Universal Standard Mapping

The frameworks — fluently spoken, plainly translated.

The standards are strong but dense, and written for far larger organizations. We translate them into a plan your team can run — and one assessment maps your posture across all of them at once.

What We Map To

The standards that matter for AI — and how we use each.

THE SPINE

NIST AI RMF 1.0

The “what” and “why” of AI risk management, through four functions: Govern, Map, Measure, Manage. It’s the backbone of every engagement.

GENERATIVE AI

NIST AI 600-1 Profile

The Generative AI Profile and its twelve risk categories — the organizing spine of our AI Adoption Assurance service.

CYBER BASELINE

NIST CSF 2.0

Core cybersecurity outcomes — Identify, Protect, Detect, Respond, Recover — that AI security has to sit on top of, not beside.

THE “HOW”

CSA AI Controls Matrix

A vendor-agnostic matrix of 243 control objectives across 18 domains — the tactical engineering detail behind the strategy.

MANAGEMENT SYSTEM

ISO/IEC 42001

The AI management-system standard — the operating structure for governing AI responsibly over time.

REGULATORY

EU AI Act

Risk-tiered regulatory obligations. We map exposure proportionally, so readiness scales with actual risk — not fear.

Operational Translation

Bridging risk philosophy and tactical engineering.

NIST AI RMF gives you the “what” and “why.” The CSA AI Controls Matrix gives you the “how.” We connect the two — turning high-level risk language into specific, owned engineering objectives, mapped to the compliance regimes you already answer to (ISO 42001, SOC 2, HIPAA, and the EU AI Act).

GovernOwnership & risk appetite
MapInventory & context
MeasureTest & evaluate
ManageTreat & monitor
The Analysis Model

CSA AICM as the foundation. Five pillars as the lens.

We use the CSA AI Controls Matrix — 243 control objectives across 18 domains — as the foundation, and align it to NIST AI RMF, the NIST AI 600-1 Generative AI Profile, ISO 42001, and the EU AI Act. Every control is then analyzed on five practical pillars — Type, Ownership, Architectural Relevance, LLM Lifecycle, and Threat Category — and we customize the set to the controls that make the most sense for your organization, never a one-size-fits-all checklist.

CSA AI Controls Matrix — 243 control objectives across 18 domains — aligned to NIST AI RMF, NIST AI 600-1, ISO 42001, and the EU AI Act, then analyzed through a five-pillar model of type, ownership, architectural relevance, LLM lifecycle, and threat category.
NIST AI 600-1 · The “Dirty Dozen”

The twelve generative-AI risk categories.

Our AI Adoption Assurance engagement gives you a documented, reasoned position on every one of these — assessed per use case as in scope, monitor, or out of scope.

01

CBRN Information

Lowered barriers to chemical, biological, radiological, or nuclear information and capabilities.

02

Confabulation

Confidently stated false or misleading content — the “hallucination” problem.

03

Dangerous or Violent Content

Generation of dangerous, violent, or hateful content at machine scale.

04

Data Privacy

Leakage or misuse of personal and sensitive data through prompts, training, or outputs.

05

Environmental Impacts

The energy and resource footprint of training and running generative models.

06

Harmful Bias

Amplified bias and homogenization — outputs that narrow or skew at scale.

07

Human-AI Configuration

Over-reliance, automation bias, and unclear roles between people and the system.

08

Information Integrity

Degraded trust in information — disinformation, deepfakes, and synthetic media.

09

Information Security

An expanded attack surface: prompt injection, data poisoning, and model theft.

10

Intellectual Property

Infringement or leakage of IP through training data or generated outputs.

11

Abusive Content

Generation of obscene, degrading, or non-consensual content, including CSAM risk.

12

Value-Chain Integration

Risks inherited from third-party data, models, and components in the supply chain.

Not another GRC engagement. We speak these frameworks fluently so you don’t have to — giving you the controls that matter, sized for the mid-market, mapped straight to business outcomes. Defensibility, not paperwork.

Map your posture across every standard at once.

One free assessment shows where you stand against the frameworks that matter — and a right-sized path to close the gaps.

Request a Free Assessment