Governance Signals
Five deterministic governance signals — implemented and live
The domains (TPRM, DORA, AI Act, CMMC) are markets. The signals are the product. The same five-signal model now runs across four governance domains with no change to the signal logic.
CMMC — Signal mapping live. Illustrative Level 2 / NIST 800-171 Rev 2 mapping; synthetic proofs, not an assessment.
View CMMC signal mapping →
Authority BoundaryDid the action stay within the declared authority limit?
Approval ChainWas the declared approval chain satisfied before the action?
Overlapping BoundariesDid all applicable controls evaluate, and did any fail?
Collective OutcomeDid individually valid actions create an unauthorised collective outcome?
Accumulation RiskDoes cumulative exposure over a rolling window breach a declared limit?
Each signal follows the same pattern:
Declared rule
→
Observed activity
→
Deterministic evaluation
→
Human review
→
Sealed decision record
→
Public verification
Verified examples — sealed on EVE Bridge, cryptographically verifiable:
Synthetic demo records.
No customer data.
Each proof is a sealed decision record.
Not a compliance certification.
From evidence to verification
A traceable path, end to end
Each step is an explicit, inspectable artefact — not a hidden inference.
Assessment seal→
Finding seals→
Document hashes→
Rule IDs→
Rule provenance→
Approved content hash→
Resolver authority→
Human decision records→
Drift signals→
Timeline history
Every node above is a recorded, inspectable artefact. The chain links what was assessed, which rule applied, whether that rule's authority was available, and which human took responsibility for what happened next.
What a seal means
A seal is a verifiability primitive — not a compliance verdict
Precision here matters for audit. EVE is deliberate about what a seal does and does not assert.
✓A seal proves authenticity and immutability of the recorded evidence object.
✓A seal makes the record verifiable.
✗A seal does not prove that the underlying rule is legally correct.
✗A seal does not certify compliance.
Modules
One platform, domain-specific rule packs
Each module uses the EVE evidence-verification pattern: source → rule → evidence → finding → seal → verify → drift → human judgement. Domain maturity may differ; EVE keeps the boundary visible. TPRM and DORA demonstrate the emerging shared evidence-rule model. AI Act is an existing evidence-review demo with planned alignment to the shared finding model.
AI Act
AI Governance Evidence Review
Existing demo · legacy resolver path
- Current demo: Article 9 — Risk Management
- Approved requirements mapping
- Evidence review
- Rule provenance
- Planned alignment to shared finding model
Open AI Act demo
TPRM
Third-Party Risk Evidence Review
🔒 Private preview · hosted workflow
- Vendor evidence assessment
- Supported / Partial / NO_ANSWER
- Evidence coverage
- Sealed assessment records
- Drift comparison
- Timeline
- Five governance signal dimensions (Authority Boundary, Approval Chain, Overlapping, Collective Outcome, Accumulation Risk)
🔒 Open TPRM evidence review
View governance signal layer →
DORA
ICT Third-Party Evidence Review
Hosted demo · source-mapped draft
- Current demo: DORA v0.1 — ICT third-party evidence review
- Source-mapped to approved DORA articles
- Runs on shared evidence_rule resolver
- Supported / Partial / NO_ANSWER
- Strong / weak / empty sample evidence
- Pending customer/SME rule approval
- Human judgement required
- DORA governance signal mapping live
Open DORA demo
View DORA signal mapping →
CMMC
Defense Supply-Chain Evidence Review
Signal mapping · illustrative
- CMMC Level 2 — NIST 800-171 Rev 2 governance signals
- Family-level mapping (illustrative practice IDs)
- Five signals, same model as TPRM/DORA/AI Act
- Synthetic proofs, sealed on EVE Bridge
- Not an assessment or C3PAO determination
- Human judgement required
View CMMC signal mapping
Become a Design Partner
Test deterministic evidence verification on real workflows
EVE Verified is currently being opened to selected governance, audit and third-party risk professionals. We are looking for design partners who want to test deterministic evidence verification on real-world governance, AI Act, TPRM or audit workflows.
Design partners help validate:
- evidence review workflows
- rule provenance
- sealed assessment records
- audit-ready reporting
- temporal validity and drift signals
EVE does not replace professional judgement. The goal is to give reviewers a verifiable evidence trail they can inspect, challenge and rely on.
Sends directly to the EVE Verified team. We’ll reply to your work email within a working day.