RaboAurora/Alibi/Governance

Is it compliant?

Which standards apply to this solution, how each was satisfied, and what is still open. Controls are applied during creation, not evidenced afterwards.

3 open findings

Standards applied

Selected automatically from the solution's tier, domain and data classification.

StandardOwnerHow it appliedResult
Model Risk ManagementMRM OfficeHigh-impact tier42 / 42 controls
GDPR — data minimisationPrivacy OfficePseudonymisation at indexPass
BCBS 239 — risk data aggregationRiskLineage + quality evidencePass
EU AI Act — high-risk dutiesComplianceTransparency + human oversightPass
Bias & fairness testingMRM Office4 protected attributes82% coverage
Internal AI policy v3AI CoEGuardrails + approval gatePass

Open findings

Each has a named owner and a due date before the next review.

f-441
Bias coverage missing on two protected attributes
Owner: Risk Analytics · due 2026-09-30
Medium
f-438
Stale lineage node — feature store refresh lag
Owner: Customer Data · due 2026-08-31
Low
f-430
Harness regression on multi-intent turns
Owner: AI CoE · due 2026-08-22
Medium

Control results

Continuously evaluated, not point-in-time.

Policy checks42 / 42
Data quality96.7%
Residual riskLow
Bias test coverage82%
Open findings3
Access reviewscurrent
Governance by design
Every control here was enforced by a gate in Forge — the evidence is a by-product of building, not a separate compliance exercise.