Standard Intelligence

From Obligation to Evidence: A Methodology for Multi-Regulatory AI Governance

AI GovernanceRegulatory Technology

A single AI system rarely sits under a single rulebook. A clinical decision-support tool sits under the EU AI Act, the Medical Devices Regulation, the GDPR and NIS2 at once, while also carrying ISO 42001 and ISO 27001 commitments — an obligation set that can run to hundreds of discrete requirements drawn from seven or more instruments.

This is a structural problem, not an incidental one. The EU AI Act was designed to sit alongside existing sectoral, data-protection, cybersecurity and product-safety law, so horizontal AI rules layer on top of vertical ones rather than replacing them. Programmes that tackle each framework separately duplicate documentation, leave gaps where obligations fall between frameworks, and classify the same system inconsistently.

The pressure is live. EU AI Act prohibitions have applied since February 2025 and general-purpose obligations since August 2026. ISO 42001 is becoming a procurement requirement, and the revised Product Liability Directive now treats AI systems as products under strict liability — making a demonstrable compliance history part of an organisation's litigation defence.

The TRACE lifecycle

TRACE is a five-phase governance lifecycle that reduces that response to five. Trace maps which rules apply to each system. Rate classifies risk and decomposes obligations. Architect builds controls into the system. Control runs monitoring and oversight continuously. Evidence maintains audit-ready proof of conformity.

A five-level maturity model — from Ad Hoc to Leading — lets an organisation locate its capability across distinct domains and plan a proportionate path forward.

Why the atomic obligation matters

The unit of work is the atomic obligation: a single, testable requirement traced to its source article. Modelling obligations this way — rather than as documents — is what lets one control satisfy several frameworks at once, and what makes a gap visible the moment a new instrument lands.

The full paper covers the design principles, the governance cadence, the interoperability with ISO 42001, NIST AI RMF and ISO 27001 board-level accountability, and worked outcomes across healthcare, financial services and enterprise technology.

Stay informed

Practical insights on EU AI Act compliance delivered to your inbox. No spam, unsubscribe any time.

We use cookies to improve your experience and analyse site traffic.

From Obligation to Evidence: A Methodology for Multi-Regulatory AI Governance