MAQPNADocs

Generate a compliance evidence pack

Build a signed, auditor-ready evidence pack for the EU AI Act, DORA or ISO/IEC 42001 from the audit ledger, and verify one offline.

An evidence pack is a signed bundle of evidence for one framework, one system and one period. MAQPNA builds it from its own records: the hash-chained audit ledger and the configuration in force. A pack is for an auditor, a regulator or your own compliance team.

The supported frameworks are:

  • the EU AI Act (Regulation (EU) 2024/1689), whose high-risk obligations apply from 2 December 2027;
  • DORA (Regulation (EU) 2022/2554);
  • ISO/IEC 42001:2023, Annex A.

How a pack is built#

flowchart LR
  L[Audit ledger<br/>file or gateway] --> G[maqpna evidence generate]
  K[Cluster configuration<br/>Agents, MCPServers, ToolPolicies,<br/>TrustTiers, SovereigntyPolicies] --> G
  M[Control mapping<br/>eu-ai-act / dora / iso42001] --> G
  G --> P[Pack<br/>manifest.json signed with Ed25519<br/>report.html, report.md<br/>CSV workpapers]
  P --> V[maqpna evidence verify<br/>offline, no licence]

Before you start#

You need:

  • the audit ledger: the gateway URL with an admin token, or a ledger copy from maqpna audit fetch ledger;
  • the audit-checkpoint signing key (--key), so the pack is signed by the same key as the ledger checkpoints;
  • a licence with the evidence-packs feature, as a file (--license or MAQPNA_LICENSE_FILE) or installed in the cluster;
  • cluster access, so the pack can include agents, tools, policy versions, trust tiers and the sovereignty policy. Without it, those controls are reported as partial.

1. Choose the framework#

maqpna evidence frameworks

The list shows each framework's mapping version, review status and how many controls are evidenced, partial or not covered. To see the controls of one framework:

maqpna evidence frameworks eu-ai-act

2. Generate the pack#

Name the system: an agent (team-a/coder), a namespace (namespace:team-a) or a tenant (tenant:acme). Then name the period: a quarter (2027-Q1), a month (2027-01), a year (2027), or --from and --to.

maqpna evidence generate --framework eu-ai-act --system team-a/coder --period 2027-Q1 \
  --gateway https://gateway.example --key /etc/maqpna/checkpoint.key --out coder-2027-Q1.zip

With a ledger copy, pass the JWKS so the pack also verifies the signed checkpoints:

maqpna audit fetch ledger --out audit.jsonl
maqpna evidence generate --framework dora --system namespace:payments --period 2027-01 \
  --ledger audit.jsonl --jwks audit.jsonl.jwks.json --key checkpoint.key --out payments-2027-01

The command prints a status for every control and writes the pack. --out takes a new or empty directory, or a .zip file.

3. Read the report#

Open report.html in a browser. It is self-contained and prints to PDF. For each control, it shows:

  • the status: evidenced, partial or not covered;
  • what the regulation asks for and how MAQPNA supports it;
  • each evidence source, with counts, sample ledger records (seq N) and the workpaper that holds the detail;
  • what MAQPNA does not cover, and the customer's part.

A pack only lowers a control's status. For example, an evidenced control becomes partial when no signed checkpoints were checked, policy versions could not be read, or the hash chain does not verify. The report says why.

The workpapers/ folder holds CSV files for the auditor: approvals, denials by reason, DLP blocks, revocations, policy versions, the agent, tool and model inventory, sandbox tiers and the retention check.

4. Verify a pack#

Anyone can verify a pack offline, without a licence:

maqpna evidence verify coder-2027-Q1.zip --jwks https://gateway.example/v1/audit/jwks

verify checks the Ed25519 signature of manifest.json, the SHA-256 of every file, and that no file was added or removed. It exits with code 3 if the pack was changed. Without --jwks or --pubkey, it checks against the key embedded in the pack and says so. Pass the issuer's key to also confirm who signed the pack.

To tie the pack to the ledger, run maqpna audit verify on the ledger copy. Then compare its head with the head seq and hash in the report.

Limits#

  • Policy versions are those in force when the pack was generated, not a history over the period.
  • The auditor role and XLSX workpapers are planned.
  • A SOC 2 mapping is planned.