Platform · Framework MappingStop rebuilding the mapping every audit cycle

AI framework mapping
across 5 standards,
scored from your own activity.

Obiguard estimates coverage from what is actually happening in your project — policies, controls, criteria, use cases, evaluations, and violations. Every category is marked covered, partial, or not covered, with the evidence behind the call and the concrete next step to close the gap.

Frameworks
5+ your AUP
Certifiable
1ISO 42001
AISCF activities
427 phases
MGF dimensions
95 evidenceable
01 / Why these five

Two global, one security,
two for Southeast Asia.

NIST AI RMF and ISO/IEC 42001 are what a multinational customer or auditor will ask for. The OWASP LLM Top 10 is what your security team already works from. AISCF and MGF for GenAI are the national frameworks in the two markets Obiguard operates in — Malaysia and Singapore.
01NIST AI RMF

NIST AI Risk Management Framework

PublisherUS National Institute of Standards and Technology
EditionVersion 1.0, January 2023
Structure4 functions · 10 categories mapped
Voluntary guidance — no certification body

The reference vocabulary for AI risk in the United States, and the one most enterprise risk teams have already adopted internally. It organises AI risk into four functions — Govern, Map, Measure, Manage — and asks whether an organisation can show it does each of them, rather than prescribing specific technology.

Govern and Map are evidenced by the registry: Policy Sets with a draft → pending → active lifecycle, Controls with segregation of duties, and AI Use Cases and Agents that record intended purpose and risk rating. Measure is where the new capabilities land — the Ethics & Bias report answers MEASURE 2.1 on trustworthy characteristics, and Project Moonshot runs answer MEASURE 2.7 on adversarial testing. Manage is the Violations pipeline and Review Queue.

What Obiguard evidences it with
Policy SetsControlsAI Use CasesEthics & BiasEvaluationsViolations
Example categories scored
GOVERN 1.1 — Governance policies and processesGOVERN 4.1 — Accountability structuresMAP 1.1 — System purpose and contextMEASURE 2.1 — Trustworthy characteristics evaluatedMEASURE 2.7 — Adversarial testing and red-teamingMANAGE 4.1 — Incidents tracked to resolution
02ISO/IEC 42001

ISO/IEC 42001 — AI Management System

PublisherISO / IEC
EditionISO/IEC 42001:2023
Structure5 clauses mapped (6 – 10)
Certifiable — via an accredited body

The only certifiable standard in this set. It is a management-system standard in the same family as ISO 27001: it asks you to plan for AI risk, resource the work, operate controls, evaluate performance, and improve — and it expects documented evidence of each, audited by an accredited certification body.

Obiguard produces the operating evidence an ISO/IEC 42001 auditor asks for, but not the certificate. Clause 6 planning maps to Controls and Criteria with risk ratings; Clause 8 operation to Policy Sets enforcing at the gateway; Clause 9 performance evaluation to the Dashboard, Audit Log, and the nightly Ethics & Bias trend; Clause 10 improvement to the Review Queue and the resolution trail behind each violation.

What Obiguard evidences it with
ControlsCriteriaPolicy SetsAudit LogDashboardReview Queue
Example categories scored
Clause 6 — Planning: risk assessment and treatmentClause 7 — Support: resources, competence, awarenessClause 8 — Operation: operational planning and controlClause 9 — Performance evaluation and internal auditClause 10 — Improvement: nonconformity and corrective action
03OWASP LLM Top 10

OWASP Top 10 for LLM Applications

PublisherOWASP Foundation
Edition2025 edition
Structure10 risk categories
Awareness list — no certification body

Not a compliance standard at all, but the security industry’s shared list of how LLM applications actually get broken — prompt injection, sensitive information disclosure, excessive agency, system prompt leakage, misinformation, unbounded consumption. It is the framework your penetration testers and your customers’ security questionnaires will both reference.

This is the framework that maps most directly onto product mechanics rather than paperwork. Guardrail Criteria address LLM01 prompt injection and LLM02 sensitive information disclosure at the gateway; agent and tool scoping addresses LLM06 excessive agency; the Ethics & Bias misinformation judge addresses LLM09; and Moonshot jailbreak recipes test whether those defences actually hold.

