Evidence kinds/Operator-supplied control (gap)
Operator-supplied control (gap)
audit output evidence
Honest acknowledgement of obligations the substrate doesn't directly cover.
What it is
Not every regulatory obligation maps to a Promethean evidence kind. The substrate covers the AI-decisioning slice; the operator's broader compliance programme covers everything else.
Each framework handoff packet (Enterprise tier) carries an explicit 'operator must also' section per article — what the substrate emits + what the operator still owes. This is the structural anti-vendor-lock-in move: we're not pretending Promethean is the complete compliance answer.
Examples of operator-supplied controls: training-data governance (AI Act Art. 10), risk-management process design (Art. 9), DPIA + FRIA (GDPR Art. 35), business-continuity + DR planning (DORA Art. 11), clinical evaluation (MDR Art. 61), BAA with covered-entity customers (HIPAA §164.504), conformity assessment + CE marking (AI Act + MDR), licensing under PSD3, AML/CFT under AMLD.
What it guarantees
- Explicit acknowledgement of gaps per framework template.
- Per-article 'operator must also' statements in handoff packets.
- Trust-building anti-pattern recognition: we name the things we don't do.
What it does NOT guarantee
Honest limits. Every primitive has them.
- Anything by definition — this is the negative-space evidence kind, the explicit non-coverage.
Regulations that engage this kind
All frameworks
Every article has an operator-side complement
Sectors that rely on this kind
Related evidence kinds
FAQ
Why call out what you don't do?
Because vendor lock-in lives in 'we solve everything' framing. The truth is Promethean is the per-decision AI-decisioning evidence layer; broader compliance is operator-side product/legal/risk-management work. Naming the gap is the trust-building move. Compliance teams + auditors prefer vendors that are explicit about scope.