category hub
Frameworks & Checklists
Open frameworks, control mappings, and checklists for NIST AI RMF, EU AI Act, ISO/IEC 42001, and OWASP LLM Top 10.
8 tools
Free
CSA AI Controls Matrix
Cloud Security Alliance's AI Controls Matrix v1.0.1 (Jul 2025): 243 controls across 18 domains with a five-role shared-responsibility model, crosswalked to NIST AI 600-1.
Free
EU GPAI Code of Practice
The EU's Code of Practice for general-purpose AI models (Jul 2025): transparency, copyright, and safety & security chapters that operationalize AI Act Chapter V obligations.
Paid
ISO/IEC 42001
The first certifiable international standard for AI management systems (AIMS).
Free
MITRE ATLAS
Knowledge base of adversarial tactics and techniques against AI systems, modeled on ATT&CK.
Free
NIST AI 600-1 (Generative AI Profile)
NIST's Generative AI Profile (Jul 2024): 12 GenAI risk categories with 200+ suggested actions, layered on the AI RMF's govern/map/measure/manage functions.
Free
NIST AI RMF
The US reference framework for AI risk management: Govern, Map, Measure, Manage.
Free
OWASP Agentic AI Security & Governance
OWASP's State of Agentic AI Security and Governance 2.0 (2026): frameworks and controls for securing autonomous agents, including the Top 10 for Agentic Applications.
Free
OWASP LLM Top 10
Community-maintained checklist of the ten most critical risks for LLM applications.
faq
Frequently asked questions
- What does Frameworks & Checklists cover?
- Frameworks & Checklists groups tools that share a primary capability area. Use this hub to compare options, see pricing models, and shortlist before booking demos.
- How is the Frameworks & Checklists list maintained?
- Each tool is reviewed against vendor docs and trust pages. The "last verified" date on each tool page reflects the most recent review.
- Can I submit a tool for Frameworks & Checklists?
- Yes. Use the Submit page to send a vendor link; we review it against the directory criteria.
