Framework coverage derived from live agent inventory and lineage.
Overall coverage
86%
6 of 8 controls covered in this framework
| Control | What Veexa proves | Status | Evidence |
|---|---|---|---|
| SR 11-7Model risk management | Inventory, ownership and validation evidence for 1,237 agents | Covered | |
| GLBASafeguards Rule | Access mapping for customer NPI-touching agents | Covered | |
| PCI DSSCardholder data scope | 3 agents with untraced access to tokenization service | Gap | |
| SOXITGC change control | Change lineage on financial-reporting agents | Covered | |
| FINRA/SEC 17a-4Records retention | WORM-retained interaction logs, 6-year window | Covered | |
| NYDFS 500Cybersecurity program | Shadow agents outside CISO attestation boundary | Gap | |
| DORAICT risk & third party | Third-party model providers mapped per agent | Covered | |
| ECOA / Reg BAdverse action explainability | Decision trace retained for credit-adjacent agents | Covered |
Evidence is current by construction — captured continuously, not a point-in-time snapshot.