Frameworks
Browse by framework
Every control maps to multiple standards and frameworks. Pick a framework to see which controls contribute evidence to its requirements.
- EU AI Act 20 controls
Regulation establishing harmonized rules on artificial intelligence, with risk-tiered obligations from prohibited and high-risk down to limited and minimal risk.
European Union
- ISO 42001 20 controls
Management system standard for AI: requirements for establishing, implementing, maintaining, and continually improving an AI Management System (AIMS) within an organization.
ISO/IEC JTC 1/SC 42
- MITRE ATLAS 10 controls
Adversarial Threat Landscape for AI Systems — a knowledge base of adversary tactics, techniques, and case studies against machine learning systems, modeled after MITRE ATT&CK.
MITRE Corporation
- NIST AI RMF 20 controls
Voluntary framework structured around four functions (GOVERN, MAP, MEASURE, MANAGE) to manage risks of AI systems across the lifecycle.
U.S. National Institute of Standards and Technology
- OWASP Agentic Top 10 4 controls
Ranked list of the most critical security risks for agentic AI systems — combining LLMs with tools, memory, and autonomy.
OWASP GenAI Security Project
- OWASP DSGAI 14 controls
Catalog of data-security risks across the GenAI lifecycle (DSGAI01–DSGAI21) with mitigations, authored by the Data Security Initiative of the OWASP GenAI Security Project.
OWASP GenAI Security Project — Data Security Initiative
- OWASP LLM Top 10 8 controls
Community-led ranked list of the most critical security risks for applications built with large language models.
OWASP GenAI Security Project
- SOC 2 20 controls
Trust Services Criteria covering Security, Availability, Processing Integrity, Confidentiality, and Privacy — the basis for SOC 2 examinations.
AICPA