Your framework, mapped to real controls.
Every framework on this page covers far more than AI, and Verillian speaks to a specific slice of each: whether you can control what your AI does, and whether you can prove what it did. Here's that slice, framework by framework, in the language your assessor reads.
Which frameworks does Verillian map to?
Six families cover most regulated work, and each row below puts one next to the controls Verillian brings to it, so your reviewer can read straight down.
Criminal justice information. Access controls and the audit record line up with CJIS Security Policy v6.1. If the record can't be written, AI stops. Hash-chaining goes further than the policy asks.
Protected health information. Patient identifiers are screened on the device before a prompt goes anywhere. Everything captured is encrypted under your own keys. The record can be held for HIPAA's six-year documentation window.
Federal information systems. Deny-by-default policy is signed and distributed to every device, with the access and audit behavior mapped to the NIST 800-53 control families your assessment reads from.
Controlled unclassified information. It runs on your own hardware, keys never leave the device, and policy is enforced the moment an AI touches CUI. That's how NIST SP 800-171 and CMMC 2.0 assessments expect controlled data to be handled.
Student records. Student data is screened on the device before a prompt reaches a provider. Every decision lands in a record your district or institution holds, not a vendor, and where COPPA is in play for younger students, that record shows exactly what a tool was given.
Financial services. Every AI tool and agent that reaches a governed provider is governed under one policy. The signed record gives supervision and recordkeeping reviews something to check, not something to believe, whichever yardstick your reviewer brings: GLBA safeguards, SOX internal controls, or SR 11-7's documentation habits.
Alignment means the controls exist and the mapping is documented. Certification is a property of your deployment, and we won't borrow the word.
The rules you answer to already ask for a record
You don't need a new federal law to need an audit trail. CJIS Security Policy v6.1 expects auditable records around criminal justice information, HIPAA's audit controls at 45 CFR 164.312(b) ask for the means to record and examine activity in systems that touch patient data, and your retention schedules already reach the work AI helps produce. Verillian treats those existing obligations as the spec: policy enforced where the AI acts, and a tamper-evident record of every captured interaction to answer from.
CJIS Security Policy v6.1 expects access to criminal justice information to be auditable. Verillian's access controls and audit record line up with that policy, aligned, not certified, because CJIS compliance is validated through FBI and state CJIS audits, not vendor certification.
45 CFR 164.312(b) asks for mechanisms that record and examine activity in systems handling patient data. When AI becomes one of those systems, the sealed record gives your compliance team something to examine rather than something to assert.
Retention schedules and public-records obligations don't pause because a draft came from AI. The record of every captured interaction is kept under your keys, on your infrastructure, for as long as your schedule says.
California SB 524 already requires a law-enforcement report drafted with AI to say so, and the agency to keep a record of it. It's narrow and specific, and it points the same way the older rulebooks do: keep the record.
Want the control-by-control detail?
Name the frameworks that matter to you and we'll send the full mappings for your audit prep. Or start with the architecture the mappings rest on.