You'll want: Northbeams Evidence
You inherited "AI governance" between the SOC 2 cycle and the EU AI Act deadline. Northbeams is the evidence layer that produces, signs, and delivers AI control evidence to your auditor and your GRC platform. So when the auditor asks, you click Download.
If you're the one person who has to evidence AI across the company, this is the page for you.
You don't need another policy template. You need the artifact. The auditor reads pages, not promises.
01 / The asks landing on your desk in 2026
The same telemetry produces evidence for every framework your buyers, regulators, and insurers will ask about. One pack per framework. One control mapping. One signature.
38 controls. Status per control. Evidence sources. Owners. Exceptions with deadlines.
Answer: Evidence Pack · ISO 42001 variant · 9 pages · signed.
Deployer obligations enforceable December 2026. Logging, human oversight, monitoring. 6-month minimum retention.
Answer: Evidence Pack · EU AI Act variant · matched to 26(1) through 26(7).
Question 41 on every modern vendor security questionnaire. Notion doc + shrug loses the deal.
Answer: Attach Northbeams Evidence Pack. Done in under a minute.
CC6.1, CC7.2, and the CSA AI Controls Matrix. Auditor wants an evidence appendix annexed to the existing Type II.
Answer: Evidence Pack · SOC 2 + AI variant · staples onto your existing report.
02 / How it lands
01 · Install
Browser extension via Chrome Web Store. Desktop app via MDM (Intune, Jamf, Kandji). No proxy, no MITM cert, no network change. The IT lead deploys this; you don't need to fight for it.
02 · Map
ISO 42001, EU AI Act, NIST AI RMF, SOC 2 + AI. Northbeams maps each control to AUTO / ATTEST / scoped-out. Re-classify rows with reasons. The scope statement is yours; you sign it.
03 · Ship
Pull a pack before a vendor questionnaire, before an audit, or on a monthly schedule. Webhook your GRC platform so it pulls a fresh pack on every control-status change.
03 / Honesty about scope
Auditors trust scoping more than blanket claims. Here's what Northbeams' evidence layer covers, and what it doesn't, in writing, on the page they're reading.
In the box
Not in the box
04 / Compliance tier
Compliance buyers don't think in seats. The Compliance tier is a line item with a number on it.
Starter
$12,000 / yr1 framework. Monthly Evidence Pack. 1 GRC integration. 90-day retention.
Pro
$36,000 / yrAll frameworks. On-demand + scheduled. All integrations. Continuous monitoring + alerts.
Enterprise
$72,000+ / yrSSO, custom controls, 7-year retention, dedicated CSM, contractual SLAs.
Bundle with per-seat Sentinel for an extra 15% off the per-seat side. See full pricing →
Forward the sample to your auditor. Ask them what's missing. We'll iterate the format with you. Build partners are how we got here; we want more.