What Obiguard evidences it with
Guardrail CriteriaPolicy SetsAgent scopingEvaluationsEthics & Bias
Example categories scored
LLM01 — Prompt InjectionLLM02 — Sensitive Information DisclosureLLM05 — Improper Output HandlingLLM06 — Excessive AgencyLLM07 — System Prompt LeakageLLM09 — Misinformation
04AISCF

AI Systems Cyber Security Framework

PublisherNACSA — National Cyber Security Agency of Malaysia
EditionAISCF, 2026
Structure7 lifecycle phases · 42 security activities
National guidance — no certification body

Malaysia’s national framework for securing AI systems, published by NACSA. Where NIST organises by risk function, AISCF organises by lifecycle: Inception, Design & Development, Verification & Validation, Deployment, Operation & Monitoring, Continuous Validation and Re-evaluation, and Retirement. Each phase carries specific security activities — 42 in total — and it is explicitly risk-based, so the depth expected scales with the system’s risk.

Obiguard covers the operational end of the lifecycle in depth and the design end only where the platform holds a record. Operation & Monitoring maps to guardrail enforcement, the Dashboard, and the Audit Log; Verification & Validation and Continuous Validation map to Moonshot evaluation runs and the nightly Ethics & Bias job; Deployment maps to scoped Access Keys and prompt-version approval. Inception and Retirement activities — requirements definition, data disposal, model retirement — are organisational steps Obiguard records rather than performs.

What Obiguard evidences it with
EvaluationsEthics & BiasAudit LogAccess KeysPolicy SetsAI Agents
Example categories scored
IN04 — Assess AI security risksDD06 — Perform AI threat modellingVV05 — Output verification & validationDP02 — Environment & access securityOM03 — Security operations & monitoringCR06 — Security assessment & testingRT02 — Model retirement
05MGF for GenAI

Model AI Governance Framework for Generative AI

PublisherIMDA & AI Verify Foundation, Singapore
EditionPublished 30 May 2024
Structure9 dimensions · 5 platform-evidenceable
Baseline guidance — no certification body

Singapore’s baseline for a trusted generative-AI ecosystem, from IMDA and the AI Verify Foundation — the same foundation behind Project Moonshot. It is deliberately broader than a security standard: nine dimensions spanning accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment research, and AI for public good.

Four of the nine dimensions — Testing & Assurance, Content Provenance, Safety & Alignment R&D, and AI for Public Good — are ecosystem-level commitments aimed at model developers, testing bodies, and policymakers, so no deployer platform can evidence them and the headline score is capped at 56% by design. Read the per-dimension detail, not the gauge. Of the five that a deployer can evidence, Security is the strongest: guardrail Criteria screen for GenAI-specific threat vectors, Policy Sets enforce at the gateway, and Access Keys bound exposure. Accountability rests on segregation of duties in Controls and full attribution in the Audit Log.

What Obiguard evidences it with
ControlsAudit LogPolicy SetsAccess KeysEvaluationsEthics & Bias
Example categories scored
AccountabilityDataTrusted Development and DeploymentIncident ReportingSecurityTesting and Assurance
06 — Internal AUP

Your own Acceptable Use Policy

Yours — mapped the same way

Define your own Controls and Criteria with custom labels and evidence mapping — the same coverage view, scored against the policy your organisation actually wrote.

What Obiguard evidences it with
Custom ControlsCustom CriteriaCustom labels
02 / How coverage is calculated

A self-assessment, not a certification.

Coverage is estimated from your platform activity. With the exception of ISO/IEC 42001, none of these frameworks has a certification body attached — this view helps you prepare for an audit, it does not substitute for one.
01 — EVIDENCE

Scored from real activity

A category turns green because an active Policy Set, an approved Control, a registered Use Case, or a completed evaluation backs it — each one linked from the coverage row, so you can click through to the record.

Covered · Partial · Not covered
02 — GAPS

Named gaps, concrete actions

Partial categories list what is still missing. Uncovered ones list the specific next steps — register a use case with a risk rating, get a control through approval, schedule an evaluation run.

Gaps · suggested actions
03 — HONEST CEILINGS

Where a score cannot reach 100%

Some categories are not a deployer’s to satisfy — four MGF dimensions are ecosystem commitments for model developers and policymakers, which caps that framework at 56% by design. We say so on the page rather than quietly scoring around it.

