Browse documentation
Help Centre · 6 articles
Programmes
How a framework becomes a path: phases, steps, gates, the SoA, overlap credit.
01Programmes: a standard as a path, not a listSwitch a framework on and it becomes a programme — ordered steps in gated phases, each producing a record. The standards stop being a checklist you tick and become work you do once.02Phases and gates: why the next step is lockedEach programme runs in phases; a phase is locked until the one before it is complete. The same rule the EU AI Act journey uses, applied to the standards — plus the GDPR bucket that sits outside the path.03Steps: Aria drafts, a person approves, then it countsOpen a step, answer its questions or let Aria draft from what you already have, then approve. Only approval files the record as evidence and creates the control.04Overlap credit: done by overlap, never done twiceA record that satisfies a clause in two frameworks is one record. A step whose every requirement is already evidenced elsewhere is marked done by overlap — with the record that did it.05The Statement of Applicability, generated from what you didThe SoA is a view over your controls and records, not a spreadsheet you fill. Every Annex A control is listed; an exclusion needs a justification sentence.06Coverage and the auditor: the matrix, the seat, the packFrameworks → Coverage shows every requirement and the workflow assigned to it. Give your auditor a read-only seat and the records; the certificate comes from them, not from us.