How our method relates to NIST, OWASP, ISO and Swiss law

This mapping helps you navigate between famous frameworks and one tested agent. It proves no conformity with any of them and never replaces their full requirements.

Two different questions

Management and risk frameworks ask how an organization governs AI: policies, roles, portfolios. AIA Guard asks a narrower, practical question: what did this agent version see, decide and do in one identified workflow — and which evidence supports the answer? Both views are useful, but one can never be claimed from the other.

Different questions answered by external frameworks and AIA Guard controls
ViewPrimary scopeTypical evidenceAIA Guard runtime link
Organizational AI governancePolicies, roles, risk processes and system portfolio.Governance records, risk register, management review.G03 binds the reviewed agent to a versioned inventory.
Privacy and data protectionPurposes, personal-data processing, rights and safeguards.Data maps, notices, impact analysis, transfer assessment.D03 tests whether protected context can leak out.
Generative-AI securityThreats and mitigations around models, inputs and outputs.Threat model, authorization design, attack tests.S02 tests least-privilege tool access.
Human oversightAbility of people to understand, intervene and stop.Approval policy, interfaces, escalation and competence.H01 tests approval locked to the exact action.
Operational assuranceMonitoring, incidents, change and traceability.Event records, response exercises, release history.O01 tests tamper-showing runtime records.

NIST AI RMF

Governance and scope follow the spirit of NIST’s GOVERN function; test design and evidence support MEASURE; incident and change controls support MANAGE. NIST describes AI RMF as voluntary. AIA Guard treats a cross-reference as orientation — never as a NIST certification or an official crosswalk.

OWASP GenAI risks

Our controls for untrusted input, tool authorization, disclosure resistance, secrets and execution boundaries use OWASP threat categories to build attack cases. AIA Guard adds operating ownership, human approval and evidence requirements for one specific deployment.

Swiss data protection

The method asks for transparent purposes and data sources, minimization, impact analysis where risk is high, and meaningful human review where relevant. Data locations are declared and transfers assessed in context. The method does not claim that all personal data must stay in Switzerland, or that consent is the only lawful basis.

Where ISO ends and we begin

ISO/IEC 42006 sets requirements for bodies that audit and certify AI management systems under ISO/IEC 42001. AIA Guard’s draft instead evaluates one bounded agent deployment: it is not an ISO management-system certificate or an accredited conformity assessment. The mapping is maintained from reviewed primary sources; it is issued and approved by AIA Guard alone, not by the referenced organizations.

Common questions

Is this an official guide published by NIST, OWASP, ISO or the FDPIC?

No. It is an AIA Guard reading aid for navigating different scopes. None of the referenced organizations has approved it.

Does passing an AIA Guard control prove compliance with another framework?

No. A control result can support evidence collection, but conformity depends on the full requirements, scope and decision process of the referenced framework or law.

Why map organizational frameworks to runtime controls?

The mapping shows where a governance claim can be tested inside one working agent — while keeping organization-wide management and runtime behaviour clearly apart.