Recce · Governance & Compliance

AI compliance
mapped to controls.

Recce maps every security control to the major AI governance frameworks — globally and across the MENA region — giving compliance teams a single pane for attestation, audit, and evidence collection.

OWASP LLM Top 10

Full coverage of the OWASP LLM Top 10.

From prompt injection to unbounded consumption — Recce addresses every risk in the OWASP Top 10 for Large Language Model Applications with purpose-built Band C controls, output filtering, and telemetry.

Recce compliance with OWASP LLM Top 10: LLM01 Prompt Injection through LLM10 Unbounded Consumption, each with Recce control mapping

OWASP LLM Top 10 · LLM01 Prompt Injection · LLM02 Sensitive Info Disclosure · LLM03 Supply Chain · LLM04–LLM10 · NeMo Guardrails · OPA · Band C controls

International Standards

Mapped to 8 global AI governance frameworks.

Twelve Recce capability domains mapped across every major AI security and governance standard — one control layer that satisfies all frameworks simultaneously.

Recce Compliance Mapping table showing 12 AI capability domains mapped to ISO/IEC 27001, EU AI Act, NIST AI RMF, UAE AI Guide, ISO/IEC 23894, OECD AI Principles, OWASP LLM Top 10 for Apps, and CIS AI Controls v1.0

Recce Compliance Mapping · 12 domains · ISO/IEC 27001 · EU AI Act · NIST AI RMF · UAE AI Guide · ISO/IEC 23894 · OECD AI Principles · OWASP LLM Top 10 · CIS AI Controls v1.0

MENA Region  ·  Gulf & North Africa
Regional Coverage

Purpose-built for MENA AI governance.

Recce maps to every major MENA-region AI and cybersecurity framework — from Saudi Arabia's SDAIA AI Control Guidelines and the UAE Information Assurance Standard to Qatar's CTRM, Oman's NCSF, Bahrain's NCA Guidelines, and Egypt's Cybersecurity Authority controls.

🇸🇦 KSA AICG (SDAIA)
🇦🇪 UAE IAS (TDRA)
🇸🇦 KSA NCA ECC
🇶🇦 Qatar CTRM (NCSC)
🇴🇲 Oman NCSF (NCA)
🇧🇭 Bahrain NCA Guidelines
🇪🇬 Egypt ECA
ISO/IEC 27001 Regional Adoption
Recce Compliance Mapping for MENA Region — 12 AI capability domains mapped to KSA AICG, UAE IAS, KSA NCA ECC, Qatar CTRM, Oman NCSF, Bahrain NCA Guidelines, Egypt ECA, and ISO/IEC 27001

MENA Compliance Mapping · KSA AICG (SDAIA) · UAE IAS (TDRA) · KSA NCA ECC · Qatar CTRM (NCSC) · Oman NCSF · Bahrain NCA · Egypt ECA · ISO/IEC 27001

Platform · Evidence & Controls

Audit-ready evidence, always on.

Recce surfaces policy decisions and audit events in real time — so evidence collection is continuous, not a last-minute scramble before your next audit.

Policy Registry
Recce Policy Registry showing three active governance policies with BLOCK and WARN actions across Band A and Band B
Policy Registry
Active policies · Block / Warn actions · Band A & B scope
Band D · Audit Log
Recce Audit Log showing 140 total events including prompt injection blocks, signature failures and document quarantine actions
Audit & Telemetry Log
140 events · Prompt injection · Quarantine · SIEM pipeline
AI Risk & Governance

A governance posture for high-risk AI.

Recce gives compliance and risk teams the technical evidence layer they need to satisfy board-level AI governance requirements.

EvidenceAudit Trail

Continuous Evidence Collection

Every allow/block decision across Bands A–D is written to an immutable, timestamped audit log. Evidence is queryable, exportable, and audit-ready.

PolicyCentralised Control

Policy-as-Code Governance

OPA policies define what can enter, deploy, and execute across your AI estate. Policy changes are versioned, reviewed, and traceable.

RiskContinuous Testing

Living Risk Posture

Garak red-team probes run continuously. The compliance scorecard updates after each run — not just at annual audit time.

ReportingSOC Integration

SOC-Ready Reporting

Telemetry streams directly to your existing SIEM. Risk events are classified and routed before they reach a human analyst.

Get Started

Ready for your next AI audit.

Request a compliance mapping session. We'll walk through which Recce controls satisfy which clauses in your target framework.