AAOAAO ABDULLAH AL OWASI

Governance architecture / decision to evidence

One connected system.
Every decision traceable.

Bring AI systems, suppliers and security controls into a reviewable operating model. Follow the evidence from its source to the decision it supports.

Discuss your governance scope ↗

Connected operating model

Scope. Implement. Verify. Review.

Automated calculations support accountable review. A passing test requires evidence, a named reviewer and a test date; expired evidence stops counting toward current coverage.

  1. 01

    Scope the decision

    Assets, AI use cases, vendors, data and applicable obligations.

    Inspect workflow →
  2. 02

    Define authority

    Ownership, access boundaries, risk appetite and release gates.

    Inspect workflow →
  3. 03

    Implement controls

    Link each control to its obligation and risk. Assign owners and tests.

    Inspect workflow →
  4. 04

    Collect and validate

    Normalize authorized source exports; retain provenance and review dates.

    Inspect workflow →
  5. 05

    Review and authorize

    Resolve evidence gaps, assign treatment and record the decision owner.

    Inspect workflow →
  6. 06

    Monitor and reopen

    Recalculate coverage and risk after source changes or evidence expiry.

    Inspect workflow →

The public workspace recalculates on interaction. Repository collectors and policy files support integration development; no live cloud collectors run behind this public page.

Extensible coverage

Start with the decision.
Map the requirements.

This review taxonomy covers 22 enterprise areas and 7 technical areas. It is an editable starting point, not an exhaustive industry standard. Framework associations guide scoping; they are not an assertion of equivalence, certification or complete control implementation.

Enterprise and market domains
Enterprise and market domains: scope-to-workflow mapping
Review areaFramework anchorsInspectable workflow and output
Corporate governance & accountabilityISO/IEC 27001 clauses 4–6; NIST SP 800-53 PMNamed owners, decisions and review dates →
Enterprise risk & appetiteNIST SP 800-53 RA; ISO/IEC 27001 clause 6Likelihood, impact, treatment and acceptance →
Regulatory applicability & changeGDPR; EU AI Act; NIST SP 800-53 PLJurisdiction, applicable requirement and effective date →
Policy lifecycleISO/IEC 27001 clause 7; NIST SP 800-53 PLVersion, ownership and attestation →
Control implementation & ownershipNIST SP 800-53; ISO/IEC 27001 Annex A; SOC 2 TSCRequirement → control → owner →
Internal audit & independenceISO/IEC 27001 clause 9; NIST SP 800-53 CAPlan, finding and corrective action →
External audit & certification readinessSOC 2 TSC; ISO/IEC 27001 clauses 9–10Reviewed tests and dated evidence →
Continuous assurance & remediationNIST SP 800-53 CA-7; SOC 2 CC4Evidence expiry, failed tests and treatment →
Supplier lifecycle & concentrationNIST SP 800-53 SR; ISO/IEC 27001 Annex ATier, dependencies and exit conditions →
Procurement & customer assuranceSOC 2 CC9; NIST SP 800-53 SRRequirements and evidence-backed answers →
Privacy & individual rightsGDPR Articles 5, 12–22, 25, 35Purpose, retention and impact review →
Processors & cross-border transfersGDPR Articles 28, 30, 44–49DPA, subprocessors and transfer mechanism →
Data classification & retentionGDPR Article 5; NIST SP 800-53 MP, PTData owner, classification and deletion review →
AI inventory & lifecycle authorizationNIST AI RMF; ISO/IEC 42001Inventory, evaluation and deployment decision →
AI fairness, safety & oversightNIST AI RMF MEASURE/MANAGE; ISO/IEC 42001Evaluation findings and human review gates →
AI transparency & content provenanceEU AI Act Article 50Disclosure decision and evidence →
Shadow AI & acceptable useNIST AI RMF; ISO/IEC 27001 Annex AUse-case intake and egress review →
Continuity, recovery & crisis readinessNIST SP 800-53 CP; ISO/IEC 27001 Annex ACritical services, recovery objectives and exercise evidence →
Incident governance & reportingNIST SP 800-53 IR; GDPR Articles 33–34Incident owner, escalation and corrective action →
Workforce, physical & organizational securityNIST SP 800-53 AT, PS, PE; ISO/IEC 27001 Annex AControl and review records; specialist assessment required →
Financial, fraud & ethical conduct riskNIST SP 800-53 PM, RAExposure and risk decisions; specialist assessment required →
Sector, market & contractual obligationsFedRAMP Rev5 when in scopeApplicability review; sector-specific controls require scoping →
Technical and authorization domains
Technical and authorization domains: scope-to-workflow mapping
Review areaFramework anchorsInspectable workflow and output
Security scope & authorization boundaryNIST RMF; NIST SP 800-53 PL-2, CA-3Asset scope and system boundary; deployment architecture review →
Identity, least privilege & segregationNIST SP 800-53 AC, IA; SOC 2 CC6IAM evidence and authorization policy source →
Cloud configuration & changeNIST SP 800-53 CM; SOC 2 CC8Configuration events and control decisions →
Threat, vulnerability & supply-chain assuranceNIST SP 800-53 RA-5, SI-2, SRAlert normalization and remediation priorities →
Logging, evidence integrity & provenanceNIST SP 800-53 AU; SOC 2 CC7Source timestamps and evidence validation →
Agent, tool & data authorizationNIST SP 800-53 AC; NIST AI RMFAgent/tool authorization policies and human escalation →
Assessment, authorization & ongoing monitoringNIST SP 800-53 CA-2, CA-6, CA-7; FedRAMP Rev5Review packages; authorization remains with designated authority →

Download the editable mapping JSON →

Adapt to your enterprise.

Inspectable today

Connected registers, risk calculations, evidence freshness, review gates, JSON import/export and source-controlled policy examples.

Open operating suite →

Integration scope

Configure authorized collectors, tenant isolation, durable evidence storage, scheduled jobs and monitored delivery in the client environment. The evaluation service requires identity, database and processing-provider configuration.

Request organization access →

Define value before delivery

Agree on evidence turnaround, reviewer effort, overdue treatments and current tested-control coverage. Establish the baseline and acceptance criteria before claiming savings.

Review scope and handover →

Native reference architecture

Native architecture and operating guide ↗ — owned source, domain review contracts, routing map and client demonstration guide.

Framework sources

Apply the current text, jurisdiction, system boundary and chosen baseline. ISO clause-level implementation requires access to licensed standards.