How the AI Assured Framework is structured
The AI Assured Framework in one page: five pillars, sixteen domains, and how they map to EU AI Act, NIST AI RMF 1.0 and ISO/IEC 42001.
The five pillars
- Governance & Accountability — roles, RACI, board oversight, policy stack. Maps to ISO/IEC 42001 §5, NIST AI RMF GOVERN, EU AI Act Art. 17 (quality management).
- Data & Model Lifecycle — inventory, lineage, data quality, model cards, change management. Maps to EU AI Act Arts 10, 11, 15 and NIST MAP/MEASURE.
- Risk, Bias & Human Oversight — risk classification, fairness testing, meaningful human review. Maps to EU AI Act Arts 9, 14 and GDPR Art. 22.
- Security, Privacy & Vendor — DLP for AI, vendor due diligence, secrets handling, sub-processor mapping. Maps to GDPR Art. 32, NIS2 and ISO/IEC 27001 Annex A.
- Transparency & Disclosure — user-facing notices, AI-content labelling, incident reporting. Maps to EU AI Act Arts 50, 73.
Tier expectations
| Pillar | Foundation | Essential | Professional |
|---|---|---|---|
| Governance | Named owner | RACI + policy | Board KPI pack |
| Lifecycle | Inventory | Versioned model cards | Automated change protocol |
| Risk & oversight | Risk register | Bias test on launch | Continuous monitoring |
| Security & vendor | Vendor list | DLP labels live | Quarterly attestation |
| Transparency | AI notices | Public model summary | Externally assured report |
Do this Monday
- Print the pillar map and circle the three weakest domains.
- Assign a named owner per pillar — most reviewer findings cluster on pillars with no owner.
Reviewer hot-buttons
- Pillar owners named in writing.
- Each control cross-referenced to at least one regulation clause.