GRC OBSERVABILITY
2 REPOS
CMPL54% NIST67% AI SYS2 THREATS5 LEAKS0
AI INVENTORY →
← REPOS
shipstuff/joeeftekhari.com main · b22bb1a · 4D AGO
  • MACHINE-READABLE
  • JSON (full state)
  • SARIF (code scanning)
  • OSCAL (assessment)
  • CSV
  • NIST CSF controls
  • EU AI Act articles
  • Risk register
  • Vulnerabilities
COMPLIANCE
94%
█████████████ 94%
NIST CSF 2.0
89%
████████████░░ 89%
EU AI ACT
83%
████████████░░ 83%

AI SYSTEMS // 2 DETECTED

PROVIDERSDKCATEGORYLOCATIONRISK TIER
OpenAIopenaiinferencepackage.jsonlimitedTENTATIVE
Anthropicdirect API callinference.grc-scanner/scanner/ai/provider.tslimitedTENTATIVE
RISK TIERprohibited (Art. 5)high (Annex III)limited (Art. 50)minimal
CATEGORYinferencetrainingvector-dbframeworkself-hosted

EU AI ACT COMPLIANCE // 83%

EU █████████████████████░░░░ 83%
2 PASS · 1 PARTIAL · 0 FAIL · 10 N/A
HIGH-RISK 0 · EU MARKET 2
GOVERN
GOV ████████░░░░░░░░ 50%
0P · 1A · 0F · 2 N/A
MAP
MAP ████████████████ 100%
1P · 0A · 0F · 1 N/A
MEASURE
N/A
0P · 0A · 0F · 3 N/A
MANAGE
MAN ████████████████ 100%
1P · 0A · 0F · 4 N/A

ARTICLES // 3 APPLICABLE

IDPHASEARTICLESTATUSNIST AI RMFISO 42001
ART-4GovernAI literacy[!!] PARTIALGOVERN 2.2, GOVERN 3.2A.3.2, A.4.2
ART-9GovernRisk management system[--] N/AGOVERN 1.4, MAP 5.1, MANAGE 1.3A.5.2, A.5.4, A.6.1.2
ART-10GovernData and data governance[--] N/AMAP 2.3, MEASURE 2.2A.7.2, A.7.3, A.7.4
ART-5MapProhibited AI practices[OK] PASSGOVERN 1.1, MAP 1.1A.5.3, A.6.1.2
ART-11MapTechnical documentation[--] N/AMAP 4.1, MEASURE 1.3A.6.2.2, A.6.2.3
ART-12MeasureRecord-keeping[--] N/AMEASURE 2.8, MANAGE 4.1A.6.2.8, A.8.4
ART-15MeasureAccuracy, robustness, cybersecurity[--] N/AMEASURE 2.5, MEASURE 2.7A.6.2.4, A.8.2
ART-27MeasureFundamental Rights Impact Assessment (FRIA)[--] N/AMAP 5.2, MEASURE 3.2A.5.5, A.8.3
ART-13ManageTransparency to deployers[--] N/AGOVERN 4.2, MANAGE 3.1A.6.2.6, A.8.1
ART-14ManageHuman oversight[--] N/AMEASURE 2.6, MANAGE 2.1A.6.2.7, A.9.2
ART-50ManageTransparency obligations for providers and users[OK] PASSGOVERN 5.1, MANAGE 3.2A.8.1, A.9.3
ART-71ManageEU database registration (Annex III high-risk)[--] N/AGOVERN 4.1A.2.3
ART-73ManageReporting of serious incidents[--] N/AMANAGE 4.3A.8.5, A.10.3

GAPS // 1 ARTICLES

IDARTICLESTATUSEVIDENCE
ART-4AI literacy[!!] PARTIALAI systems detected (2). AI literacy is a program-level obligation — document the training your developers and deployers receive.
Scoping. High-risk-only articles (9 / 11 / 12 / 13 / 14 / 15 / 27 / 60 / 73) display N/A unless a high or prohibited system is detected. Articles 27 and 60 additionally require eu_market: true.
Overrides. Hover any tier for its reasoning. Declare risk_tier and eu_market per system under ai_systems: in .grc/config.yml to replace the heuristic.
Caveat. Advisory output — this is not a conformity assessment and does not substitute for review by a notified body.