---
title: "Governance and compliance"
description: "Governance in BRAIAN by AETERION means controls enforced by the runtime and evidence produced by it. Policies constrain what agents may do, the audit log records what they did, and evaluation shows how behaviour changed between versions. This section maps those mechanisms to the EU AI Act, the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP)."
url: "https://aeterion.tech/en/docs/governance-and-compliance"
locale: "en"
publisher: "AETERION SA"
---
# Governance and compliance

> Governance in BRAIAN by ÆTERION means controls enforced by the runtime and evidence produced by it. Policies constrain what agents may do, the audit log records what they did, and evaluation shows how behaviour changed between versions. This section maps those mechanisms to the EU AI Act, the General Data Protection Regulation (GDPR) and the Swiss Federal Act on Data Protection (nFADP).

Source: https://aeterion.tech/en/docs/governance-and-compliance
Last updated: 2026-09-20

## Evidence produced by the runtime

- Records of automated decisions with inputs, outputs and the model version used.
- Human oversight records: who approved what, when, and with which amendment.
- Policy change history, including who activated a control in which environment.
- Evaluation results per process version, showing behaviour changes over time.

## Mapping to obligations

- **EU AI Act** — Human oversight, logging, transparency of automated decisions and technical documentation of the deployed system.
- **GDPR** — Lawful processing boundaries, data minimisation through field policies, and records of processing activities.
- **Swiss nFADP** — Processing within Swiss residency boundaries and disclosure of automated individual decisions.
- **ISO/IEC 27001 and 42001** — ÆTERION is preparing for certification against both standards; no certification is held today.

## Division of responsibility

ÆTERION supplies the software, its controls and the evidence it produces. The customer decides which processes are automated, which thresholds apply and who approves escalations. Regulatory classification of a use case remains with the organisation deploying it.

> **Certification status** — ISO/IEC 27001 and ISO/IEC 42001 are in preparation and SOC 2 Type II is planned. The Trust Center states the current status; no certification is claimed before it is issued.

