Evidence kinds/Operator-supplied control (gap)

Operator-supplied control (gap)

audit output evidence

Honest acknowledgement of obligations the substrate doesn't directly cover.

What it is

Not every regulatory obligation maps to a Promethean evidence kind. The substrate covers the AI-decisioning slice; the operator's broader compliance programme covers everything else.

Each framework handoff packet (Enterprise tier) carries an explicit 'operator must also' section per article — what the substrate emits + what the operator still owes. This is the structural anti-vendor-lock-in move: we're not pretending Promethean is the complete compliance answer.

Examples of operator-supplied controls: training-data governance (AI Act Art. 10), risk-management process design (Art. 9), DPIA + FRIA (GDPR Art. 35), business-continuity + DR planning (DORA Art. 11), clinical evaluation (MDR Art. 61), BAA with covered-entity customers (HIPAA §164.504), conformity assessment + CE marking (AI Act + MDR), licensing under PSD3, AML/CFT under AMLD.

What it guarantees

  • Explicit acknowledgement of gaps per framework template.
  • Per-article 'operator must also' statements in handoff packets.
  • Trust-building anti-pattern recognition: we name the things we don't do.

What it does NOT guarantee

Honest limits. Every primitive has them.

  • Anything by definition — this is the negative-space evidence kind, the explicit non-coverage.

Regulations that engage this kind

All frameworks

Every article has an operator-side complement

Sectors that rely on this kind

Related evidence kinds

FAQ

Why call out what you don't do?

Because vendor lock-in lives in 'we solve everything' framing. The truth is Promethean is the per-decision AI-decisioning evidence layer; broader compliance is operator-side product/legal/risk-management work. Naming the gap is the trust-building move. Compliance teams + auditors prefer vendors that are explicit about scope.