| Regulatory Reference | Control Name | Implementation Status | Evidence | Gaps / Notes | Owner |
|---|---|---|---|---|---|
Art. 12(1)(a) |
Automatic Event Logging | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
Art. 12(1)(b) |
Traceability of AI Outputs | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
Art. 12(2)(a) |
Identification of Input Data | PARTIALLY IMPLEMENTED | 1 lower-severity finding mapped to this control. | 1 open finding — see Gap Plan | [ORG TO COMPLETE: Control owner] |
Art. 12(2)(b) |
Tamper-Evidence | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
Art. 12(3) |
Retention & Accessibility | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
Art. 12(4) |
National Authority Access | IMPLEMENTED | No findings detected for this control. | — | [ORG TO COMPLETE: Control owner] |
Disclaimer: Code-level controls only. Coverage percentages reflect how many framework controls have matching RepoScope detectors. This is a development aid, not a certification tool — auditors make the final determination.
Note: Code-level provenance controls only. This assessment identifies where AI-generated code exists and whether provenance records are in place. It is a development aid for Article 12 readiness, not a legal compliance determination — consult qualified legal counsel for formal compliance assessment.