Compliance Tools
Every compliance acronym and concept used in Quox, explained in plain English. Each entry tells you what it means and how Quox handles it.
Also available as a searchable in-product tool at Compliance Command Center → Glossary.
Frameworks
| Term | Definition | Quox coverage |
|---|
| SOC 2 | AICPA audit standard. Type II = tested over a period (6-12 months). | CC6/CC7/CC8/PI1/A1 formatter with scope, attestation, type guidance |
| ISO 27001 | International Information Security Management standard. 2022 revision has 93 Annex A controls. | SoA Builder + Annex A formatter |
| GDPR | EU data privacy law. Fines up to 4% of global revenue. | Article-by-article formatter + DPIA form + DSAR guidance + Art.28 processor assessment |
| HIPAA | US law for electronic Protected Health Information. | 54-safeguard Risk Analysis with BAA assessment |
| EU AI Act | Regulation (EU) 2024/1689. Classifies AI by risk tier. | Free Risk Classifier + operator matrix + GPAI obligations + QMS + classification memo |
| ISO/IEC 42001:2023 | First international AI Management System standard. | Clauses 4-10 formatter + AI System Lifecycle Record guidance |
| NIST AI RMF 1.0 | Voluntary US framework. Govern/Map/Measure/Manage. | 22-control formatter with AI system profile + cross-framework mappings |
Quox Protocols
| Protocol | Full name | Purpose |
|---|
| AEE | Agent Envelope Exchange | Structured audit trail wrapping every agent interaction (14 fields per envelope) |
| AOCL | Agent Orchestration Control Layers | 11-layer processing stack (L0-L10). Identity, policy gates, verification, audit commit |
| VOLT | Verifiable Operations Ledger & Trace | Append-only hash chain. Tamper = chain breaks detectably |
| WARD | Write-once Append-only Receipt Digests | External timestamps (RFC 3161) + Ed25519 signatures on VOLT tips |
Compliance concepts
| Term | Definition |
|---|
| SoA | Statement of Applicability — ISO 27001 document listing every Annex A control and your decision about it |
| DPIA | Data Protection Impact Assessment — GDPR Art.35 risk assessment for high-risk processing |
| DPO | Data Protection Officer — responsible for GDPR compliance |
| PBC List | Prepared by Client — evidence your auditor requests from you |
| Working Papers | The auditor's record of what they tested and what they found |
| IPE | Information Produced by Entity — system-generated evidence the auditor must verify |
| Assurance Pack | Signed JSON bundle: WARD chain + VOLT bundles + audit events for a period |
| Redaction | Stripping secrets, IPs, and sensitive data before sharing externally |
| HITL | Human-in-the-Loop — approval workflow requiring human authorisation |
| CUECs | Complementary User Entity Controls — controls your customers must implement |
| ROPA | Records of Processing Activities — GDPR Art.30 register |
Audit terms
| Term | Severity |
|---|
| Material Weakness (SOC 2) | Most severe. Qualified audit opinion. |
| Significant Deficiency (SOC 2) | Less severe but requires attention. |
| Major Nonconformity (ISO 27001) | Blocks certification until fixed. |
| Minor Nonconformity (ISO 27001) | Must be closed by next surveillance audit. |
| Observation / OFI (ISO 27001) | Opportunity for improvement. Not a failure. |
| Addressable (HIPAA) | Must assess — then implement, equivalent, or document why not. NOT optional. |
| Required (HIPAA) | Must implement. No exceptions. |
EU AI Act risk tiers
| Tier | Examples | Obligations |
|---|
| Prohibited | Social scoring, real-time biometric surveillance | Don't build |
| High-Risk (Annex I) | Safety component of regulated product | Full conformity assessment |
| High-Risk (Annex III) | Hiring, education, law enforcement | Same + post-market monitoring |
| GPAI with Systemic Risk | Frontier foundation models (>10²⁵ FLOPs) | Model eval + adversarial testing |
| GPAI Standard | Most commercial LLMs | Transparency + technical docs |
| Limited Risk | Chatbots, deepfake generators | Must disclose AI |
| Minimal Risk | Internal analytics | AI literacy training (Art.4) |
Numbers to remember
- 93 — ISO 27001:2022 Annex A controls
- 54 — HIPAA safeguards
- 7 — EU AI Act risk tiers / frameworks Quox supports
- 11 — AOCL processing layers (L0-L10)
- 14 — Fields in an AEE envelope
- 3 — Report redaction levels (internal / external / public)