Why existing standards are not enough
Current governance frameworks do two things well: they evaluate systems before deployment, and they analyze failures after they happen. The gap — the moment where execution actually occurs — is left unaddressed.
The table below is SnapOS's own reading of what these frameworks cover, based on the cited articles and public scope statements — not a legal opinion, an official interpretation by the standard-setting body, or a claim of legal equivalence. Gaps are stated relative to the references analyzed, not as an absolute claim that no other mechanism anywhere addresses them.
| Standard / Framework | What it addresses | What it misses |
|---|---|---|
| EU AI Act (Art. 9, 17) | Risk management, quality management, technical documentation | Whether the authorized mandate still matches operational state after deployment |
| ISO/IEC 42001 | AI management system requirements | A mechanism for detecting mandate drift in live systems |
| Model risk management (EBA, ECB) | Model validation, performance monitoring | Whether the decision identity has changed without the model changing |
| SOC 2 / ISAE 3402 | Controls over service organization operations | Decision-level continuity and re-legitimation requirements |
| Monitoring dashboards | Threshold violations, latency, accuracy metrics | Whether the decision being executed is still the decision that was authorized |
This is not a criticism of existing frameworks. They address real and important concerns. In the references analyzed, the gap they leave is structural — it is the layer between approval and ongoing legitimacy that has not yet been formalized. SnapOS maps its Decision Integrity controls to this gap as an interpretive mapping, not a legal equivalence claim. That is the layer Decision Integrity defines. Read the full field definition →
This matrix reflects SnapOS's own interpretive reading of the referenced frameworks' public scope, not a certification, legal opinion or equivalence claim.