Documentation

Operate · Guide 06

Compliance templates

Start from operational control narratives for 20 common frameworks, then adapt, confirm and publish only what applies to your organization.

6 min read

Pre-release documentation. This guide describes the current product design and evaluation build. Packaging, availability and commercial terms may change before release.

01

What a template contains

A template contains Avery-authored operational control narratives with clause references and declared exclusions. It is designed for the subset of a framework that a runtime compliance gate can apply.

  • AI: EU AI Act and NIST AI RMF
  • Security and controls: SOC 2, ISO 27001, FedRAMP Moderate, PCI DSS and SOX ITGC
  • Privacy: GDPR, UK GDPR, CCPA/CPRA, LGPD, PIPEDA, India DPDP, Singapore PDPA and Australian Privacy Principles
  • Sector and resilience: HIPAA, GLBA, SEC/FINRA, DORA and NIS2
02

Nothing arrives in force

Installing a template creates proposals in the same review queue as material compiled from your own documents. No template, including Avery-authored content, can confirm itself.

avy templates
avy templates install gdpr --rulebook compliance
avy review --rulebook compliance
avy publish compliance
03

Upgrades preserve control

  • New controls arrive as proposals
  • Changed controls lose prior confirmation and return to review
  • Withdrawn controls are journalled
  • Local edits and rejections remain visible
  • Nothing changes in production until a new version is published

Executive briefing

Apply the architecture to one consequential workflow.

Bring one consequential agent workflow. We will map the governing policies and regulations, runtime gate, human authority and auditable evidence path with your team.

Request a briefing