The evidence Froga produces, standard by standard.
Twelve standard families. Which part of each Froga addresses for an AI system and how many clauses its catalogue evaluates. What stays outside, on the same page.
DORA · 11 clauses
What the evaluation coversICT risks, protection controls, resilience testing and a dependency inventory.
EN 18286 · 11 of 39 clauses
What the evaluation coversSystem documentation, risk treatment, data, changes and a monitoring plan.
ENS · 4 clauses
What the evaluation coversLifecycle records, a monitoring plan, secure development and a component inventory.
Estatuto de los Trabajadores · 1 clause
What the evaluation coversAlgorithmic transparency towards worker representatives.
ISO 14971 · 10 clauses
What the evaluation coversRisk analysis and control, residual risk, benefit–risk analysis and risks introduced by controls.
ISO/IEC 23894 · 8 clauses
What the evaluation coversAI risk identification, assessment and treatment, with records and a monitoring plan.
ISO/IEC 27001 · 19 clauses
What the evaluation coversSystem security risks, controls and a software component inventory; monitoring and review.
ISO/IEC 42001 · 9 clauses
What the evaluation coversAI risks and impacts, objectives, operational control and system review.
Ley 15/2022 · 1 clause
What the evaluation coversBias minimisation in decision-making algorithms.
MDR · 12 clauses
What the evaluation coversMedical software safety and risks, performance, lifecycle and dependencies.
prEN 18228 · 28 clauses
What the evaluation coversAI risks throughout the lifecycle: testing, controls and residual risk evaluation.
prEN 18229-1 · 6 clauses
What the evaluation coversLifecycle records, foreseeable misuse and controls for human oversight and intervention.
prEN 18282 · 8 clauses
What the evaluation coversCybersecurity threats, resistance to attacks, integrity, access, confidentiality and monitoring.
prEN 18283 · 10 clauses
What the evaluation coversBias, data governance, measurement, mitigation and residual bias monitoring.
Scope is partial and applies to the AI system, not the entire organisation or the whole standard. Counts do not represent a compliance percentage.
If it fits so far, the next step is a conversation.
Let's talk
