DORA & NIS2 AI governance evidence
Prove that AI agent skills are governed, trained, approved, and reviewable.
Bakara helps security teams create evidence around AI skills, role-based loadouts, training prerequisites, approvals, exceptions, usage, and review history.
The evidence gap
Cybersecurity regulations increasingly expect organizations to demonstrate governance, training, access control, resilience, and management accountability. At the same time, AI agents are gaining access to business systems, sensitive data, developer tools, and operational processes.
Security teams may know who completed training, but not which AI capabilities those users or agents can actually access.
Bakara helps close that gap by turning AI capabilities into governed loadouts with owners, approvals, training prerequisites, monitoring, and audit evidence.
Evidence categories
Six categories of AI capability evidence.
AI skill inventory
Evidence to show:
- Which AI agents and AI-enabled workflows exist
- Which skills, tools, connectors, and permissions they can use
- Which systems and data types they can access
- Who owns each AI capability
- Which capabilities are considered high risk
Role-based access
Evidence to show:
- Which roles or teams can access each AI capability
- Which capabilities are restricted, blocked, or approval-based
- Whether access is aligned to least privilege
- Whether access is reviewed periodically
- Whether exceptions expire
Training and awareness
Evidence to show:
- Which modules are required for each role
- Whether training is completed before high-risk skills are enabled
- Whether policy acknowledgment is recorded
- Whether training status affects AI access
Approval and accountability
Evidence to show:
- Who approved each AI skill or loadout
- Who owns each AI agent or workflow
- Which skills require human oversight
- Which changes were reviewed
- Which exceptions were granted and why
Runtime and drift
Evidence to show:
- When AI skills are used
- When an agent gains a new tool, connector, or permission
- When a skill is used outside the approved loadout
- When a restricted capability is attempted
- How risky changes are investigated
Audit and board reporting
Evidence to show:
- Current AI capability risk posture
- High-risk AI skills by business unit
- Training coverage by role
- Open exceptions and recent changes
- Review status and evidence export
How Bakara supports readiness
Map expectations to controls and evidence.
Regulatory expectation
Training and awareness
Bakara control / evidence
Maps training prerequisites to AI skills and role-based loadouts.
Regulatory expectation
Access control and least privilege
Bakara control / evidence
Defines which AI capabilities each role, team, or agent is allowed to use.
Regulatory expectation
Governance and accountability
Bakara control / evidence
Records owners, approvers, review status, and exception history.
Regulatory expectation
Operational resilience
Bakara control / evidence
Helps monitor changes to AI capabilities, tools, workflows, and permissions.
Regulatory expectation
Audit evidence
Bakara control / evidence
Exports evidence for inventory, training, approvals, usage, exceptions, and reviews.
Regulatory expectation
Management reporting
Bakara control / evidence
Provides board/CISO-ready views of AI capability risk and governance status.
Make AI agent governance visible before the audit.
Bakara helps security teams create a live evidence trail for AI capabilities, training prerequisites, approvals, access decisions, exceptions, and reviews.
Bakara supports AI governance, security operations, and audit-readiness workflows. Regulatory obligations vary by organization, jurisdiction, use case, and implementation. This material is not legal advice.