13 frameworks. One assessment.
Every framework below ships built in, down to the individual requirement: 650+ articles, clauses and controls, seeded and assessable. Map an AI system once and the evidence serves all of them, with no parallel compliance programs.
AI standards & risk
NIST AI RMF
Voluntary framework, published January 2023. Widely referenced by US enterprises and regulators.
72 requirements seeded
The US reference framework for trustworthy AI: four functions — Govern, Map, Measure, Manage — for identifying and managing AI risk across the lifecycle.
Read the guideISO/IEC 42001
Published December 2023. Certifiable management system standard.
32 requirements seeded
The certifiable management system standard for AI: an AIMS that governs how an organization develops and uses AI responsibly, with Annex A controls.
Read the guideISO/IEC 23894
Published February 2023. Guidance standard (not certifiable), companion to ISO 31000 and ISO/IEC 42001.
26 requirements seeded
International guidance for managing AI-specific risk across the lifecycle — the bridge between enterprise risk management and day-to-day AI governance.
Read the guidePrivacy
GDPR
In force since May 2018. Fines up to EUR 20 million or 4% of global turnover.
99 requirements seeded
The EU's data protection law — and a de facto AI regulation wherever models train on or process personal data, or make automated decisions about people.
Read the guideUK GDPR
In force. The UK's post-Brexit data protection regime, enforced by the ICO.
30 requirements seeded
The UK's data protection law — substantively parallel to EU GDPR but separately enforced, with its own guidance on AI and automated decision-making.
Read the guideCCPA/CPRA
In force. CPRA amendments effective January 2023, enforced by the California Privacy Protection Agency.
30 requirements seeded
California's privacy law: consumer rights over personal information, with rulemaking that reaches automated decision-making technology.
Read the guideSecurity & resilience
ISO/IEC 27001
Published (2022 revision). The most widely adopted certifiable security management standard.
118 requirements seeded
The global standard for information security management — and the security backbone AI systems inherit, from access control to supplier risk.
Read the guideNIST CSF 2.0
Published February 2024. Voluntary framework with six functions, including the new Govern function.
22 requirements seeded
The most widely used cybersecurity framework, updated with a Govern function — and increasingly applied to the AI systems inside the enterprise attack surface.
Read the guideSOC 2
Ongoing attestation regime (Type I / Type II). The default B2B trust report in North America.
56 requirements seeded
The attestation enterprise buyers ask for first: independent examination of controls against the Trust Services Criteria — security, availability, confidentiality, and more.
Read the guideOWASP LLM Top 10
Community security standard, actively maintained. The reference list of LLM application risks.
10 requirements seeded
The security community's canonical list of LLM application risks — prompt injection, insecure output handling, supply chain, excessive agency, and more.
Read the guideFinancial services
DORA
Applies since January 17, 2025 to EU financial entities and critical ICT providers.
32 requirements seeded
The EU's operational resilience regime for finance: ICT risk management, incident reporting, resilience testing, and third-party risk — AI dependencies included.
Read the guideOCC Model Risk Management
Long-standing US supervisory guidance for banks; examination expectations extend to AI/ML models.
18 requirements seeded
The US banking supervisor's model risk regime: inventory, validation, and governance for models — now examined with AI and machine learning squarely in scope.
Read the guideFacing more than one of these?
That's the point. See how a single assessment maps your AI systems to every enabled framework at once.