Handvantage

COMPLIANCE EVIDENCE

A grade is only the summary.Ask for the evidence behind it.

Vantage Workspace maps observed deployment evidence to eleven base framework templates. A serious evaluation goes further: the buyer selects a control, reruns it, and retrieves the record produced by that run.

The displayed grade applies to the assessed deployment, loaded policies, and assessment window. It is not certification of the customer organization.

buyer test / claim to evidence
Editorial illustration of a buyer moving an AI claim through review, evidence, and a human decision gate.
The buyer test — define the claim, rerun the selected control, and inspect the resulting evidence.

HOW TO READ THE DASHBOARD

A grade · 100% displayed coverage · 11 base mappings

Scope

Which deployment, build, policy set, and assessment window produced the result?

Evidence

Which observed events support the mapped controls, and which controls remain untested?

Rerun

Can the buyer select one control and reproduce the result in the evaluated environment?


THE BUYER TEST

Claimed is not documented. Documented is not demonstrated.

Demonstrated is not reproduced. The evaluation is complete only when the buyer can repeat the selected test and retrieve the evidence.

  1. 01

    What was tested?

    Name the workflow, control, source, and expected refusal or outcome.

  2. 02

    Which configuration?

    Record the build, policy set, model route, and assessment window.

  3. 03

    Who had authority?

    Identify the human, AI Worker, role, approval boundary, and reviewer.

  4. 04

    What happened?

    Inspect the observed decision, escalation, refusal, or completed draft.

  5. 05

    Can it be reproduced?

    Ask the buyer to select a control, rerun it, and retrieve the resulting evidence.


FRAMEWORK MAPPINGS

Eleven base templates. Sector extensions kept separate.

A framework mapping organizes evidence for review. It does not certify the product or the customer, determine legal compliance, or replace an independent assessor.

NIST AI RMF

A · 2026-05-05

ISO/IEC 42001

A · 2026-05-05

ISO/IEC 27001

A · 2026-05-05

EU AI Act

A · 2026-05-05

SOC 2 Type II

A · 2026-05-05

PCI DSS v4.0

A · 2026-05-05

HIPAA

A · 2026-05-05

PIPEDA

A · 2026-05-05

OWASP LLM Top Ten

A · 2026-05-05

TBSDADM

A · 2026-05-05

GDPR

A · 2026-05-05

VERTICAL EXTENSIONS

FINRA, FedRAMP, and similar mappings are applied only when the customer's sector, deployment, and evidence requirements make them relevant.

FINRA

US financial services

FedRAMP

US public sector

Privacy Act (Canada)

Canadian public sector


ASSESSMENT OUTPUT

A decision-support report, with its boundary stated plainly.

The general and healthcare self-assessment journeys have completed end to end in a controlled demonstration, including valid PDF output. Fintech has been verified through launch and first question; its full completion and export path is qualified before use. Other sector journeys remain subject to the same check.

The report reflects the deployment evidence and answers in scope. It is not a legal opinion, certification, independent audit, or assurance statement.

For US buyers, the practical drivers include HIPAA enforcement in healthcare, SEC cybersecurity disclosure requirements for public companies, FTC enforcement involving AI claims and data practices, state laws such as the Colorado AI Act, and cyber-insurance underwriting requests for AI-control evidence.

workspace.local / evidence / event
Example governed-workflow event showing sensitive data detected and a boundary decision retained for review.
Example event view — the useful question is whether the buyer can reproduce and retrieve it.

BUYER QUESTIONS

Questions to settle before the first production workflow.

What does the displayed compliance grade mean?
It summarizes control coverage for the assessed Vantage Workspace deployment, loaded policy set, and assessment window. It is not certification, an audit opinion, or assurance about the customer organization.
How should a buyer verify the grade?
Choose one control, rerun it in the evaluation environment, inspect the observed result, and retrieve the corresponding evidence. The build, assessment window, policy set, and evidence version should remain visible.
Which framework mappings are included?
The base set contains eleven mappings: NIST AI RMF, ISO/IEC 42001, ISO/IEC 27001, EU AI Act, SOC 2 Type II, PCI DSS v4.0, HIPAA, PIPEDA, OWASP LLM Top Ten, TBSDADM, and GDPR. FINRA, FedRAMP, and other sector mappings are extensions.
Does an assessment report certify an organization?
No. The report is a structured self-assessment and decision-support artifact for the deployment and answers provided. It does not replace legal advice, an independent audit, certification, or regulatory assurance.
Which assessment journeys have been verified?
The general and healthcare assessment journeys have completed end to end in a controlled demonstration, including valid PDF output. Other sector journeys are qualified during the engagement until their full completion and export path has been verified.

Use the Agentic AI Procurement Workbench to record the decision rights, test prompts, and evidence expected from every vendor.


CONTINUE THE CONVERSATION

Bring one AI workflow to the table.

We will name its source, model route, authority, approval, rejection rule, and evidence, then run a bounded proof your reviewer can challenge.

Review one workflow →

Or write to hello@handvantage.com directly.