Inspectable today
Connected registers, risk calculations, evidence freshness, review gates, JSON import/export and source-controlled policy examples.
Open operating suite →
ABDULLAH AL OWASIGovernance architecture / decision to evidence
Bring AI systems, suppliers and security controls into a reviewable operating model. Follow the evidence from its source to the decision it supports.
Discuss your governance scope ↗Connected operating model
Automated calculations support accountable review. A passing test requires evidence, a named reviewer and a test date; expired evidence stops counting toward current coverage.
Assets, AI use cases, vendors, data and applicable obligations.
Inspect workflow →Ownership, access boundaries, risk appetite and release gates.
Inspect workflow →Link each control to its obligation and risk. Assign owners and tests.
Inspect workflow →Normalize authorized source exports; retain provenance and review dates.
Inspect workflow →Resolve evidence gaps, assign treatment and record the decision owner.
Inspect workflow →Recalculate coverage and risk after source changes or evidence expiry.
Inspect workflow →The public workspace recalculates on interaction. Repository collectors and policy files support integration development; no live cloud collectors run behind this public page.
Extensible coverage
This review taxonomy covers 22 enterprise areas and 7 technical areas. It is an editable starting point, not an exhaustive industry standard. Framework associations guide scoping; they are not an assertion of equivalence, certification or complete control implementation.
| Review area | Framework anchors | Inspectable workflow and output |
|---|---|---|
| Corporate governance & accountability | ISO/IEC 27001 clauses 4–6; NIST SP 800-53 PM | Named owners, decisions and review dates → |
| Enterprise risk & appetite | NIST SP 800-53 RA; ISO/IEC 27001 clause 6 | Likelihood, impact, treatment and acceptance → |
| Regulatory applicability & change | GDPR; EU AI Act; NIST SP 800-53 PL | Jurisdiction, applicable requirement and effective date → |
| Policy lifecycle | ISO/IEC 27001 clause 7; NIST SP 800-53 PL | Version, ownership and attestation → |
| Control implementation & ownership | NIST SP 800-53; ISO/IEC 27001 Annex A; SOC 2 TSC | Requirement → control → owner → |
| Internal audit & independence | ISO/IEC 27001 clause 9; NIST SP 800-53 CA | Plan, finding and corrective action → |
| External audit & certification readiness | SOC 2 TSC; ISO/IEC 27001 clauses 9–10 | Reviewed tests and dated evidence → |
| Continuous assurance & remediation | NIST SP 800-53 CA-7; SOC 2 CC4 | Evidence expiry, failed tests and treatment → |
| Supplier lifecycle & concentration | NIST SP 800-53 SR; ISO/IEC 27001 Annex A | Tier, dependencies and exit conditions → |
| Procurement & customer assurance | SOC 2 CC9; NIST SP 800-53 SR | Requirements and evidence-backed answers → |
| Privacy & individual rights | GDPR Articles 5, 12–22, 25, 35 | Purpose, retention and impact review → |
| Processors & cross-border transfers | GDPR Articles 28, 30, 44–49 | DPA, subprocessors and transfer mechanism → |
| Data classification & retention | GDPR Article 5; NIST SP 800-53 MP, PT | Data owner, classification and deletion review → |
| AI inventory & lifecycle authorization | NIST AI RMF; ISO/IEC 42001 | Inventory, evaluation and deployment decision → |
| AI fairness, safety & oversight | NIST AI RMF MEASURE/MANAGE; ISO/IEC 42001 | Evaluation findings and human review gates → |
| AI transparency & content provenance | EU AI Act Article 50 | Disclosure decision and evidence → |
| Shadow AI & acceptable use | NIST AI RMF; ISO/IEC 27001 Annex A | Use-case intake and egress review → |
| Continuity, recovery & crisis readiness | NIST SP 800-53 CP; ISO/IEC 27001 Annex A | Critical services, recovery objectives and exercise evidence → |
| Incident governance & reporting | NIST SP 800-53 IR; GDPR Articles 33–34 | Incident owner, escalation and corrective action → |
| Workforce, physical & organizational security | NIST SP 800-53 AT, PS, PE; ISO/IEC 27001 Annex A | Control and review records; specialist assessment required → |
| Financial, fraud & ethical conduct risk | NIST SP 800-53 PM, RA | Exposure and risk decisions; specialist assessment required → |
| Sector, market & contractual obligations | FedRAMP Rev5 when in scope | Applicability review; sector-specific controls require scoping → |
| Review area | Framework anchors | Inspectable workflow and output |
|---|---|---|
| Security scope & authorization boundary | NIST RMF; NIST SP 800-53 PL-2, CA-3 | Asset scope and system boundary; deployment architecture review → |
| Identity, least privilege & segregation | NIST SP 800-53 AC, IA; SOC 2 CC6 | IAM evidence and authorization policy source → |
| Cloud configuration & change | NIST SP 800-53 CM; SOC 2 CC8 | Configuration events and control decisions → |
| Threat, vulnerability & supply-chain assurance | NIST SP 800-53 RA-5, SI-2, SR | Alert normalization and remediation priorities → |
| Logging, evidence integrity & provenance | NIST SP 800-53 AU; SOC 2 CC7 | Source timestamps and evidence validation → |
| Agent, tool & data authorization | NIST SP 800-53 AC; NIST AI RMF | Agent/tool authorization policies and human escalation → |
| Assessment, authorization & ongoing monitoring | NIST SP 800-53 CA-2, CA-6, CA-7; FedRAMP Rev5 | Review packages; authorization remains with designated authority → |
Connected registers, risk calculations, evidence freshness, review gates, JSON import/export and source-controlled policy examples.
Open operating suite →Configure authorized collectors, tenant isolation, durable evidence storage, scheduled jobs and monitored delivery in the client environment. The evaluation service requires identity, database and processing-provider configuration.
Request organization access →Agree on evidence turnaround, reviewer effort, overdue treatments and current tested-control coverage. Establish the baseline and acceptance criteria before claiming savings.
Review scope and handover →Native architecture and operating guide ↗ — owned source, domain review contracts, routing map and client demonstration guide.
Apply the current text, jurisdiction, system boundary and chosen baseline. ISO clause-level implementation requires access to licensed standards.