Who authorized the action, and what evidence exists?
Supervisors and internal risk functions are converging on two questions about AI in regulated work. Who authorized this action. What evidence exists that it was controlled. Reign is built to help you answer both of them with material a reviewer can test. It does not answer them on your behalf, and it never will.
This page describes frameworks that exist and how our four motions relate to them. It makes no claim about our status under any of them.
No compliance claim. iTmethods makes no compliance, certification or accreditation claim under any framework named on this page. We are not certified against, accredited for, or approved under any of them. Alignment is not compliance. We design against published expectations, map our controls to them, and prepare evidence you can use. The determination belongs to your own risk function, and nothing here transfers it to us.
What each one asks for, and where the motions sit.
Summarised at a high level. Your obligations depend on your sector, your jurisdiction and your use case, and your advisers own that reading.
EU AI Act
It classifies AI systems by risk and places obligations on higher risk uses, including technical documentation, human oversight, record keeping, and monitoring after deployment.
Reign Gateway is the relevant motion for policy at the model boundary and for logging each crossing. Reign Assurance is designed against the record keeping and human oversight expectations. The EU AI Act page →
NIST AI Risk Management Framework
It is a voluntary framework organised around four functions, Govern, Map, Measure and Manage, intended to structure how an organization identifies and treats AI risk across a lifecycle. Its Generative AI Profile applies the same four functions to generative systems.
Reign Ops and Reign Gateway map to Govern and Manage in operational terms. Reign Assurance is designed to produce the artifacts that make Map and Measure demonstrable rather than asserted. The NIST AI RMF page →
ISO/IEC 42001
It is a management system standard for artificial intelligence, requiring policy, defined roles, risk assessment, documented controls and continual improvement, in the same shape as other management system standards.
Reign Ops is the relevant motion, because a management system needs an operated environment with defined ownership rather than a set of intentions. We do not hold it. What we hold, and do not →
OSFI E-23, Canada
It sets supervisory expectations for model risk management at federally regulated financial institutions, covering an enterprise wide framework, lifecycle governance from development through to decommissioning, and treatment proportionate to model risk. It takes effect on 1 May 2027.
Reign Assurance is the relevant motion for lifecycle evidence, with Reign Gateway supplying the boundary controls that make proportionate treatment enforceable. The OSFI E-23 page →
DORA, European Union
It sets digital operational resilience requirements for financial entities in the European Union, covering information and communication technology risk management, incident reporting, resilience testing, and oversight of third party providers.
Reign Ops is the relevant motion, because DORA questions are largely questions about how a service is operated, who operates it, and how it is isolated. How it is deployed and isolated →
United States model risk management expectations
Supervisory guidance in the United States sets expectations for model development, implementation and use, supported by validation and effective challenge performed independently of the people who built the model. SR 26-2 superseded SR 11-7 in April 2026.
Reign Assurance prepares the material that supports validation. It is not the validator, and it never performs effective challenge on your behalf. The model risk and validation page →
On United States public sector questions, we do not hold a FedRAMP authorization, we do not describe ourselves as FedRAMP Ready, and we make no FedRAMP alignment claim.
What a reviewer actually needs.
Not a narrative. A set of facts captured while the work ran, each traceable to a decision and a person.
Authorization
The scope a population of work was permitted to touch, who set it, and the eligibility decision that let each item start. Produced by Reign Gateway, under policy your team configures.
Can you show what was out of scope, as well as what was in it?
Execution
Where the work ran, what it could reach, which model and version was involved at each boundary crossing, and what was supplied. Produced by Reign Gateway and Reign Ops together.
For a single change, can you list every model that saw it?
Decision
Who reviewed, what they changed, what they declined, what merged and when. Produced in your own delivery lifecycle and assembled by Reign Assurance, which is in co-design development.
Would a declined change appear anywhere in your current records?
Reign Ops is available today. Reign Gateway is available today. Reign Factory is in beta and being productized. It is not generally available; beta access is agreed with us and scoped in writing before anything runs. Reign Assurance is in co-design development, and we say so plainly rather than describing it as finished. Where each motion stands is dated on the product status register.
What we will not do.
These are not caveats added by lawyers. They are the boundary that makes the rest of it usable.
No supplier can determine your compliance position, and any supplier who offers to should be treated with suspicion. We can show you how our controls are designed against a framework, and hand you evidence. The conclusion is yours.
We build and operate. Independent challenge has to come from people who are not us, because independence is the property that gives it value. If we validated our own work and you relied on that, you would have less than you started with.
Reign Assurance does not issue certification, attestation, an audit opinion or independent assurance, in any tense. It prepares the record. Reign prepares; people decide.
We make no CMMC, CUI or ITAR claim. We do not publish our own certification scopes on a marketing page. Those questions are answered under a briefing, with documents, to the people whose job it is to read them.
Read this with your own advisers. Nothing on this page is legal or regulatory advice, and it does not describe your obligations. Frameworks change, and their application depends on your sector, jurisdiction and use case. Reign is aligned to the frameworks named above. It is not certified against any of them, no product can be, and no product makes an institution compliant with one. No authority responsible for any of them endorses, approves or recommends Reign or iTmethods.
Bring your risk function to the first meeting.
The questions worth asking on this subject are theirs, not ours. We will walk one population of work from request to merge and let them judge whether the record holds.