy controls based on internal governance rules, operational requirements, or specific standards.

Custom controls can be grouped into custom AI control frameworks and applied consistently across teams and AI use cases.

### How do automated checks work?

Automated checks are built-in validations that verify whether an AI control requirement has been met. For example, a check can confirm whether required documentation exists, whether a risk assessment was completed, or whether monitoring rules are configured.

When an automated check passes, the control status is updated automatically, helping teams track AI compliance and risk controls without manual oversight.

### How do approval rules work in Deeploy, and why do they matter for AI governance?

Approval rules let you require sign-off from designated roles (owners, operators, or reviewers) before a new AI deployment goes live or an existing one is updated. Rules are configured at the organisation level and applied per Workspace, so you can enforce different levels of oversight depending on the sensitivity of the use case. This creates a documented, multi-party approval trail that serves as governance evidence for auditors and regulators, preventing unauthorised changes from reaching production.

### What are periodic reviews in Deeploy and how are they configured?

Periodic reviews are scheduled reassessments of your AI use cases to ensure they remain compliant and reliable over time. Review cadence is set per Workspace (defaulting to every six months) and can be updated from the Organisation panel. When a use case is due for review, Deeploy sends notifications to the relevant team members so nothing falls through the cracks. This is particularly relevant for the EU AI Act, which requires organisations to demonstrate ongoing oversight of deployed AI systems, not just at the point of initial deployment.

### What risk classifications does Deeploy assign to AI use cases, and what does each mean?

Deeploy's risk classification system is based on the EU AI Act's tiered framework.

The built-in risk classification assessment guides you through a structured questionnaire that evaluates your AI system against four categories: **unacceptable risk** (prohibited uses under Article 5, such as social scoring or real-time biometric surveillance), **high risk** (systems falling under Annex I or Annex III of the Act, such as credit scoring, recruitment tools, or medical devices), **limited risk** (systems with transparency obligations, such as chatbots), and **minimal risk** (all other AI systems).

The assessment is based on the Algorithm Audit Implementation Tool and covers your system's intended purpose, application domain, and potential impacts. The completed assessment can be exported as a PDF to serve as documented evidence of your classification rationale for auditors.

### What does Deeploy's AI governance dashboard show, and who is it for?

The AI governance dashboard gives compliance leads and AI program owners a single, organisation-wide view of AI governance health without having to dig into individual use cases or workspaces.

At a glance it shows the total number of use cases, active deployments, and controls in play across the organisation, alongside four key breakdowns: use cases by risk classification (unacceptable, high, limited, minimal, and unclassified), use cases by lifecycle stage (exploration through to production), overall controls progress (completed, in progress, and not started), and use cases by applied framework, showing which frameworks are in use and how many use cases under each have completed their controls.

A time-series chart also tracks how quickly new use cases are being added over the last 30 days, giving leadership a sense of how fast the AI portfolio is growing relative to governance capacity.

Together these views make it easy to spot concentration risks, for example, a large share of unclassified or high-risk use cases still in exploration, and to report on governance programme progress to regulators or the board.

---

**Get in touch:** You can book a demo at https://deeploy.ai/book-demo/ or reach the team via https://deeploy.ai/contact/.