MGF capped at 56%
04 — VERSIONED

Mapped against a stated edition

Each crosswalk records which edition of the source standard it was built against and when a human last reviewed it. Standards revise; the mapping does not silently follow, so staleness is visible rather than assumed away.

Edition · last reviewed
05 — EXPORT

Export for the auditor

Pull the whole coverage view as CSV — every category, its status, and the evidence behind it — alongside the Audit Log export for the underlying events.

CSV export · per framework
06 — CONTINUOUS

Recomputed, not re-collected

Coverage is computed from live platform state, so activating a Policy Set or completing a red-team run moves the number the same day — no spreadsheet refresh, no evidence-gathering sprint before a review.

Live · no manual collection
03 / FAQ

Frameworks,
explained.

What each framework is, who publishes it, and what Obiguard can and cannot evidence against it.

Talk to an SE →

What is AISCF?[01]

AISCF is Malaysia’s AI Systems Cyber Security Framework, published by NACSA, the National Cyber Security Agency of Malaysia. It is a risk-based framework that organises AI security by lifecycle rather than by risk function: seven phases — Inception, Design & Development, Verification & Validation, Deployment, Operation & Monitoring, Continuous Validation and Re-evaluation, and Retirement — carrying 42 security activities in total. It is national guidance, not a certifiable standard, so there is no AISCF certificate to obtain.

What is the MGF for GenAI?[02]

MGF for GenAI is Singapore’s Model AI Governance Framework for Generative AI, published on 30 May 2024 by IMDA and the AI Verify Foundation — the same foundation behind Project Moonshot. It sets out nine dimensions for a trusted generative-AI ecosystem: accountability, data, trusted development and deployment, incident reporting, testing and assurance, security, content provenance, safety and alignment R&D, and AI for public good. It is baseline guidance rather than a certifiable standard.

Why is the MGF for GenAI score capped at 56%?[03]

Four of the nine MGF dimensions — Testing & Assurance, Content Provenance, Safety & Alignment R&D, and AI for Public Good — are ecosystem-level commitments aimed at model developers, third-party testing bodies, and policymakers. No platform used by a deploying organisation can evidence them, so Obiguard caps the framework at 56% rather than scoring around the gap. Read the per-dimension detail instead of the headline gauge.

How does Obiguard calculate framework coverage?[04]

Coverage is computed from live platform activity, not from a questionnaire. Each framework category is marked covered, partial, or not covered based on whether an active Policy Set, an approved Control, a registered AI Use Case, a completed evaluation run, or logged violations evidence it. Partial categories list what is still missing; uncovered ones list concrete next steps. The whole view exports to CSV.

Does Obiguard certify us against ISO/IEC 42001?[05]

No. ISO/IEC 42001:2023 is the only certifiable standard of the five, and certification comes from an accredited certification body, not from a software vendor. What Obiguard produces is the operating evidence an auditor asks for — risk assessment and treatment under Clause 6, operational control under Clause 8, monitoring and internal audit under Clause 9, and nonconformity handling under Clause 10. The other four frameworks have no certification body attached at all, so coverage against them is a self-assessment aid for audit preparation.

Do you support the EU AI Act, SOC 2, or HIPAA?[06]

Not as built-in framework mappings today. Obiguard ships crosswalks for NIST AI RMF, ISO/IEC 42001, the OWASP LLM Top 10, AISCF, and MGF for GenAI. You can express any other obligation — including EU AI Act articles, SOC 2 criteria, or HIPAA safeguards — as your own Controls and Criteria with custom labels, and it will be scored and exported the same way. Tell us which framework you need next and we will prioritise it.

Can I map my own internal AUP?[07]

Yes. Define your own Controls and Criteria with custom labels and custom evidence mapping, and the coverage view scores them exactly as it scores the five published frameworks — including the same CSV export for auditors.
04 / Related

The capabilities behind the coverage.

Most categories turn green because something in the platform evidences them. Adversarial-testing categories are answered by Project Moonshot evaluations; trustworthy-characteristic categories by the nightly Ethics & Bias report; monitoring and improvement categories by the Audit Ledger and Policy Sets. See them together on the Governance AI page.